Description
Setting no-new-privileges:true in Docker Compose security_opt restricts privilege gains from setuid, setgid and file capabilities when a process executes a new program. Without this protection, those escalation paths may remain available.
The option does not remove existing privileges or prevent every exploit. Use it alongside least-privilege execution.
Potential impact
- A compromised process may gain greater privileges by executing a program that provides them.
- The resulting access can extend damage to additional data or resources.
Remediation
- Set
no-new-privileges:truein the service’ssecurity_opt. - Identify startup or runtime operations that depend on privilege escalation and adapt them to work with minimal privileges.
- Review
privileged, added capabilities and sensitive mounts, then test the application after the change.
Examples
The example requires the actual build context and service.dockerfile.
Before
yaml
version: "3.4"
services:
app:
build:
context: ./
dockerfile: service.dockerfile
security_opt:
- no-new-privileges:false
Protection against privilege gains through execution of a new program is disabled.
After
yaml
version: "3.4"
services:
app:
build:
context: ./
dockerfile: service.dockerfile
security_opt:
- no-new-privileges:true
The service enables no-new-privileges:true. Confirm that its required startup and runtime operations work under this restriction.