They then provide an example Dockerfile in an Appendix.
I've looked through NSA hardening guides for AD, Linux, and many other technologies. They're helpful and imminently reasonable.
Do the NSA and CIA do dirty things? Yes. Should you trust everything they do? No. But you probably should at least skim the hardening document before you completely dismiss it because of your distrust.
Or don't even bother to read the document. Just look at the works cited section, which tells you a lot about the content of the article. Works are cited from: Center for Internet Security, Defense Information Security Agency, Linux Foundation, MITRE ATT&CK, Cybersecurity and Infrastructure Security Agency, Kubernetes.
The guide talks about the following:
- Scanning containers for vulnerabilities and misconfigurations - Running Pods with least privilege - Use network segmentation to limit blast radius - Use firewalls - Use strong authN and authZ - Capture and monitor logs - Periodically check your configurations and do vuln scans
It then points to CIS Kubernetes benchmarks, Kubernetes Security Technical Implimentation Guide, and CISA.
Where's the boogey man?
https://www.techdirt.com/2013/12/20/nsa-gave-rsa-10-million-...
Should all my service accounts run as root because NSA thinks that's a bad idea?
What I am saying is that when taking advice from a proven malicious actor, it’s important scrutinize the advice more carefully than one would usually do.
Osama bin Laden could have said “eat your vegetables to be healthy” and that is obviously reasonable advice but it’s also largely useless because we already know it is true. It’s the stuff that isn’t obviously already correct that we should take extra care to verify.
Not running containers as root is accepted by pretty much everyone I'm aware of as a 'good move. Same for building images carefully and preventing filesystem changes at runtime. Same goes for using sandboxing, syscall filtering etc.
This is a bit different from giving you a series of black box parameters and telling you to blindly rely on them. (And even then, DES being hardened against differential cryptography shows that's not always a bad thing, though more recent examples show the opposite can also happen).