reference workloads Container security¶ The following settings are applied to all containers running in Nais: Read only root filesystem. Only /tmp is writable. Runs as non-root, with user and group id 1069 To override these settings, see the following how-to guides: Disable read-only file system Overriding runAsUser / runAsGroup Was this page helpful? Thanks for your feedback! Thanks for your feedback! Help us improve this page by using our feedback form or contact us on Slack.