cis-docker-v170-5.13
Ensure that the container's root filesystem is mounted as read only
1.21k repo starsObserved in 1 repos
DevOps & Security
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that the container's root filesystem is mounted as read only
Ensure that incoming container traffic is bound to a specific host interface
Ensure that the 'on-failure' container restart policy is set to '5'
Ensure that the host's process namespace is not shared
Ensure that the host's IPC namespace is not shared
Ensure that host devices are not directly exposed to containers
Ensure that, if applicable, an AppArmor Profile is enabled
Ensure mount propagation mode is not set to shared
Ensure that the host's UTS namespace is not shared
Ensure the default seccomp profile is not Disabled