SV-260934r966159_rule
V-260934
SRG-APP-000243-CTR-000595
CNTR-MK-001010
CAT II
10
Start the containers using the following:
docker run --rm -it --security-opt=no-new-privileges <image>
A reference for the Docker run command can be found at https://docs.docker.com/engine/reference/run/.
no-new-privileges command information can be found here: https://docs.mirantis.com/mke/3.7/install/plan-deployment/mcr-considerations/no-new-privileges.html.
This check must be executed on all nodes in an MKE cluster to ensure all containers are restricted from acquiring additional privileges.
Via CLI:
Linux: As an MKE Admin, execute the following command using a Universal Control Plane (MKE) client bundle:
docker ps --quiet --all | xargs -L 1 docker inspect --format '{{ .Id }}: SecurityOpt={{ .HostConfig.SecurityOpt }}'
The above command returns the security options currently configured for the running containers. If the "SecurityOpt=" setting does not include the "no-new-privileges" flag, this is a finding.
V-260934
False
CNTR-MK-001010
This check must be executed on all nodes in an MKE cluster to ensure all containers are restricted from acquiring additional privileges.
Via CLI:
Linux: As an MKE Admin, execute the following command using a Universal Control Plane (MKE) client bundle:
docker ps --quiet --all | xargs -L 1 docker inspect --format '{{ .Id }}: SecurityOpt={{ .HostConfig.SecurityOpt }}'
The above command returns the security options currently configured for the running containers. If the "SecurityOpt=" setting does not include the "no-new-privileges" flag, this is a finding.
M
5595