docker build -t readonly .
Show how the setcap stuff works in conjunction with dropping all capabilities.
$ docker-compose run --rm readonly --readonly
$ docker-compose run --rm readonly-setcap --readonly
exec /usr/local/bin/readonly-setcap: operation not permitted
$ docker-compose run --rm readonly --readonly