Skip to content

Commit b354514

Browse files
authored
Merge pull request #385 from J0WI/ro
Mount volumes read only
2 parents d1934b6 + 59c289e commit b354514

File tree

2 files changed

+14
-14
lines changed

2 files changed

+14
-14
lines changed

README.md

+10-10
Original file line numberDiff line numberDiff line change
@@ -24,12 +24,12 @@ running our pre-built container:
2424
```sh
2525
docker run -it --net host --pid host --userns host --cap-add audit_control \
2626
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
27-
-v /etc:/etc \
28-
-v /usr/bin/docker-containerd:/usr/bin/docker-containerd \
29-
-v /usr/bin/docker-runc:/usr/bin/docker-runc \
30-
-v /usr/lib/systemd:/usr/lib/systemd \
31-
-v /var/lib:/var/lib \
32-
-v /var/run/docker.sock:/var/run/docker.sock \
27+
-v /etc:/etc:ro \
28+
-v /usr/bin/docker-containerd:/usr/bin/docker-containerd:ro \
29+
-v /usr/bin/docker-runc:/usr/bin/docker-runc:ro \
30+
-v /usr/lib/systemd:/usr/lib/systemd:ro \
31+
-v /var/lib:/var/lib:ro \
32+
-v /var/run/docker.sock:/var/run/docker.sock:ro \
3333
--label docker_bench_security \
3434
docker/docker-bench-security
3535
```
@@ -86,10 +86,10 @@ cd docker-bench-security
8686
docker build --no-cache -t docker-bench-security .
8787
docker run -it --net host --pid host --cap-add audit_control \
8888
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
89-
-v /var/lib:/var/lib \
90-
-v /var/run/docker.sock:/var/run/docker.sock \
91-
-v /usr/lib/systemd:/usr/lib/systemd \
92-
-v /etc:/etc --label docker_bench_security \
89+
-v /var/lib:/var/lib:ro \
90+
-v /var/run/docker.sock:/var/run/docker.sock:ro \
91+
-v /usr/lib/systemd:/usr/lib/systemd:ro \
92+
-v /etc:/etc:ro --label docker_bench_security \
9393
docker-bench-security
9494
```
9595

docker-compose.yml

+4-4
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ docker-bench-security:
1515
stdin_open: true
1616
tty: true
1717
volumes:
18-
- /var/lib:/var/lib
19-
- /var/run/docker.sock:/var/run/docker.sock
20-
- /usr/lib/systemd:/usr/lib/systemd
21-
- /etc:/etc
18+
- /var/lib:/var/lib:ro
19+
- /var/run/docker.sock:/var/run/docker.sock:ro
20+
- /usr/lib/systemd:/usr/lib/systemd:ro
21+
- /etc:/etc:ro

0 commit comments

Comments
 (0)