@@ -24,12 +24,12 @@ running our pre-built container:
24
24
``` sh
25
25
docker run -it --net host --pid host --userns host --cap-add audit_control \
26
26
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
27
- -v /etc:/etc \
28
- -v /usr/bin/docker-containerd:/usr/bin/docker-containerd \
29
- -v /usr/bin/docker-runc:/usr/bin/docker-runc \
30
- -v /usr/lib/systemd:/usr/lib/systemd \
31
- -v /var/lib:/var/lib \
32
- -v /var/run/docker.sock:/var/run/docker.sock \
27
+ -v /etc:/etc:ro \
28
+ -v /usr/bin/docker-containerd:/usr/bin/docker-containerd:ro \
29
+ -v /usr/bin/docker-runc:/usr/bin/docker-runc:ro \
30
+ -v /usr/lib/systemd:/usr/lib/systemd:ro \
31
+ -v /var/lib:/var/lib:ro \
32
+ -v /var/run/docker.sock:/var/run/docker.sock:ro \
33
33
--label docker_bench_security \
34
34
docker/docker-bench-security
35
35
```
@@ -86,10 +86,10 @@ cd docker-bench-security
86
86
docker build --no-cache -t docker-bench-security .
87
87
docker run -it --net host --pid host --cap-add audit_control \
88
88
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
89
- -v /var/lib:/var/lib \
90
- -v /var/run/docker.sock:/var/run/docker.sock \
91
- -v /usr/lib/systemd:/usr/lib/systemd \
92
- -v /etc:/etc --label docker_bench_security \
89
+ -v /var/lib:/var/lib:ro \
90
+ -v /var/run/docker.sock:/var/run/docker.sock:ro \
91
+ -v /usr/lib/systemd:/usr/lib/systemd:ro \
92
+ -v /etc:/etc:ro --label docker_bench_security \
93
93
docker-bench-security
94
94
```
95
95
0 commit comments