Security best practices

  • Execution with non-root user
  • Start containers in read-only mode
  • Disable the setuid and setgid permissions
  • Verifying images with Docker Content Trust
  • Resource limitation
  • Disabling ping command in a container
  • AppArmor allows you to regulate permissions and access of the containers in the filesystem
  • SELinux provides a system of rules that allows you to implement access controls to the kernel resources
  • Secure Computing Mode (Seccomp) monitors kernel system calls


  • Implementing DevSecOps with Docker and Kubernetes

