cis-docker-v170-5.6
Ensure sensitive host system directories are not mounted on containers
1.21k repo starsObserved in 1 repos
DevOps & Security
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure sensitive host system directories are not mounted on containers
Ensure sshd is not run within containers
Ensure that only needed ports are open on the container
Ensure that image sprawl is avoided
Ensure that container sprawl is avoided
Ensure that the minimum number of manager nodes have been created in a swarm
Ensure that swarm services are bound to a specific host interface
Ensure that all Docker swarm overlay networks are encrypted
Ensure that Docker's secret management commands are used for managing secrets in a swarm cluster
Ensure that swarm manager is run in auto-lock mode