docker-socket-proxy
docker-socket-proxy copied to clipboard
Update documentation/tags to make docker-socket-proxy more secure for novice users
The README.md shows this usage example:
docker container run \
-d --privileged \
--name dockerproxy \
-v /var/run/docker.sock:/var/run/docker.sock \
-p 127.0.0.1:2375:2375 \
tecnativa/docker-socket-proxy
In my optioning the example contains two security risks:
tecnativa/docker-socket-proxyon Docker Hub (link) defaults tolatest, which is already 3 years old. Please either updatelatesttag on Docker Hub to a more current version or add theedgetag to the usage example.- The example uses
-privileged, which gives a lot of permissions to the container, even though this is not required, it runs without any issue on plain Debian without the parameter. If there are exceptions, they should be noted, but--privilegedshould not be assumed to be default, and in 2024 there should be more granular options.
Combining a 3 year old image with --privileged seems to be a very insecure usage example for novice users. The project is intended to improve security, but the example seems very counter-productive.
Can you please propose a better text?
i don't think this is maintained anymore
Not really true, as we are here, but lacking some knowledge as the employee behind this is no longer working with us. Any help is appreciated.
The 1st point seems to be solved now. Latest points to a recent image and logs: haproxy version is 3.0.2-a45a8e6