fix(vector): close local pgvector final review
This commit is contained in:
@@ -5,7 +5,9 @@ repository and point the `*_SECRET_FILE` variables documented in the root README
|
||||
|
||||
Compose mounts each file read-only beneath `/run/secrets`. The core process runs as UID 10001;
|
||||
the mounted files must be readable by that UID. Docker Compose file-backed secrets are normally
|
||||
mounted read-only with mode `0444`; verify with:
|
||||
mounted read-only with mode `0444`. This mode is accepted only for runtime paths beneath
|
||||
`/run/secrets`, where the container mount is read-only and scoped to services that declare the
|
||||
secret. Source files on the host must have no group/other bits (`0600` or `0400`). Verify with:
|
||||
|
||||
```sh
|
||||
docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
|
||||
Reference in New Issue
Block a user