Description
Docker Compose privileged: true gives a container much broader kernel and device access than an ordinary container. On Linux, it grants all capabilities and access to host devices while relaxing some security restrictions.
Ordinary application services rarely need this setting. Enabling it for convenience can greatly increase the impact of a compromise.
Potential impact
- The container can gain excessive access to host resources and kernel functionality.
- An application compromise can extend to the host or other workloads.
Remediation
- Remove
privileged: truefrom ordinary services or set it tofalse. - Grant only the specific capabilities and devices the application needs, and remove unnecessary privileges.
- Run work that requires privileged mode in an isolated, dedicated environment. Verify required functionality and security restrictions after the change.
Examples
Supply the actual build directory and Dockerfile-alternate.
Before
yaml
version: "3.9"
services:
webapp:
build:
context: ./dir
dockerfile: Dockerfile-alternate
privileged: true
The service runs in privileged mode.
After
yaml
version: "3.9"
services:
webapp:
build:
context: ./dir
dockerfile: Dockerfile-alternate
The privileged setting is removed. Review the image’s runtime user, capabilities and mounts separately.