0
[security] Monitoring docker containers
Source: louislam/uptime-kuma#4783 · opened by @thielj
📑 I have found these related issues/pull requests • • 🛡️ Security Policy • I agree to have read this project [Security Policy]( Description Access to the docker socket is almost equivalent to a root shell, no matter if the socket is mounted read-only or made available through a (SSL) network connection. Instead of the procedure suggested [in the docs]( a much better approach would be to expose the socket through a proxy that makes only the necessary read-only API available to Uptimee Kuma through an internal docker network. I'm using [Tecnativa/docker-socket-proxy]( for that purpose. See the docs there. I'm deliberately reporting this as a "documentation bug" and not a direct vulnerability to Uptime Kuma as it requires the host system or *ANY* container or any other system having access to the exposed socket to be compromised. However, suggesting this to users who are probably unaware of the implications is simply bad practice as…
No pledges yet. Be the first to back this.
Comments
Similar requests
Integrate sablier for better monitoring of docker containers that are automatically managed
0 votes · 0 comments
Automatically add `docker` containers to be tracked
40 votes · 0 comments
Monitoring NTRIP caster service
0 votes · 0 comments
Delta / Change monitoring
0 votes · 0 comments
SMB over QUIC monitoring
0 votes · 0 comments
No comments yet.