Container name runs in privileged mode
A privileged container can take over the whole server.
Remove privileged: true from the service in docker-compose.yml, and add only the capabilities it needsReferenceThe 22 checks
Security checkrisky-containers
Each running container's settings for privileged mode, mounted volumes and user, read from the Docker socket.
It needs root for part of what it reads. The Docker socket can be read only by root and the docker group. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.
The report lists it as passed, in these words:
Container name runs in privileged mode
A privileged container can take over the whole server.
Remove privileged: true from the service in docker-compose.yml, and add only the capabilities it needsContainer name has the Docker socket mounted
Whoever controls this container controls Docker, and so the whole server.
Remove the /var/run/docker.sock volume from the service, or give it a read-only socket proxyContainer name runs as root
If the app is broken into, the attacker is root inside the container, one step from the server.
Add user: "1000:1000" to the service in docker-compose.yml, or a USER line to its Dockerfile