From 51bc75eb55b2df0d94a9f607ad6a2d32eb87d83d Mon Sep 17 00:00:00 2001 From: Ilya Dus Date: Fri, 10 Apr 2020 16:27:32 +0300 Subject: [PATCH] fix(docs): explain the need of mounting `/lib/systemd/system` folder for Ubuntu Signed-off-by: Ilya Dus --- README.md | 21 ++++++++++++++++++--- 1 file changed, 18 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 68835a0..4d74645 100644 --- a/README.md +++ b/README.md @@ -33,9 +33,8 @@ docker run -it --net host --pid host --userns host --cap-add audit_control \ docker/docker-bench-security ``` -Don't forget to adjust the shared volumes according to your operating system, -for example `Docker Desktop` on macOS don't have `/usr/lib/systemd` or the above -Docker binaries. +Don't forget to adjust the shared volumes according to your operating system. Some examples are: +1. `Docker Desktop` on macOS don't have `/usr/lib/systemd` or the above Docker binaries. ```sh docker run -it --net host --pid host --userns host --cap-add audit_control \ @@ -48,6 +47,22 @@ docker run -it --net host --pid host --userns host --cap-add audit_control \ docker/docker-bench-security ``` +2. On Ubuntu the `docker.service` and `docker.secret` files are located in `/lib/systemd/system` folder by default. + +```sh +docker run -it --net host --pid host --userns host --cap-add audit_control \ + -e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \ + -v /etc:/etc:ro \ + -v /lib/systemd/system:/lib/systemd/system:ro \ + -v /usr/bin/docker-containerd:/usr/bin/docker-containerd:ro \ + -v /usr/bin/docker-runc:/usr/bin/docker-runc:ro \ + -v /usr/lib/systemd:/usr/lib/systemd:ro \ + -v /var/lib:/var/lib:ro \ + -v /var/run/docker.sock:/var/run/docker.sock:ro \ + --label docker_bench_security \ + docker/docker-bench-security +``` + Docker bench requires Docker 1.13.0 or later in order to run. Note that when distributions doesn't contain `auditctl`, the audit tests will