FeatureFuel
0

[security] Monitoring docker containers

Source: louislam/uptime-kuma#4783 · opened by @thielj
📑 I have found these related issues/pull requests • • 🛡️ Security Policy • I agree to have read this project [Security Policy]( Description Access to the docker socket is almost equivalent to a root shell, no matter if the socket is mounted read-only or made available through a (SSL) network connection. Instead of the procedure suggested [in the docs]( a much better approach would be to expose the socket through a proxy that makes only the necessary read-only API available to Uptimee Kuma through an internal docker network. I'm using [Tecnativa/docker-socket-proxy]( for that purpose. See the docs there. I'm deliberately reporting this as a "documentation bug" and not a direct vulnerability to Uptime Kuma as it requires the host system or *ANY* container or any other system having access to the exposed socket to be compromised. However, suggesting this to users who are probably unaware of the implications is simply bad practice as…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests