World Congress 2023 • Sep 27, 2023

Turning Container security up to 11 with Capabilities

Mathias Tausig

Are default container permissions exposing your internal traffic to rogue images? Discover why dropping all Linux kernel capabilities is the ultimate way to shrink your blast radius.

Pause
Mute Enter Fullscreen
#1 about 4 min

Identifying single-host container network vulnerabilities

Unencrypted HTTP traffic between isolated containers creates potential attack vectors on a local host.

#2 about 3 min

Building a proof of concept container deployment

Docker Compose establishes a frontend and backend architecture with an auxiliary health check.

#3 about 4 min

Executing a containerized man-in-the-middle attack

A malicious image sniffs unencrypted communication between containers running on the same host.

#4 about 5 min

Moving from all-or-nothing root access to capabilities

Linux kernel capabilities split administrative privileges into targeted categories for granular access control.

#5 about 4 min

Managing file and process permissions with capability boundaries

Command line tools like filecap and pscap inspect and manage granular process permissions across the system.

#6 about 2 min

Evaluating default capabilities assigned by Docker runtimes

Analyzing the extensive list of permissions granted to standard containers reveals the danger of using privileged modes.

#7 about 2 min

Enforcing container security with capability allow-list approaches

Dropping all default capabilities and appending only essential ones enforces the principle of least privilege.

#8 about 4 min

Finding essential application capabilities through trial and error

Testing container execution failures accurately identifies required permissions like chown and setuid.

#9 about 1 min

Blocking container spoofing attacks by removing raw network access

Dropping the raw network capability successfully prevents ARP spoofing and malicious container sniffing.

#10 about 2 min

Applying capability constraints in Kubernetes pod specifications

Configuring security contexts in Kubernetes limits the blast radius during an exploit to enforce defense in depth.

#11 about 2 min

Discussing sidecar attacks and transport layer security limitations

Unencrypted traffic handled by sidecar containers introduces security gaps between standard components and mesh proxies.

Matching moments

4:27 min

Identifying software vulnerabilities and typical configuration weaknesses

Marc Nimmerrichter · World Congress 2022

2:40 min

Discussing container privilege escalation and volume security risks

Andrew Martin · World Congress 2022

4:02 min

Applying tactical security configurations to Docker container layers

Madhu Akula · LIVE

3:21 min

Restricting container privileges using capability and seccomp profiles

Marc Nimmerrichter · World Congress 2022

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

5:59 min

Live demonstration of vulnerability exploitation and zero trust mitigation

Jan Peer Stöcklmair Jan Peer Stöcklmair · World Congress 2026 Europe

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

Your registry can't stop a valid login. What happens then?

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 11

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author

Kristiyan Velkov
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 23, 2026 · 11:00–11:30

Stage 1

Docker does that? Five Docker capabilities you did not know about

Michael Irwin

Principal Engineer, Developer Success

Michael Irwin
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate at Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner