diff --git a/README.md b/README.md index d9c8f01..62b851d 100644 --- a/README.md +++ b/README.md @@ -66,8 +66,8 @@ add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; prelo The CI runners operate on a dedicated host system located in a completely separate Autonomous System (AS). This host is solely dedicated to providing CI runners and does not perform any other tasks. Each runner is hermetically isolated from others using non-privileged, shell-less user accounts with no direct login capability. Additionally, each runner executes within its own -separate directory tree, employs `DynamicUser` features, and adheres to strict systemd hardening policies (achieving a security -rating of 2.6). Docker containers used by runners do not run in privileged mode. Security is further enhanced through the use +separate directory tree, employs `DynamicUser` features, and adheres to strict systemd hardening policies (achieving a ``systemd-analyze security`` +rating of **``2.6``**). Docker containers used by runners do not run in privileged mode. Security is further enhanced through the use of both UFW software firewalls and dedicated hardware firewall appliances. ## 1.2. Immutable Source-of-Truth System