turbot/docker_compliance

Query: docker_container_no_new_privileges

Usage

powerpipe query docker_compliance.query.docker_container_no_new_privileges

Steampipe Tables

SQL

select
id as resource,
case
when inspect->'HostConfig'->'SecurityOpt' @> '["no-new-privileges=false"]' then 'alarm'
else 'ok'
end as status,
case
when inspect->'HostConfig'->'SecurityOpt' @> '["no-new-privileges=false"]' then (names ->> 0) || ' new privileges are not restricted.'
else (names ->> 0) || ' new privileges are restricted.'
end as reason
, _ctx ->> 'connection_name' as connection_name
from
docker_container;

Controls

The query is being used by the following controls: