Description
cgroup_parent is a standard Compose option that selects the container's parent cgroup. Customizing it does not itself disable isolation, but choosing inappropriate parent limits or policies can prevent the intended CPU and memory controls from applying.
If a separate resource hierarchy is unnecessary, you can leave cgroup_parent unset. Assigning containers to an unintended cgroup can complicate resource control and incident analysis.
Potential impact
- A complex resource hierarchy can make operational tracking harder.
- Incorrect placement can cause resource contention with other workloads.
- Different parent cgroups across environments can reduce deployment consistency and maintainability.
Remediation
- Remove
cgroup_parentwhen no specific requirement needs it. - Review Compose resource limits when resource control is required.
- Document platform-level cgroup policies and manage them in shared templates.
Examples
Before
yaml
services:
app:
image: nginx:latest
cgroup_parent: custom-parent
After
yaml
services:
app:
image: nginx:latest
Explanation:
- Before: A custom parent is selected. Verify its limits; the setting itself is not a vulnerability.
- After: Parent selection follows runtime defaults. This change alone does not set CPU or memory limits.