Container runs in privileged mode

Privileged containers can substantially weaken isolation through broad permissions and device access.

Description

Docker Compose privileged: true gives a container much broader kernel and device access than an ordinary container. On Linux, it grants all capabilities and access to host devices while relaxing some security restrictions.

Ordinary application services rarely need this setting. Enabling it for convenience can greatly increase the impact of a compromise.

Potential impact

  • The container can gain excessive access to host resources and kernel functionality.
  • An application compromise can extend to the host or other workloads.

Remediation

  • Remove privileged: true from ordinary services or set it to false.
  • Grant only the specific capabilities and devices the application needs, and remove unnecessary privileges.
  • Run work that requires privileged mode in an isolated, dedicated environment. Verify required functionality and security restrictions after the change.

Examples

Supply the actual build directory and Dockerfile-alternate.

Before

yaml
version: "3.9"

services:
  webapp:
    build:
      context: ./dir
      dockerfile: Dockerfile-alternate
    privileged: true

The service runs in privileged mode.

After

yaml
version: "3.9"

services:
  webapp:
    build:
      context: ./dir
      dockerfile: Dockerfile-alternate

The privileged setting is removed. Review the image’s runtime user, capabilities and mounts separately.

References