Mount volumes read only

Signed-off-by: J0WI <J0WI@users.noreply.github.com>
This commit is contained in:
J0WI 2019-08-29 15:11:10 +02:00
parent 495a8674c4
commit 59c289eefe
2 changed files with 14 additions and 14 deletions

View file

@ -24,12 +24,12 @@ running our pre-built container:
```sh ```sh
docker run -it --net host --pid host --userns host --cap-add audit_control \ docker run -it --net host --pid host --userns host --cap-add audit_control \
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \ -e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
-v /etc:/etc \ -v /etc:/etc:ro \
-v /usr/bin/docker-containerd:/usr/bin/docker-containerd \ -v /usr/bin/docker-containerd:/usr/bin/docker-containerd:ro \
-v /usr/bin/docker-runc:/usr/bin/docker-runc \ -v /usr/bin/docker-runc:/usr/bin/docker-runc:ro \
-v /usr/lib/systemd:/usr/lib/systemd \ -v /usr/lib/systemd:/usr/lib/systemd:ro \
-v /var/lib:/var/lib \ -v /var/lib:/var/lib:ro \
-v /var/run/docker.sock:/var/run/docker.sock \ -v /var/run/docker.sock:/var/run/docker.sock:ro \
--label docker_bench_security \ --label docker_bench_security \
docker/docker-bench-security docker/docker-bench-security
``` ```
@ -87,10 +87,10 @@ cd docker-bench-security
docker build --no-cache -t docker-bench-security . docker build --no-cache -t docker-bench-security .
docker run -it --net host --pid host --cap-add audit_control \ docker run -it --net host --pid host --cap-add audit_control \
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \ -e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
-v /var/lib:/var/lib \ -v /var/lib:/var/lib:ro \
-v /var/run/docker.sock:/var/run/docker.sock \ -v /var/run/docker.sock:/var/run/docker.sock:ro \
-v /usr/lib/systemd:/usr/lib/systemd \ -v /usr/lib/systemd:/usr/lib/systemd:ro \
-v /etc:/etc --label docker_bench_security \ -v /etc:/etc:ro --label docker_bench_security \
docker-bench-security docker-bench-security
``` ```

View file

@ -15,7 +15,7 @@ docker-bench-security:
stdin_open: true stdin_open: true
tty: true tty: true
volumes: volumes:
- /var/lib:/var/lib - /var/lib:/var/lib:ro
- /var/run/docker.sock:/var/run/docker.sock - /var/run/docker.sock:/var/run/docker.sock:ro
- /usr/lib/systemd:/usr/lib/systemd - /usr/lib/systemd:/usr/lib/systemd:ro
- /etc:/etc - /etc:/etc:ro