Default seccomp profile disabled

Remove unnecessary seccomp overrides and allow only required system calls.

Description

Seccomp restricts the system calls a container can use, reducing its exposure to the kernel.

A setting such as seccomp:unconfined in security_opt disables this protection. Removing the default seccomp restrictions without a specific need can weaken container isolation.

Potential impact

  • More system calls become available, increasing the attack surface.
  • An application vulnerability may create additional opportunities to exploit kernel weaknesses.
  • The container loses a layer of isolation expected by security standards.

Remediation

  • Remove settings that disable seccomp from security_opt.
  • If additional system calls are needed, consider a tailored profile instead of disabling filtering entirely.
  • Keep debugging exceptions separate from production deployment settings.

Examples

These excerpts assume a Linux Docker environment with seccomp support. Replace sample/app:latest with the actual service image.

Before

yaml
services:
  demo:
    image: sample/app:latest
    security_opt:
      - seccomp:unconfined

After

yaml
services:
  demo:
    image: sample/app:latest

Explanation:

  • Before: Seccomp protection is disabled, making more system calls available to the container.
  • After: The seccomp override is removed. Verify that the runtime actually applies its default profile.

References