cis-docker-5.4
Ensure that Linux kernel capabilities are restricted within containers
1.21k repo starsObserved in 1 repos
DevOps & Security
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that Linux kernel capabilities are restricted within containers
Ensure that privileged containers are not used
Ensure sensitive host system directories are not mounted on containers
Ensure sshd is not run within containers
Ensure privileged ports are not mapped within containers
Ensure that only needed ports are open on the container
Ensure that image sprawl is avoided
Ensure that container sprawl is avoided
Ensure that the minimum number of manager nodes have been created in a swarm
Ensure that swarm services are bound to a specific host interface