Mount root fs read only with docker-compose

I try to apply the docker CIS (

The test 5.13 is: Mount container’s root filesystem as read only
There is an option for docker run to mount the root FS read only: --read-only=true
But I can’t find the possibility to achieve the same with docker-compose.

Is there a possibility to mount the root FS read only with docker-compose?

Hi this can be done by adding read_only: true to the service description, see also


The reference documentation talks about this flag in the volume section, not in the service definition section. However, it does appears to be actually honored when at the service definition.

Is it a docu mishap?