Make /cvmfs read-only in containers
Potential fix for the atlas-sim issue discussed in BMK-448, allowing Singularity full containment with atlas-sim. Also increments the version tag in the atlas-sim spec, so will rebuild that workload container with the change.