Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

在Docker Compose中配置网络 | 李旭光的成长博客 #49

Open
lixuguang opened this issue Sep 20, 2023 · 0 comments
Open

在Docker Compose中配置网络 | 李旭光的成长博客 #49

lixuguang opened this issue Sep 20, 2023 · 0 comments

Comments

@lixuguang
Copy link
Owner

https://lixuguang.github.io/2022/08/02/Docker%20%E9%95%9C%E5%83%8F%E5%AE%89%E5%85%A8%E6%9C%80%E4%BD%B3%E5%AE%9E%E8%B7%B5%20/

Docker 镜像安全最佳实践Docker 和 宿主机 的设置 保证宿主机和 Docker 的版本是最新的 不要暴露 Docker 的 守护进程(daemon) 的套接字 使用 rootless 模式启动 Docker 避免使用特权容器 限制容器资源 隔离容器网络 提高容器的隔离度 将文件系统和卷设置为只读 完整的生命周期管理 限制来自容器内的系统调用 确保镜像安全 扫描和验证容器镜像 使用最小

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant