5 ms·
Disclaimer: I work for Docker For the security enthusiasts out there, Docker 1.10 comes with some really cool Security focused additions. In particular: - Sec
by diogomonicapt 11y ago
Disclaimer: I work for Docker
For the security enthusiasts out there, Docker 1.10 comes with some really cool Security focused additions. In particular:
- Seccomp filtering: you can now use bpf to filter exactly what system calls the processes inside of your containers can use.
- Default Seccomp Profile: Using the newly added Seccomp filtering capabilities we added a default Seccomp profile that will help keep reduce the surface exposed by your kernel. For example, last month's use-after-free vuln in join_session_keyring was blocked by our current default profile.
- User Namespaces: root inside of the container isn't root outside of the container (opt-in, for now).
- Authorization Plugins: you can now write plugins for allowing or denying API requests to the daemon. For example, you could block anyone from using --privileged.
- Content Addressed Images: The new manifest format in Docker 1.10 is a full Merkle DAG, and all the downloaded content is finally content addressable.
- Support for TUF Delegations: Docker now has support for read/write TUF delegations, and as soon as notary 0.2 comes out, you will be able to use delegations to provide signing capabilities to a team of developers with no shared keys.
These are just a few of the things we've been working on, and we think these are super cool.
Checkout more details here: http://blog.docker.com/2016/02/docker-engine-1-10-security/ http://blog.docker.com/2016/02/docker-engine-1-10-security/ or me know if you have any questions.
- krat0sprakhar 11y ago> The new manifest format in Docker 1.10 is a full Merkle DAG, and all the downloaded content is finally content addressable. Can someone elaborate on this a bit more? From a CS point-of-view, sounds like a problem where a data structure came in handy but I'm not sure what it solves. Thanks!
- kordless 11y agoA simple immutable data structure can be implemented with a Merkle DAG. Merkle tree leaves store hashes of previous nodes and DAGs are directed graphs that don't loop around. Examples include simple blockchains. These structure provides immutable, versioned control of information. Containers are immutable, or like to think they are at least, so blockchains are an obvious thing to use in conjunction with deployments of said containers. At least that's what I keep telling everyone.
- tlrobinson 11y agoDo you literally mean a proof-of-work backed blockchain (like Bitcoin), or something more like git, which has a similar structure to a blockchain without the consensus mechanism? I don't see how the former would be useful to someone deploying containers, but interested to hear your thoughts in either case.
- _ikke_ 11y agoFrom the blogpost: > Image IDs now represent the content that is inside an image, in a similar way to how Git commit hashes represent the content inside commits.
- tlrobinson 11y agoI was referring to the second part of the comment: "Containers are immutable, or like to think they are at least, so blockchains are an obvious thing to use in conjunction with deployments of said containers. At least that's what I keep telling everyone."
- mikekchar 11y agoI'm pretty sure they mean that they are using Merkle DAGs. A blockchain is a Merkle DAG. The proof-of-work algorithm in Bitcoin is an algorithm for deciding how a node gets added to the blockchain. Depending on how you look at it, that algorithm is not part of what makes it a "blockchain". Admittedly people are sloppy about how they use the term "blockchain". I would prefer that people use the term Merkle DAG and forget the term "blockchain" altogether, but I think we are stuck with "blockchain" ;-)
- kordless 11y ago"People" are also sloppy about how they use the term "cloud", yet the world goes on with that concept in hand applying it to everything in site, often times in irritating ways. "Blockchain" is now a thing people can hold in their hand as a way to visualize the concept of a nearly immutable data store. That idea of storing something in an immutable way represents a shift in the way we can think about system's design. Calling it a "Merkle DAG" isn't going to kick off that insight any better than using "blockchain", but remembering what it really is and drawing the distinction with the right people can be immensely useful when trying to implement the insight.
- deleted 11y ago[deleted]
- sandGorgon 11y agoAny idea on the priority of getting a container with working systemd ? https://github.com/docker/docker/pull/5773 https://github.com/docker/docker/pull/5773 and https://github.com/docker/docker/issues/3629 https://github.com/docker/docker/issues/3629
- cyphar 11y agoDisclaimer: I work for SUSE, specifically on Docker and other container technologies. Docker containers /in principle/ do work with systemd. They are implemented as transient units when you use --exec-opt native.cgroupdriver=systemd (in your daemon's cmdline). I've been working on getting this support much better (in runC and therefore in Docker), however systemd just has bad support for many of the new cgroups when creating transient units. So really, Docker has systemd support. Systemd doesn't have decent support for all of the cgroup knobs that libcontainer needs (not to mention that systemd has no support for namespaces). I'd recommend pushing systemd to improve their transient unit knobs. But I'd rather like to know why the standard cgroupfs driver doesn't fulfil your needs? The main issues we've had with systemd was that it seems to have a mind of it's own (it randomly swaps cgroups and has its own ideas about how things should be run).
- sandGorgon 11y agoim not sure if we are talking the same thing here. I'm talking about systemd inside a container (as pid 1). I think that's the part that's not working. Every few days someone comes up with a new run script for docker (baseimage "my_init", etc). I personally use supervisord. Since systemd is already universal, might as well use that. Somebody posted this yesterday - https://news.ycombinator.com/item?id=11019143 https://news.ycombinator.com/item?id=11019143 Im already running my containers on a debian host with systemd - so that is ok. Overlayfs is still causing some problems though.
- nemothekid 11y agoWhats advantage of having a "supervisor" inside the container, rather than just "supervising" the container itself?
- jmnicolas 11y agoIt's "funny" yesterday RKT made the announcement of their version 1.0 (with emphasis on security) and today we have 2 news about Docker at the top of HN with your comment about security.
- kylequest 11y agoBy the way, you can use DockerSlim [1] to auto-generate custom seccomp profiles (in addition to shrinking your image). They are already usable, but they can be improved. Any enhancements or ideas are appreciated. [1] http://dockersl.im http://dockersl.im