Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,20 @@
# Changelog

## 3.0.0 (unreleased)

**Implemented enhancements:**

- Update to CIS Docker Benchmark v1.8.0 with 118 controls, revised numbering, and removal of retired recommendations [\#59](https://github.com/dev-sec/cis-docker-benchmark/issues/59)
- Add configurable package, setuid/setgid, image-history, published-port, image-tag, and artifact-signature checks
- Extend package-index update checks to apk, yum, dnf, and zypper
- Update profile inputs, sample attributes, and migration documentation

**Fixed bugs:**

- Check running daemon arguments alongside its configuration file [\#27](https://github.com/dev-sec/cis-docker-benchmark/issues/27)
- Avoid matching image metadata as package update commands [\#80](https://github.com/dev-sec/cis-docker-benchmark/issues/80)
- Report container IDs and checked properties instead of full Docker inspect objects [\#76](https://github.com/dev-sec/cis-docker-benchmark/issues/76)

## [2.1.4](https://github.com/dev-sec/cis-docker-benchmark/tree/2.1.4) (2023-05-02)

[Full Changelog](https://github.com/dev-sec/cis-docker-benchmark/compare/2.1.3...2.1.4)
Expand Down
103 changes: 52 additions & 51 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,65 +6,66 @@

## Description

This [InSpec](https://github.com/chef/inspec) compliance profile implement the [CIS Docker 1.13.0 Benchmark](https://downloads.cisecurity.org/) in an automated way to provide security best-practice tests around Docker daemon and containers in a production environment.
This [InSpec](https://github.com/chef/inspec) compliance profile implements the [CIS Docker Benchmark v1.8.0](https://www.cisecurity.org/benchmark/docker), published July 24, 2025. It contains 118 recommendations covering Linux hosts, the Docker daemon, container images and runtime, security operations, and Swarm.

InSpec is an open-source run-time framework and rule language used to specify compliance, security, and policy requirements for testing any node in your infrastructure.

## Requirements

* at least [InSpec](http://inspec.io/) version 2.3.23
* Docker 1.13+
* InSpec 4.6.3 or later, or a compatible CINC Auditor release.
* Docker Engine on Linux. CIS v1.8.0 updates the benchmark for Docker 28.x.
* Access to the Docker CLI, daemon configuration, systemd units (where used), and audit rules on the target. Run with sufficient privileges, normally `--sudo`.
* The Docker context must point to the daemon on the audited host; a remote Docker context would mix daemon evidence with the wrong host files.

### Platform
### Assessment coverage

* Debian 8
* Ubuntu 16.04
* CentOS 7
Controls check host configuration, daemon files, auditd rules, image build histories, and container runtimes. CIS's `Manual` classification does not disable executable checks. Organizational practices without verifiable host evidence still require review.

Controls `docker-5.23` and `docker-5.24` search retained audit logs for Docker exec events. They require a running audit daemon and an execution rule for `docker_cli_path` under the `docker` audit key. The search is shared between both controls and validates that no unapproved privileged or root execs are recorded.

Set policy inputs to your approved values. `container_capadd` and `seccomp_default_profile` retain their existing defaults; `default_ulimits` makes daemon limits configurable. `docker_min_version` defaults to 28.0.0, the benchmark's target major version. `swarm_node_cert_expiry_days` and `swarm_ca_rotation_days` default to 90 days.

Container configuration checks include stopped containers. Process, published-port, and runtime health checks inspect running containers. Swarm controls apply only when the target is in Swarm mode, with manager-only checks skipped on workers. Optional files are skipped when absent.

Package checks query dpkg, rpm, or apk inside running containers. Unavailable or failed package queries skip that container with instructions to review its image SBOM manually. Setuid/setgid checks read their root filesystems through `/proc` on the host; failed filesystem queries report an evidence error. Image-history checks detect known credential patterns and verification-bypass flags; they do not establish the absence of every possible secret or validate every installed package. Control 5.28 checks image-reference policy, without pulling images or asserting that a tag matches the current registry digest.

Control 4.12 verifies each declared artifact's detached SHA-256 signature with OpenSSL and its approved RSA or EC public key. Supply target paths in `signed_artifacts`; an empty list skips verification with instructions to review signatures and provenance in the build pipeline. Docker content-trust settings are not a substitute for artifact signatures.

### Migration from 2.x

Control IDs now follow CIS v1.8.0 numbering: `host-1.1.1`, `docker-2.1`, through `docker-7.9`. Update control selections and waivers accordingly. Legacy benchmark selection and retired recommendations have been removed.

`trusted_users` replaces `trusted_user` and checks every Docker group member against the approved list. Workload requirements and security baselines are supplied through policy inputs where the resulting settings are checked automatically.

## Attributes

We use a yml attribute file to steer the configuration, the following options are available:

* `trusted_user: vagrant`
define trusted user to control Docker daemon.
* `authorization_plugin: authz-broker`
define authorization plugin to manage access to Docker daemon.
* `log_driver: syslog`
define preferable way to store logs.
* `log_opts: /syslog-address/`
define Docker daemon log-opts.
* `registry_cert_path: /etc/docker/certs.d`
directory contains various Docker registry directories.
* `registry_name: /etc/docker/certs.d/registry_hostname:port`
directory contain certificate certain Docker registry.
* `registry_ca_file: /etc/docker/certs.d/registry_hostname:port/ca.crt`
certificate file for a certain Docker registry certificate files.
* `container_user: vagrant`
define user within containers.
* `app_armor_profile: docker-default`
define apparmor profile for Docker containers.
* `selinux_profile: /label\:level\:s0-s0\:c1023/`
define SELinux profile for Docker containers.
* `container_capadd: null`
define needed capabilities for containers. example: `container_capadd: NET_ADMIN,SYS_ADMIN`
* `managable_container_number: 25`
keep number of containers on a host to a manageable total.
* `daemon_tlscacert : /etc/docker/ssl/ca.pem`
configure the certificate authority.
* `daemon_tlscert: /etc/docker/ssl/server_cert.pem`
configure the server certificate.
* `daemon_tlskey: /etc/docker/ssl/server_key.pem`
configure the server key.
* `swarm_mode: inactive`
configure the swarm mode.
* `swarm_max_manager_nodes: 3`
configure the maximum number of swarm leaders.
* `swarm_port: 2377`
configure the swarm port.
* `benchmark_version`
to execute also the old controls from previous benchmarks, e.g. set it to 1.12.0 to execute also the tests from cis-benchmark-1.12.0 (which is the default).

These settings can be overridden using an attributes file (e.g. --attrs <attributefile.yml>). See [sample_attributes.yml](sample_attributes.yml) as an example.
Use [sample_attributes.yml](sample_attributes.yml) with `--input-file sample_attributes.yml` to override these inputs:

* `trusted_users: []`: approved Docker group members; an empty list permits no members.
* `managable_container_number: 25`: maximum stopped containers retained on the host.
* `registry_cert_path: /etc/docker/certs.d`: registry certificate directory; all files below it are checked.
* `docker_daemon_config: /etc/docker/daemon.json`: effective daemon configuration file.
* `docker_daemon_path: /usr/bin/dockerd`: daemon executable to audit.
* `docker_cli_path: /usr/bin/docker`: Docker CLI client executable to audit.
* `docker_socket: /var/run/docker.sock`: Docker API Unix socket.
* `containerd_socket: /run/containerd/containerd.sock`: containerd gRPC socket.
* `authorization_plugin: authz-broker`: required daemon authorization plugin.
* `log_driver: syslog`: expected daemon log driver.
* `log_opts: syslog-address`: required remote logging option key.
* `swarm_mode: inactive`: expected Swarm state; set to `active` when Swarm is required.
* `swarm_max_manager_nodes: 3`: maximum approved number of Swarm managers.
* `swarm_port: 2377`: Swarm management port; discovery port 7946 is also checked.
* `swarm_node_cert_expiry_days: 90`: maximum Swarm node certificate lifetime in days.
* `swarm_ca_rotation_days: 90`: maximum age of the Swarm root CA certificate file in days.
* `approved_container_ports: []`: approved published container ports, such as `443/tcp`; empty permits none.
* `prohibited_packages`: list of high-risk / bloat packages prohibited in containers (`gcc`, `g++`, `gdb`, `tcpdump`, `wireshark`, `telnet`, `netcat`, `nc`).
* `whitelisted_suid_binaries`: approved setuid/setgid binaries inside containers.
* `image_max_age_days: 90`: maximum image age in days before rebuild is required.
* `allowed_unused_images_count: 5`: threshold of allowed unused/cached images before image sprawl is flagged.
* `allowed_unused_images: []`: explicit whitelist of approved unused image IDs or names (e.g. rollback images).
* `allowed_latest_tag_images: []`: images allowed to use unpinned `:latest` tags.
* `signed_artifacts: []`: artifacts with `path`, `signature`, and `public_key` paths on the target; see the sample attributes.
* `dockerfile_paths: []`: optional target Dockerfiles to inspect alongside image history.

## Usage

Expand All @@ -85,7 +86,7 @@ inspec exec cis-docker-benchmark -t ssh://user@hostname -i /path/to/key
inspec exec cis-docker-benchmark -t ssh://user@hostname -i /path/to/key --sudo

# run profile on remote host via SSH with sudo and define attribute value
inspec exec cis-docker-benchmark --attrs sample_attributes.yml
inspec exec cis-docker-benchmark --input-file sample_attributes.yml

# run profile direct from inspec supermarket
inspec supermarket exec dev-sec/cis-docker-benchmark -t ssh://user@hostname --key-files private_key --sudo
Expand All @@ -96,7 +97,7 @@ inspec supermarket exec dev-sec/cis-docker-benchmark -t ssh://user@hostname --ke
In order to verify individual controls, just provide the control ids to InSpec:

```sh
inspec exec cis-docker-benchmark --controls 'cis-docker-benchmark-1.4 cis-docker-benchmark-1.5'
inspec exec cis-docker-benchmark --controls host-1.1.3 docker-2.15
```

## Contributors + Kudos
Expand Down
Loading