turbot/docker_compliance

Control: 2.14 Ensure containers are restricted from acquiring new privileges

Description

By default you should restrict containers from acquiring additional privileges via suid or sgid.

Usage

Run the control in your terminal:

powerpipe control run docker_compliance.control.cis_v160_2_14

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run docker_compliance.control.cis_v160_2_14 --share

SQL

This control uses a named query:

exec_containers_no_new_privilege_disabled

Tags