Docker Compose

Guidance on Docker Compose resource limits, container isolation, networking and volume settings.

Documentation

Article Path
Docker Compose CPU usage limit missing dockerCompose/cpus_not_limited
Review container healthcheck settings dockerCompose/healthcheck_not_set
Custom cgroup_parent dockerCompose/cgroup_not_default
Container lacks no-new-privileges protection dockerCompose/no_new_privileges_not_set
Review on-failure restart limits dockerCompose/restart_policy_on_failure_not_set_to_5
Review container process limits dockerCompose/pids_limit_not_set
Container runs in privileged mode dockerCompose/privileged_containers_enabled
Container security options not specified dockerCompose/security_opt_not_set
Bind mount permits mount propagation dockerCompose/volume_mounted_in_multiple_containers
Default seccomp profile disabled dockerCompose/default_seccomp_profile_disabled
Review container memory limits dockerCompose/memory_not_limited
Sensitive host directory is mounted in a container dockerCompose/volume_has_sensitive_host_directory
Review volumes shared between containers dockerCompose/shared_volumes_between_containers
Excessive container capabilities dockerCompose/container_capabilities_unrestricted
Container port binding is too broad dockerCompose/container_traffic_not_bound_to_host_interface
Docker socket is mounted in a container dockerCompose/docker_socket_mounted_in_container
Review low port mappings and privileges dockerCompose/privileged_ports_mapped_in_container
Shared host IPC namespace dockerCompose/shared_host_ipc_namespace
Shared host PID namespace dockerCompose/host_namespace_is_shared
Shared host network namespace dockerCompose/shared_host_network_namespace
Shared host user namespace dockerCompose/shared_host_user_namespace

Related pages21

Docker Compose CPU usage limit missing

Set a CPU limit suited to the service’s workload.

Review container healthcheck settings

Check actual service health and connect the results to failure handling.

Custom cgroup_parent

Check that the parent cgroup matches the intended resource limits and operational policy.

Container lacks no-new-privileges protection

no-new-privileges restricts acquiring additional privileges by executing a new program.

Review on-failure restart limits

Bound restart attempts to recovery requirements and monitor repeated failures.

Review container process limits

Limit process counts to workload needs to reduce the risk of host resource exhaustion.

Container runs in privileged mode

Privileged containers can substantially weaken isolation through broad permissions and device access.

Container security options not specified

Review default protections and the additional runtime security options required by the service.

Bind mount permits mount propagation

Permit mount propagation only when its direction and effect on nested mounts are required.

Default seccomp profile disabled

Remove unnecessary seccomp overrides and allow only required system calls.

Review container memory limits

Set per-service memory limits and verify their enforcement and actual usage.

Sensitive host directory is mounted in a container

Mounting a sensitive host directory can give a container access to host data.

Review volumes shared between containers

Check the need for shared data and its write permissions.

Excessive container capabilities

Allow only required Linux capabilities and test the service after reducing privileges.

Container port binding is too broad

Limit published ports to the host interfaces the service requires.

Docker socket is mounted in a container

Mounting the Docker socket can give container processes control of the host Docker daemon.

Review low port mappings and privileges

Publish only required ports and remove network privileges the service does not need.

Shared host IPC namespace

Remove unnecessary host IPC sharing and isolate interprocess communication resources.

Shared host PID namespace

Remove unnecessary host PID sharing and preserve process isolation.

Shared host network namespace

Review the need for host networking and expose only required addresses and ports.

Shared host user namespace

Reduce host user-namespace exceptions and verify the actual UID mappings.