To facilitate scalability and resilience, many organizations now run applications in cloud native environments using containers and orchestration. But how do you know if the deployment is secure? This practical book examines key underlying technologies to help developers, operators, and security professionals assess security risks and determine appropriate solutions.
Author Liz Rice, VP of open source engineering at Aqua Security, looks at how the building blocks commonly used in container-based systems are constructed in Linux. You’ll understand what’s happening when you deploy containers and learn how to assess potential security risks that could affect your deployments. If you run container applications with kubectl or docker and use Linux command-line tools such as ps and grep, you’re ready to get started.
• Explore attack vectors that affect container deployments
• Dive into the Linux constructs that underpin containers
• Examine measures for hardening containers
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A practical, Linux-first explanation of how containers actually work and where their security boundaries really lie, written for developers, operators, and security professionals who already run containers but want to reason about risk instead of trusting defaults. If you use `docker` or `kubectl` and want to understand the "why" behind container isolation, this is your book.
【Book Arc】
- **Opening (~0%–10%)**: Frames the problem — cloud native deployments are everywhere, but how do you know they're secure? Introduces the audience (Ops, DevOps, DevSecOps, security pros, developers) and previews the book's structure across threats, Linux primitives, and hardening.
- **Early (~10%–32%)**: Builds the threat model. Walks through actors (external, internal, malicious, inadvertent, and even non-sentient application processes), their credentials/permissions/network access, and how attack vectors chain across a container's lifecycle — from app vulnerability to container escape to host root. Closes with guiding principles like least privilege.
- **Early–Middle (~32%–48%)**: Dives into Linux fundamentals that underpin containers: system calls, file permissions, the setuid bit, and capabilities (e.g., `CAP_NET_RAW`, `getpcaps`). Then introduces cgroups as the resource-limiting building block, including the `pid` cgroup's role against fork bombs.
- **Middle (~48%–70%)**: Continues the container construction story — namespaces, changing root directory, and how these combine to form what we call a "container." Likely covers the container runtime stack (Docker daemon, containerd, runc, CRI, CRI-O) and image considerations.
- **Late (~70%–90%)**: Moves into hardening and operational security: seccomp, strengthening container isolation, image scanning in the CI/CD pipeline, preventing vulnerable images from running, and zero-day vulnerabilities.
- **Ending (~90%–100%)**: Covers container network security — firewalls, OSI model, IP addressing for containers, network isolation, iptables, IPVS, network policies and best practices, and service mesh — before wrapping up.
【Key Takeaways】
- **Containers are just Linux processes with extra constraints** (Early–Middle): Namespaces, cgroups, and root-directory changes are the real building blocks; understanding them is what lets you assess risk rather than memorize rules.
- **Threat modeling starts with actors and their permissions** (Early): External attackers, malicious insiders, inadvertent insiders, and even application processes each carry credentials, system permissions, and network access worth auditing.
- **Attack vectors chain together** (Early): A dependency vulnerability can lead to remote code execution, then container escape, then host root — each boundary you fail to harden compounds the next.
- **Least privilege is the guiding principle** (Early): Limit credentials and permissions to the bare minimum a component needs — e.g., a product-search microservice should only have read-only access to the product database.
- **Capabilities are finer-grained than root** (Middle): Tools like `ping` use `CAP_NET_RAW` rather than full root; understanding `getpcaps` and file capabilities helps you avoid over-privileged containers.
- **Cgroups prevent resource-starvation attacks** (Middle): Memory, CPU, and `pid` limits protect against denial-of-service and fork bombs; setting them at container runtime is strongly recommended.
- **Isolation is layered, not absolute** (Late): Seccomp, namespace separation, and rootless containers each strengthen isolation, but container escape remains a real risk if configuration is weak.
- **Supply chain and network are part of the attack surface** (Late): Scanning images in CI/CD, blocking vulnerable images from running, and applying network policies/service mesh are all part of a complete posture.
【Reading Tips】
- **Skim if you know Linux internals**: The author explicitly says readers familiar with syscalls, permissions, and capabilities can skip ahead — use this to jump straight to the container-specific chapters.
- **Deep-read the threat model and attack-chain sections**: These are the conceptual backbone; the later technical chapters make more sense once you've internalized how vectors chain.
- **Run the commands yourself**: The book uses hands-on examples (`getpcaps`, cgroup files, `ping` capabilities) — reproducing them builds the mental models the author wants you to have.
- **Treat it as a mental-model builder, not a checklist**: The stated goal is to help you assess risks in *your* environment, so focus on the "why" rather than memorizing specific tool flags.
- **Pair with your own deployment**: As you read about network policies, image scanning, and isolation, map each topic back to your actual cluster configuration.
【Coverage Limits】
This guide is based on stratified excerpts covering roughly the first half of the book in detail (front matter, threat model, Linux fundamentals, cgroups) plus table-of-contents-level visibility into later chapters on isolation, image scanning, and networking. Specific technical content from the later chapters (e.g., detailed seccomp profiles, network policy YAML, service mesh internals) is not covered in the excerpts and is summarized only at the chapter-topic level.
Page 4
First Edition 2020-04-03: First Release See http://oreilly.com/catalog/errata.csp?isbn=9781492056706 for release details. The O’Reilly logo is a registered t...
o make your own assessment of potential security risks that could affect your deployments. This book primarily considers the kind of “application containers”...
at performs product search in an ecommerce application, the principle of least privilege suggests that the microservice should only have credentials that giv...
er. Let’s see how cgroups are organized. Cgroup Hierarchies There is a hierarchy of control groups for each type of resource being managed, and each hierarch...
t easier to see the effects of changing the root directory: vagrant@myhost:~$ sudo chroot alpine sh / $ ls bin etc lib mnt proc run srv tmp var dev home medi...
security. 54 | Chapter 4: Container Isolation Enter the VMM As you have just seen, in a regular setup, the kernel manages the machine’s resources directly. I...
t’s possible for them to take malicious actions, including: • adding malware or cryptomining software into the image • accessing build secrets • enumerating...
nd you found that your server has bash version 4.2-2ubuntu2.2, you might think that it is vulnerable because it’s based on bash 4.2, which is included in the...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Container Security Fundamental Technology Concepts that Protect Containerized Applications (Liz Rice) (Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Container Security Fundamental Technology Concepts that Protect Containerized Applications (Liz Rice) (Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment