Skip to Content
Container Security
book

Container Security

by Liz Rice
April 2020
Intermediate to advanced
198 pages
5h 30m
English
O'Reilly Media, Inc.
Content preview from Container Security

Chapter 9. Breaking Container Isolation

In Chapter 4, you saw how a container is constructed and how it gets a limited view of the machine it is running on. In this chapter, you’ll see how easy it is to configure containers to run in such a way that this isolation is effectively broken.

Sometimes you will want to do this deliberately, to achieve something specific such as off-loading networking functionality to a sidecar container. In other circumstances, the ideas discussed in this chapter could be seriously compromising the security of your applications!

To start with, let’s talk about what is arguably the most insecure-by-default behavior in the container world: running as root.

Containers Run as Root by Default

Unless your container image specifies a non-root user or you specify a non-default user when you run a container, by default the container will run as root. And it’s easy to confirm that (unless you are set up with user namespaces) this is not just root inside the container but also root on the host machine.

Note

This example assumes that you are using the docker command provided by Docker. If you have installed podman, you may have followed the advice to alias docker so that it actually runs podman instead. The behavior of podman is quite different with regard to root users. I’ll come to the differences later in this chapter, but for now be aware that the following example won’t work with podman.

As a non-root user, run a shell inside an Alpine container using

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Security as Code

Security as Code

BK Sarthak Das, Virginia Chu

Publisher Resources

ISBN: 9781492056690Errata Page