Skip to main content

Security defaults

The enclave applies hardened defaults to every container, so the attested config honestly reflects what runs. These differ from stock Docker, so a container that relied on Docker’s permissive defaults may need adjustment.
If your app needs writable scratch space, add a tmpfs mount or set read_only: false. List required capabilities (for example IPC_LOCK for pinned memory or NET_BIND_SERVICE to listen below port 1024) under cap_add.A container with cvm_admin: true is exempt from these defaults: it runs privileged, as root, with a writable root filesystem. See Direct admin SSH.
The read-only /tinfoil mount contains:

Healthchecks

Add a healthcheck so the enclave checks that your app is ready before marking the deployment Running. Without one in the config, the container is considered ready as soon as Docker starts the process (a HEALTHCHECK in the Dockerfile is not enough). That can be too early for apps that load model weights or warm caches before serving requests.
How it’s used during boot. The enclave’s boot process polls Docker’s health state every 5 seconds once the container starts and waits until Docker reports the container Healthy before finishing boot. If Docker reports Unhealthy (i.e. retries consecutive failures after start_period has elapsed), the deployment fails and the last healthcheck output is surfaced as the error detail. The test command runs inside the container, so whatever you invoke (curl, wget, a language runtime) has to be available in the image. For an inference server like vLLM that already exposes /health, a curl -sf http://localhost:<port>/health check is idiomatic.
If your container takes 15 minutes to load model weights, set start_period to at least 20 minutes. Otherwise, healthcheck failures during startup can exhaust retries and fail the deployment before the app is ready.
See also. The fields above follow Docker Compose semantics; the Compose healthcheck reference covers exit codes and CMD-SHELL vs CMD. Only the five fields above are accepted. disable: true is rejected, and test: ["NONE"] must not be used: it turns off health reporting, so boot waits forever.

Restart policy

By default, Docker does not restart a container when its process exits. For long-running servers, set restart so Docker restarts the process after a crash.
Interaction with healthchecks. The restart policy fires when the container process exits. It has no effect when Docker marks the container Unhealthy (the process keeps running; only its health state changes). During boot, the enclave fails the deployment on Unhealthy regardless of restart. Once the container has been declared Healthy, restart governs what happens if the process later dies. See also. This field follows Docker Compose semantics, documented in the Compose restart reference.