mirror of
https://github.com/docker/docker-bench-security.git
synced 2025-01-18 16:22:33 +01:00
Mount volumes read only
Signed-off-by: J0WI <J0WI@users.noreply.github.com>
This commit is contained in:
parent
495a8674c4
commit
59c289eefe
2 changed files with 14 additions and 14 deletions
20
README.md
20
README.md
|
@ -24,12 +24,12 @@ running our pre-built container:
|
||||||
```sh
|
```sh
|
||||||
docker run -it --net host --pid host --userns host --cap-add audit_control \
|
docker run -it --net host --pid host --userns host --cap-add audit_control \
|
||||||
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
|
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
|
||||||
-v /etc:/etc \
|
-v /etc:/etc:ro \
|
||||||
-v /usr/bin/docker-containerd:/usr/bin/docker-containerd \
|
-v /usr/bin/docker-containerd:/usr/bin/docker-containerd:ro \
|
||||||
-v /usr/bin/docker-runc:/usr/bin/docker-runc \
|
-v /usr/bin/docker-runc:/usr/bin/docker-runc:ro \
|
||||||
-v /usr/lib/systemd:/usr/lib/systemd \
|
-v /usr/lib/systemd:/usr/lib/systemd:ro \
|
||||||
-v /var/lib:/var/lib \
|
-v /var/lib:/var/lib:ro \
|
||||||
-v /var/run/docker.sock:/var/run/docker.sock \
|
-v /var/run/docker.sock:/var/run/docker.sock:ro \
|
||||||
--label docker_bench_security \
|
--label docker_bench_security \
|
||||||
docker/docker-bench-security
|
docker/docker-bench-security
|
||||||
```
|
```
|
||||||
|
@ -87,10 +87,10 @@ cd docker-bench-security
|
||||||
docker build --no-cache -t docker-bench-security .
|
docker build --no-cache -t docker-bench-security .
|
||||||
docker run -it --net host --pid host --cap-add audit_control \
|
docker run -it --net host --pid host --cap-add audit_control \
|
||||||
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
|
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
|
||||||
-v /var/lib:/var/lib \
|
-v /var/lib:/var/lib:ro \
|
||||||
-v /var/run/docker.sock:/var/run/docker.sock \
|
-v /var/run/docker.sock:/var/run/docker.sock:ro \
|
||||||
-v /usr/lib/systemd:/usr/lib/systemd \
|
-v /usr/lib/systemd:/usr/lib/systemd:ro \
|
||||||
-v /etc:/etc --label docker_bench_security \
|
-v /etc:/etc:ro --label docker_bench_security \
|
||||||
docker-bench-security
|
docker-bench-security
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
|
@ -15,7 +15,7 @@ docker-bench-security:
|
||||||
stdin_open: true
|
stdin_open: true
|
||||||
tty: true
|
tty: true
|
||||||
volumes:
|
volumes:
|
||||||
- /var/lib:/var/lib
|
- /var/lib:/var/lib:ro
|
||||||
- /var/run/docker.sock:/var/run/docker.sock
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
- /usr/lib/systemd:/usr/lib/systemd
|
- /usr/lib/systemd:/usr/lib/systemd:ro
|
||||||
- /etc:/etc
|
- /etc:/etc:ro
|
||||||
|
|
Loading…
Reference in a new issue