From 9e97c7a49091ba20305cf74362d7ec06e872d6e8 Mon Sep 17 00:00:00 2001 From: Bret Fisher Date: Fri, 14 Apr 2017 01:34:51 -0400 Subject: [PATCH 1/2] adding user namspace change and daemon.json example also adding .footnote css --- docs/index.html | 113 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 113 insertions(+) diff --git a/docs/index.html b/docs/index.html index 93c3ed83..8d4a1287 100644 --- a/docs/index.html +++ b/docs/index.html @@ -26,6 +26,10 @@ .remark-slide-content h1 { font-size: 50px; } .remark-slide-content h2 { font-size: 50px; } .remark-slide-content h3 { font-size: 25px; } + .footnote { + position: absolute; + bottom: 3em; + } .remark-code { font-size: 25px; } .small .remark-code { font-size: 16px; } @@ -4381,6 +4385,115 @@ class: secrets --- +class: namespaces +name: namespaces + +## Security Level Up: User Namespaces + +Lets increase the default security of containers on `node1` to run as non-root user. + +** Namespaces ** + +- Kernel feature, always on in Docker +- Fundamental part of Docker that isolates every container + +-- + +** *User* Namespaces ** (1.10+) + +- Optional additional feature +- Containers run as non-root user (UID:GID) +- Root user inside container mapped to non-root outside +- Enabled at daemon level, but only affects containers +- Selectively disabled per container with `--userns=host` +- Not the same as running non-root inside container + +--- + +class: namespaces + +## User Namespaces Caveats + +Once enabled, containers can't: +- Share PID or NET namespaces with the host (no `--pid=host` or `--network=host`) +- Use `--privileged` mode flag on docker run (unless also specifying `--userns=host`) +- Use `--read-only` container filesystem (a Linux kernel restriction) +- Use some external (volume or graph) drivers which can't do user mappings + +.footnote[ +.red[*] +This is "phase 1" of user namespaces, where all containers are same user (not ideal if you run untrusted code for others on shared hardware). One day, it'll hopefully have UID-per-container. #hardproblems] + +--- + +class: namespaces + +## Remove `node1` From Swarm + +- We need to add a startup setting to dockerd daemon to enable User Namespaces +- However *this will reset dockerd config*. Why? Because User Namespaces will make new locked down dir for docker files/settings/cache/swarm +- So, IRL, enable user-namespaces before you deploy servers +- Here we'll need add `node1` back to Swarm once we've reconfigured it + +.exercise[ + +- removes manager role, reschedules services, removes node from swarm +```bash +docker node demote node1 +docker swarm leave +ssh node2 docker node rm -f node1 +``` +] + +--- + +class: namespaces + +## Add Namespaces to daemon.json + +We need to create custom daemon config. Lets do it with JSON! + +.exercise[ + +```bash +echo '{"userns-remap": "default"}' | sudo tee /etc/docker/daemon.json +sudo systemctl restart docker +``` + +- Notice the new docker path and permissions + +```bash +docker info | grep var/lib +sudo ls -al /var/lib/docker +``` +] + +--- + +class: namespaces + +## Add `node1` Back To Swarm + +Get our manager token from another node (same token as before) + +.exercise[ +```bash +ssh node2 docker swarm join-token manager +``` +] + +- Now lets run a test container from `node1` and see the process UID + +.exercise[ +```bash +docker run -d --name lockdown alpine sleep 300 +docker top lockdown +ps aux +``` +] + +--- + ## A reminder about *scope* - Out of the box, Docker API access is "all or nothing" From 45402a28e5f5d1839b43e3a5110f62ed431bcf24 Mon Sep 17 00:00:00 2001 From: Bret Fisher Date: Fri, 14 Apr 2017 02:37:07 -0400 Subject: [PATCH 2/2] updated to preventls accidently registry delete --- docs/index.html | 27 ++++++++++++++------------- 1 file changed, 14 insertions(+), 13 deletions(-) diff --git a/docs/index.html b/docs/index.html index 8d4a1287..c6efe290 100644 --- a/docs/index.html +++ b/docs/index.html @@ -4390,7 +4390,7 @@ name: namespaces ## Security Level Up: User Namespaces -Lets increase the default security of containers on `node1` to run as non-root user. +Lets increase the default security of containers on `node3` to run as non-root user. ** Namespaces ** @@ -4420,28 +4420,27 @@ Once enabled, containers can't: - Use `--read-only` container filesystem (a Linux kernel restriction) - Use some external (volume or graph) drivers which can't do user mappings -.footnote[ -.red[*] -This is "phase 1" of user namespaces, where all containers are same user (not ideal if you run untrusted code for others on shared hardware). One day, it'll hopefully have UID-per-container. #hardproblems] +.footnote[.red[*] This is "phase 1" of user namespaces, where all containers are same user (not ideal if you run untrusted code for others on shared hardware). One day, it'll hopefully have UID-per-container. #hardproblems] --- class: namespaces -## Remove `node1` From Swarm +## Remove `node3` From Swarm - We need to add a startup setting to dockerd daemon to enable User Namespaces - However *this will reset dockerd config*. Why? Because User Namespaces will make new locked down dir for docker files/settings/cache/swarm - So, IRL, enable user-namespaces before you deploy servers -- Here we'll need add `node1` back to Swarm once we've reconfigured it +- Here we'll need add `node3` back to Swarm once we've reconfigured it +- NOTE: for this lesson, make sure `node3` doesn't have registry on it (`docker stack ps registry`). If so, pick another node .exercise[ - removes manager role, reschedules services, removes node from swarm ```bash -docker node demote node1 -docker swarm leave -ssh node2 docker node rm -f node1 +docker node demote node3 +ssh node3 docker swarm leave +docker node rm -f node3 ``` ] @@ -4456,6 +4455,7 @@ We need to create custom daemon config. Lets do it with JSON! .exercise[ ```bash +ssh node3 echo '{"userns-remap": "default"}' | sudo tee /etc/docker/daemon.json sudo systemctl restart docker ``` @@ -4472,7 +4472,7 @@ sudo ls -al /var/lib/docker class: namespaces -## Add `node1` Back To Swarm +## Add `node3` Back To Swarm Get our manager token from another node (same token as before) @@ -4480,16 +4480,17 @@ Get our manager token from another node (same token as before) ```bash ssh node2 docker swarm join-token manager ``` -] -- Now lets run a test container from `node1` and see the process UID +- Now lets run a test container from `node3` and see the process UID -.exercise[ ```bash docker run -d --name lockdown alpine sleep 300 docker top lockdown ps aux ``` + +- `exit` back to node1 when finished + ] ---