mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
3.6 KiB
3.6 KiB
Standards Reference - Docker Container Hardening
CIS Docker Benchmark v1.8.0
Section 1: Host Configuration
- 1.1.1: Ensure a separate partition for containers has been created
- 1.1.2: Ensure only trusted users are allowed to control Docker daemon
- 1.1.3-1.1.18: Ensure Docker daemon audit configuration
Section 2: Docker Daemon Configuration
- 2.1: Run the Docker daemon as non-root user (rootless mode)
- 2.2: Ensure network traffic is restricted between containers (--icc=false)
- 2.3: Ensure logging level is set to info
- 2.4: Ensure Docker is allowed to make changes to iptables
- 2.5: Ensure insecure registries are not used
- 2.6: Ensure aufs storage driver is not used
- 2.7: Ensure TLS authentication for Docker daemon is configured
- 2.8: Ensure default ulimit is configured appropriately
- 2.9: Enable user namespace support
- 2.10: Ensure default cgroup usage has been confirmed
- 2.11: Ensure base device size is not changed until needed
- 2.12: Ensure centralized and remote logging is configured
- 2.13: Ensure live restore is enabled
- 2.14: Ensure Userland Proxy is disabled
- 2.15: Ensure daemon-wide custom seccomp profile is applied
- 2.16: Ensure experimental features are not used in production
- 2.17: Ensure containers are restricted from acquiring new privileges
Section 4: Container Images and Build Files
- 4.1: Ensure that a user for the container has been created
- 4.2: Ensure containers use trusted base images
- 4.3: Ensure unnecessary packages are not installed
- 4.4: Ensure images are scanned for vulnerabilities
- 4.5: Ensure Content trust for Docker is enabled
- 4.6: Ensure HEALTHCHECK instructions have been added to container images
- 4.7: Ensure update instructions are not used alone in the Dockerfile
- 4.8: Ensure setuid and setgid permissions are removed
- 4.9: Ensure COPY is used instead of ADD
- 4.10: Ensure secrets are not stored in Dockerfiles
- 4.11: Ensure only verified packages are installed
Section 5: Container Runtime
- 5.1: Ensure AppArmor profile is enabled
- 5.2: Ensure SELinux security options are set
- 5.3: Ensure Linux kernel capabilities are restricted
- 5.4: Ensure privileged containers are not used
- 5.5: Ensure sensitive host system directories are not mounted
- 5.6: Ensure sshd is not running within containers
- 5.7: Ensure privileged ports are not mapped within containers
- 5.8: Ensure only needed ports are open on the container
- 5.9: Ensure host network mode is not used
- 5.10: Ensure memory usage for container is limited
- 5.11: Ensure CPU priority is set appropriately
- 5.12: Ensure container root filesystem is mounted as read only
- 5.13: Ensure incoming container traffic is bound to a specific host interface
- 5.25: Ensure container is restricted from acquiring additional privileges
NIST SP 800-190 - Application Container Security Guide
Key Recommendations
- Use container-specific host OS (CoreOS, Flatcar, Bottlerocket)
- Segment container networks by sensitivity level
- Use container runtime with minimal attack surface
- Implement image signing and verification
- Harden container registries with access controls
- Monitor container runtime behavior for anomalies
OWASP Docker Security Cheat Sheet
Top Docker Security Risks
- Unrestricted container access to host resources
- Running containers in privileged mode
- Running as root inside containers
- Unverified or unscanned container images
- Exposed Docker daemon socket
- Insecure container networking
- Secrets stored in images or environment variables
- Missing resource limits
- Outdated base images with known vulnerabilities
- Insufficient logging and monitoring