Description
Do not grant unnecessary Linux capabilities to a Docker Compose service. Capabilities permit privileged kernel operations, so granting more than required can weaken isolation.
Using cap_add with ALL can grant system privileges the application does not need. Containers should retain only required capabilities and drop unnecessary ones where possible.
Potential impact
- Additional privileges can be abused in container escape or system misuse attempts.
- An application vulnerability may have a larger impact.
- Effects on the host or other containers depend on the actual privileges and other isolation settings.
Remediation
- Minimize
cap_addand specify only capabilities the service requires. - Use
cap_dropto remove unnecessary capabilities where possible. - Document each service’s needs to prevent repeated excessive grants.
Examples
Before
yaml
services:
webapp:
image: nginx:latest
cap_add:
- ALL
After
yaml
services:
webapp:
image: nginx:latest
cap_drop:
- ALL
Explanation:
- Before: All capabilities are added, unnecessarily broadening system privileges.
- After: All capabilities are dropped. This can also remove privileges needed for image initialization or execution; test the service and restore only those it requires.