4 ms·
Handing an unprivileged user access to Docker is, functionally, the same as handing them access to sudo. Once you are allowed to run arbitrary Docker containers
by manacit 10y ago
Handing an unprivileged user access to Docker is, functionally, the same as handing them access to sudo. Once you are allowed to run arbitrary Docker containers, you have limitless access to root on the running host.
For this reason, I would vastly prefer requiring sudo to communicate with a local Docker daemon. Sudo was designed for this purpose, has the proper logging and fin(er) grained access control.
- lojack 10y agoEveryone always says this, and I know security isn't a #1 priority and that it'd be a big mistake to assume Docker is secure -- but, are there any known security issues with Docker that could give sudo access to the host machine? Anything beyond the standard: "Don't trust it because its almost certainly not secure."
- Titanous 10y agoYes, you can run a privileged container that bind-mounts / on the host into the container. root.
- emmelaich 10y agoI presume that the default selinux policy in redhat7 would stop this. But that would mean using the docker version in redhat7, which tends to trail behind a little.
- manacit 10y agoThe issue, as another poster pointed out, is not that there are vulnerabilities in the Docker daemon, but that access to the socket inherently gives you access to run arbitrary containers in privileged mode. This allows you access to the full host: https://docs.docker.com/engine/reference/run/#/runtime-privilege-and-linux-capabilities https://docs.docker.com/engine/reference/run/#/runtime-privi... and everything that a normal root user can do. At present, there is no great way to mitigate this if you're tracking the official Docker releases (at least, as far as I know).