Description
Seccomp restricts the system calls a container can use, reducing its exposure to the kernel.
A setting such as seccomp:unconfined in security_opt disables this protection. Removing the default seccomp restrictions without a specific need can weaken container isolation.
Potential impact
- More system calls become available, increasing the attack surface.
- An application vulnerability may create additional opportunities to exploit kernel weaknesses.
- The container loses a layer of isolation expected by security standards.
Remediation
- Remove settings that disable seccomp from
security_opt. - If additional system calls are needed, consider a tailored profile instead of disabling filtering entirely.
- Keep debugging exceptions separate from production deployment settings.
Examples
These excerpts assume a Linux Docker environment with seccomp support. Replace sample/app:latest with the actual service image.
Before
yaml
services:
demo:
image: sample/app:latest
security_opt:
- seccomp:unconfined
After
yaml
services:
demo:
image: sample/app:latest
Explanation:
- Before: Seccomp protection is disabled, making more system calls available to the container.
- After: The seccomp override is removed. Verify that the runtime actually applies its default profile.