Skip to content

ReferenceThe 22 checks

Risky containers

Security checkrisky-containers

What it reads

Each running container's settings for privileged mode, mounted volumes and user, read from the Docker socket.

Does it need root?

It needs root for part of what it reads. The Docker socket can be read only by root and the docker group. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • No container is privileged, has the Docker socket, or runs as root
  • No containers on this server

What it can find

Critical

Container name runs in privileged mode

A privileged container can take over the whole server.

Fix
Remove privileged: true from the service in docker-compose.yml, and add only the capabilities it needs
Critical

Container name has the Docker socket mounted

Whoever controls this container controls Docker, and so the whole server.

Fix
Remove the /var/run/docker.sock volume from the service, or give it a read-only socket proxy
Warning

Container name runs as root

If the app is broken into, the attacker is root inside the container, one step from the server.

Fix
Add user: "1000:1000" to the service in docker-compose.yml, or a USER line to its Dockerfile