Container security options not specified

Review default protections and the additional runtime security options required by the service.

Description

security_opt can declare runtime security options such as AppArmor, SELinux and no-new-privileges.

Omitting security_opt does not automatically disable Docker protections such as default seccomp or AppArmor profiles where supported. Declaring the additional controls a service needs makes its security requirements easier to maintain and review.

Potential impact

  • Missing additional controls can leave a service's security requirements unmet.
  • Service-specific runtime controls can be harder to apply consistently.
  • Different host defaults can provide different protection for the same service.

Remediation

  • Declare the security_opt settings needed by the service.
  • Select and apply options such as no-new-privileges, AppArmor or SELinux according to the environment.
  • Keep development and production configurations separate when their security options differ.

Examples

Replace sample/webapp:latest with the actual image and check that the host supports the selected option.

Before

yaml
services:
  webapp:
    image: sample/webapp:latest
    ports:
      - "8080:8080"

After

yaml
services:
  webapp:
    image: sample/webapp:latest
    ports:
      - "8080:8080"
    security_opt:
      - no-new-privileges:true

Explanation:

  • Before: No additional security options are declared. Check the actual runtime settings to determine which default protections apply.
  • After: no-new-privileges prevents a program from gaining new privileges during execution through mechanisms such as setuid or file capabilities. It does not remove root privileges or capabilities the process already holds.

References