上传者: lz_yq
|
上传时间: 2020-04-10 08:56:43
|
文件大小: 1.72MB
|
文件类型: PDF
Docker 通用安全配置指南。
Conventions ......................................................................................................................... 9
Scoring Information ........................................................................................................................................ 9
Profile Definitions ......................................................................................................................................... 10
Acknowledgements ...................................................................................................................................... 11
Recommendations ............................................................................................................................................. 12
1 Host Configuration .................................................................................................................................... 12
1.1 Ensure a separate partition for containers has been created (Scored) .................. 12
1.2 Ensure the container host has been Hardened (Not Scored) ...................................... 14
1.3 Ensure Docker is up to date (Not Scored) .......................................................................... 16
1.4 Ensure only trusted users are allowed to control Docker daemon (Scored) ........ 18
1.5 Ensure auditing is configured for the docker daemon (Scored) ................................ 20
1.6 Ensure auditing is configured for Docker files and directories - /var/lib/docker (Scored) ................................................................................................................................................... 22
1.7 Ensure auditing is configured for Docker files and directories - /etc/docker (Scored) ................................................................................................................................................... 24
1.8 Ensure auditing is configured for Docker files and di