turbot/docker_compliance

Control: 2.16 Ensure Userland Proxy is Disabled

Description

The Docker daemon starts a userland proxy service for port forwarding whenever a port is exposed. Where hairpin NAT is available, this service is generally superfluous to requirements and can be disabled.

Usage

Run the control in your terminal:

powerpipe control run docker_compliance.control.cis_v160_2_16

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run docker_compliance.control.cis_v160_2_16 --share

SQL

This control uses a named query:

exec_userland_proxy_disabled

Tags