Linux Capabilities
Reducing Attack Surface: Capabilities and Build Optimization
Dropping Linux Capabilities in Container Processes
Linux capabilities allow fine-grained control over process privileges, enabling containers to perform specific actions without full root access. However, running containers with unnecessary capabilities increases the attack surface. By explicitly dropping unused capabilities using Docker's --cap-drop flag, you can limit the privileges of container processes and reduce potential exploitation vectors.
Understanding Linux Capabilities¶
Linux capabilities are a mechanism to split the traditional "root" privileges into distinct, manageable permissions. For example:
- CAP_NET_BIND_SERVICE: Allows binding to ports below 1024 (e.g., port 80).
- CAP_SETUID: Enables changing the process's user ID.
- CAP_SETGID: Enables changing the process's group ID.
Containers often inherit capabilities from the host kernel, which can be exploited if a container is compromised. Dropping unused capabilities ensures processes cannot perform unintended actions.
Using Docker's --cap-drop Flag¶
Docker allows you to explicitly drop capabilities using the --cap-drop flag. This flag removes specified capabilities from the container's effective set.
Syntax¶
Example: Dropping NET_BIND_SERVICE¶
A web server that does not need to bind to privileged ports (e.g., port 80) can safely drop CAP_NET_BIND_SERVICE:
Dropping Multiple Capabilities¶
You can drop multiple capabilities in a single command:
Common Capabilities to Drop¶
Here are common capabilities often dropped in secure containers:
- NET_BIND_SERVICE: Prevents binding to privileged ports.
- SETUID/SETGID: Limits ability to change user/group IDs.
- SYS_ADMIN: Disables system administration operations (e.g., mounting filesystems).
- CHOWN: Restricts file ownership changes.
Always audit your application's requirements before dropping capabilities. For example, a database might need CAP_NET_BIND_SERVICE to bind to a specific port, but a static website server likely does not.
Best Practices for Capability Management¶
- Start with minimal capabilities: Drop all capabilities by default and only add those explicitly required.
- Avoid over-reliance on
--cap-add: Adding capabilities should be a last resort. Prefer dropping unused ones. - Test thoroughly: Ensure dropped capabilities do not break application functionality.
- Document requirements: Track which capabilities are necessary for your workload.
Key takeaways¶
- Dropping unused Linux capabilities in containers limits potential attack vectors.
- Use
--cap-dropto remove specific privileges, such asNET_BIND_SERVICEorSETUID. - Always validate that dropped capabilities do not interfere with application behavior.
- Combine capability dropping with other security practices (e.g., non-root users, read-only filesystems) for a layered defense.
- Avoid granting unnecessary capabilities to containers, even if they are not explicitly required.