Run containers with read only root file systems where the application supports it. Use tmpfs or volumes for paths that need to be writable so that an attacker cannot persist modifications inside a running container.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.