As best practice the application must be run as a non root user with a read only root file system. We could not find a way to configure such security context and moreover we can see the graphdb instance runs as a root user inside a container.