Container Runtime Hardening: Rootless, Read-Only, and Fewer Capabilities
Scanning tells you what is inside the image. These four settings decide what it can do once it is running — and what breaks when you turn them on.
category
7 posts in this category.
Scanning tells you what is inside the image. These four settings decide what it can do once it is running — and what breaks when you turn them on.
Tags move underneath you and nobody tells you. Pinning digests, gating on real CVEs, emitting an SBOM, and signing what my pipeline actually built.
An access key sitting in CI secrets has no expiry and no owner. Replacing it with OIDC federation means the pipeline authenticates per run instead of carrying a permanent password.
Out of the box a cluster lets almost anything run as root with a mounted token and an open network. Three labels, one role cleanup, and a default-deny policy fix most of it.
A scanner that blocks on every historic finding gets bypassed within a week. Baselines, severity floors, and the split between fast PR checks and slow nightly ones.
The .env file I committed once, how I cleaned it up, and the boring habits that keep API keys out of git history for good.
Effective Linux hardening isn't a security checklist that makes the machine unusable. It's SSH config, patching, least privilege, and logging.