Skip to content

Rootless Containers

Rootless Containers for Enhanced Privilege Isolation

Rootless containers are a Docker runtime configuration that isolates the Docker daemon from the host kernel's root privileges. By default, Docker runs as the root user, which exposes the host system to potential privilege escalation if the container escapes its sandbox. Rootless mode mitigates this risk by running the Docker daemon as a non-root user, thereby limiting the impact of a compromise. This section demonstrates how to configure rootless containers and the security benefits they provide.


Enabling Rootless Mode in Docker

To use rootless containers, you must configure Docker to operate in rootless mode. This requires installing Docker with rootless support and setting up the necessary user and directory permissions.

1. Install Docker with Rootless Support

On Linux, install Docker using the rootless package (available in some distributions like Fedora or via Docker's official rootless installation script):

# For systems using Docker's rootless installation script
curl -fsSL https://get.docker.com/rootless | sh

This script creates a dedicated user (e.g., docker) and sets up the required directories for rootless operation.

2. Configure the Docker Daemon

Edit the Docker daemon configuration to enable rootless mode. Create or modify /etc/docker/daemon.json with the following content:

{
  "rootless": true,
  "user": "docker"
}

This configuration tells Docker to run as the docker user and operate in rootless mode.

3. Initialize Rootless Setup

Run the Docker rootless setup script to finalize the configuration:

sudo docker-rootless-setup.sh

This script ensures the Docker user has the correct permissions and sets up the necessary environment variables.

4. Start the Docker Daemon

Restart the Docker service to apply the changes:

sudo systemctl start docker

Verify the setup by checking the Docker daemon's status:

docker info | grep "Rootless"

If rootless mode is active, this command will show Rootless: true.


Security Benefits of Rootless Containers

  • Privilege Isolation: The Docker daemon runs as a non-root user, reducing the risk of kernel-level attacks if the daemon is compromised.
  • Limited Attack Surface: Even if a container escapes its sandbox, the attacker cannot escalate privileges to the host kernel.
  • User-Specific Isolation: Each user can have their own rootless Docker environment, preventing cross-user exploitation.

Key Considerations

  • User Permissions: The Docker user must have access to necessary system resources (e.g., /var/run/docker.sock). Ensure the user is added to the docker group or configured explicitly.
  • Compatibility: Some Docker features (e.g., docker build with privileged containers) may require additional configuration or may not work in rootless mode.
  • Security Layering: Rootless mode is not a standalone solution. Combine it with seccomp, AppArmor, or SELinux policies for comprehensive protection.

Key takeaways

  • Rootless containers isolate the Docker daemon from host privileges, reducing the risk of privilege escalation.
  • Enabling rootless mode requires configuring Docker with a dedicated user and adjusting the daemon settings.
  • While rootless mode enhances security, it must be paired with other runtime protections like seccomp and AppArmor for full isolation.