From my experience, whoever is running docker seems to be able to run root commands on the host [1].
So any best practices for running docker ?
[1] http://reventlov.com/advisories/using-the-docker-command-to-...
From my experience, whoever is running docker seems to be able to run root commands on the host [1].
So any best practices for running docker ?
[1] http://reventlov.com/advisories/using-the-docker-command-to-...
However generally you don't give people access to run any docker command in production, you have some system that lets them deploy containers with predetermined settings, which don't include being able to set --privileged or add capabilities or change security policies.
But docker = sudo without password essentially.
So I am curious if there is a recommended way to run a service with a docker run.
Of course, that just replaces the question of "how is access to the docker daemon secured?" with "how is access to the orchestrator API secured?".
Do you think this is insufficient?
There is also a docker-bench-security tool set worth checking out.
Correct me if I'm wrong, I'm interested to know? I'm currently looking into docker and the advantages it brings to deployment instead of using a VM.