Control: 1.1.1 Ensure a separate partition for containers has been created
Description
All Docker containers and their data and metadata is stored under /var/lib/docker
directory. By default, /var/lib/docker
should be mounted under either the /
or /var
partitions dependent on how the Linux operating system in use is configured.
Remediation
For new installations, you should create a separate partition for the /var/lib/docker
mount point. For systems which have already been installed, you should use the Logical
Volume Manager (LVM) within Linux to create a new partition.
Default Value
By default, /var/lib/docker
is mounted under the /
or /var
partitions dependent on
how the OS is configured.
Usage
Run the control in your terminal:
powerpipe control run docker_compliance.control.cis_v160_1_1_1
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run docker_compliance.control.cis_v160_1_1_1 --share
SQL
This control uses a named query:
exec_separate_partition_for_containers_created