Published Sep 3, 2019

SE-Radio Episode 290: Diogo Mónica on Docker Security

Join Diogo Mónica as he details Docker's transformative journey from a security risk to a leading secure container platform, diving into Linux Kernel security, namespaces, and Docker's robust security features that emphasize secure defaults and simplified processes.
Episode Highlights
Software Engineering Radio - the podcast for professional software developers logo

Popular Clips

Episode Highlights

  • Namespaces & Capabilities

    Linux namespaces and capabilities are pivotal in enhancing Docker's security framework. emphasizes the importance of understanding these components, alongside control groups and security modules, to fortify Linux environments 1. By managing capabilities effectively, unnecessary permissions can be minimized, reducing potential vulnerabilities 2. notes, "There are quite a few capabilities that could have been turned off that weren't," highlighting the need for continuous evaluation and adjustment.

       

    Security Modules

    Kernel security modules like Selinux and AppArmor play a crucial role in Docker's security strategy. explains that Docker provides secure defaults for these modules, ensuring applications are safer when deployed in containers 3. He stresses that while advanced users can further tweak these settings, the default configurations already offer substantial protection. states, "We continue shipping software that just comes secure by default," underscoring Docker's commitment to security.

Related Episodes