{"id":1237,"date":"2020-06-17T20:46:00","date_gmt":"2020-06-17T20:46:00","guid":{"rendered":"https:\/\/jan.schnasse.org\/blog\/?p=1237"},"modified":"2026-09-28T11:38:45","modified_gmt":"2026-09-28T09:38:45","slug":"docker-security","status":"publish","type":"post","link":"https:\/\/jan.schnasse.org\/blog\/2020\/06\/17\/docker-security\/","title":{"rendered":"Docker Security"},"content":{"rendered":"<blockquote><p>There are four major areas to consider when reviewing Docker security:<\/p><\/blockquote>\n<ul>\n<li>\n<blockquote><p>the intrinsic security of the kernel and its support for namespaces and cgroups;<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>the attack surface of the Docker daemon itself;<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>loopholes in the container configuration profile, either by default, or when customized by users.<\/p><\/blockquote>\n<\/li>\n<li>\n<blockquote><p>the \u201chardening\u201d security features of the kernel and how they interact with containers.<\/p><\/blockquote>\n<\/li>\n<\/ul>\n<p><a href=\"https:\/\/docs.docker.com\/engine\/security\/security\/\">https:\/\/docs.docker.com\/engine\/security\/security\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are four major areas to consider when reviewing Docker security: the intrinsic security of the kernel and its support for namespaces and cgroups; the attack surface of the Docker daemon itself; loopholes in the container configuration profile, either by default, or when customized by users. the \u201chardening\u201d security features of the kernel and how [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1237","post","type-post","status-publish","format-standard","hentry","category-admin"],"_links":{"self":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/1237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/comments?post=1237"}],"version-history":[{"count":1,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/1237\/revisions"}],"predecessor-version":[{"id":4151,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/posts\/1237\/revisions\/4151"}],"wp:attachment":[{"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/media?parent=1237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/categories?post=1237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jan.schnasse.org\/blog\/wp-json\/wp\/v2\/tags?post=1237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}