cis-docker-v170-5.24
Ensure that docker exec commands are not used with the user=root option
1.21k repo starsObserved in 1 repos
DevOps & Security
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that docker exec commands are not used with the user=root option
Ensure that cgroup usage is confirmed
Ensure that the container is restricted from acquiring additional privileges
Ensure that container health is checked at runtime
Ensure that Docker commands always make use of the latest version of their image
Ensure that Docker's default bridge docker0 is not used
Ensure that the host's user namespaces are not shared
Ensure that the Docker socket is not mounted inside any containers
Ensure that Linux kernel capabilities are restricted within containers
Ensure that privileged containers are not used