- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`Classification:
compliance
Framework:
cis-docker
Control:
5.24
Set up the docker integration.
It is possible to attach to a particular cgroup
when a container is instantiated. Confirming cgroup
usage would ensure that containers are running in defined cgroup
s.
System administrators typically define cgroup
s in which containers are supposed to run. If cgroup
s are not explicitly defined by the system administrator, containers run in the docker cgroup
by default. At run time, it is possible to attach a container to a different cgroup
other than the one originally defined. This usage should be monitored and confirmed, as by attaching to a different cgroup
, excess permissions and resources might be granted to the container and this can therefore prove to be a security risk.
Run this command: docker ps --quiet --all | xargs docker inspect --format '{{ .Id }}: CgroupParent={{ .HostConfig.CgroupParent }}'
This command returns the cgroup where the containers are running. If it is blank, it means that containers are running under the default docker cgroup. Any other return value indicates that the system is not configured in line with good security practice.
You should not use the --cgroup-parent
option within the docker run command unless strictly required.
None.
By default, containers run under docker cgroup
.
Version 6
18 Application Software Security Application Software Security
You should run the following command: docker ps –quiet –all | xargs docker inspect –format ‘{{ .Id }}: CgroupParent={{ .HostConfig.CgroupParent }}’ The above command returns the cgroup where the containers are running. If it is blank, it means that containers are running under the default docker cgroup. Any other return value indicates that the system is not configured in line with good security practice.