Description
security_opt can declare runtime security options such as AppArmor, SELinux and no-new-privileges.
Omitting security_opt does not automatically disable Docker protections such as default seccomp or AppArmor profiles where supported. Declaring the additional controls a service needs makes its security requirements easier to maintain and review.
Potential impact
- Missing additional controls can leave a service's security requirements unmet.
- Service-specific runtime controls can be harder to apply consistently.
- Different host defaults can provide different protection for the same service.
Remediation
- Declare the
security_optsettings needed by the service. - Select and apply options such as
no-new-privileges, AppArmor or SELinux according to the environment. - Keep development and production configurations separate when their security options differ.
Examples
Replace sample/webapp:latest with the actual image and check that the host supports the selected option.
Before
yaml
services:
webapp:
image: sample/webapp:latest
ports:
- "8080:8080"
After
yaml
services:
webapp:
image: sample/webapp:latest
ports:
- "8080:8080"
security_opt:
- no-new-privileges:true
Explanation:
- Before: No additional security options are declared. Check the actual runtime settings to determine which default protections apply.
- After:
no-new-privilegesprevents a program from gaining new privileges during execution through mechanisms such as setuid or file capabilities. It does not remove root privileges or capabilities the process already holds.