We should investigate, if we could create minimalistic implementation to replace nabeken/docker-volume-container-rsync.
In addition of dropping external dependency, if the image is built during packer build, we could use the bastion ssh keys to limit access to the results.
Other hardening would also be possible, if needed.