- In order to use a seccomp policy with a Docker container, you must be running the container on a host OS with a Linux kernel configured with seccomp support. To check this, you can search for CONFIG_SECCOMP in the kernel configuration file:
$ grep CONFIG_SECCOMP= /boot/config-$(uname -r)CONFIG_SECCOMP=y
- Now that we've verified that seccomp is enabled in the Linux kernel, we can take a look at the default profile that is packaged with Docker (https://github.com/moby/moby/blob/master/profiles/seccomp/default.json). This default policy is sufficient for most needs and is fairly restrictive. If seccomp support is enabled, containers will be run with this policy.
- To further verify that seccomp is configured and Docker is able ...