做什么
Hardens Dockerfiles,图像,以及针对 CIS Docker Basic v1.8.0 的每个容器运行时间设置:非根用户、已掉落的能力、只读根文件系统、seccomp和 AppArmor 配置文件,以及最小的多相建置,通过 docker-bench-security, Hadolint 和 Dockle 验证
技能库 智客分类:安全测试 hardening-docker-containers-for-production
Hardens Dockerfiles,图像,以及针对 CIS Docker Basic v1.8.0的每个容器运行时设置:非根用户,能力下降,只读根文件系统,seccomp和AppArmor配置,以及最小多相建构,通过docker-bench-security,Hadolint,和Dockle验证. 在为生产准备容器或多克文件时使用,或者对照CIS多克控制来审核图像和运行时的旗帜. 关键词 : Dockerfile,USER, -- cap-drop,只读取rootfs,seccomp,AppArmor,多相,哈多林特,多克. 不要用于多克守护进程自己的配置 - 使用硬化- 多克守护进程配置 .
官方网址:skills.sh
先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。
Hardens Dockerfiles,图像,以及针对 CIS Docker Basic v1.8.0 的每个容器运行时间设置:非根用户、已掉落的能力、只读根文件系统、seccomp和 AppArmor 配置文件,以及最小的多相建置,通过 docker-bench-security, Hadolint 和 Dockle 验证
- 安装或配置硬接接器容器,以达到环境的生产能力
按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Hardening Docker Containers for Production、Overview、When to Use、Prerequisites、Core Concepts、CIS Docker Benchmark Sections。 其中含规范建议的小节:分步指令。
文件分析:这是一份仅含 SKILL.md 的指令型技能,代理激活后整份正文进入上下文。
Hardens Dockerfiles, images, and per-container runtime settings against the CIS Docker Benchmark v1.8.0: non-root users, dropped capabilities, read-only root filesystem, seccomp and AppArmor profiles, and minimal multi-stage builds, validated with docker-bench-security, Hadolint, and Dockle. Use when preparing a container or Dockerfile for production, or auditing images and runtime flags against CIS Docker controls. Keywords: Dockerfile, USER, --cap-drop, read-only rootfs, seccomp, AppArmor, multi-stage, Hadolint, Dockle. Do not use for the Docker daemon's own configuration - use hardening-docker-daemon-configuration.
Hardening Docker Containers for ProductionOverviewWhen to UsePrerequisitesCore ConceptsCIS Docker Benchmark SectionsKey Hardening PrinciplesWorkflowStep 1: Harden the DockerfileUse specific digest for reproducibilityProduction stage - minimal imageCopy only necessary artifacts
· 许可:Apache-2.0
来源分类:skills.sh agent-skill
namehardening-docker-containers-for-productiondescription具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗
先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。
复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。
把 Agent Skill「hardening-docker-containers-for-production」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-a7475d9b7b797b11-%E7%94%A8%E4%BA%8E%E7%94%9F%E4%BA%A7%E7%9A%84%E5%8A%A0%E5%9B%BA%E5%A4%9A%E5%85%8B%E5%AE%B9%E5%99%A8.html 请存为 .cursor/skills/hardening-docker-containers-for-production/SKILL.md 或 .claude/skills/hardening-docker-containers-for-production/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。
npx skills add 'https://github.com/mukul975/anthropic-cybersecurity-skills' --list
npx skills add 'https://github.com/mukul975/anthropic-cybersecurity-skills' --skill 'hardening-docker-containers-for-production'
CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。
name: hardening-docker-containers-for-production description: >- Hardens Dockerfiles, images, and per-container runtime settings against the CIS Docker Benchmark v1.8.0: non-root users, dropped capabilities, read-only root filesystem, seccomp and AppArmor profiles, and minimal multi-stage builds, validated with docker-bench-security, Hadolint, and Dockle. Use when preparing a container or Dockerfile for production, or auditing images and runtime flags against CIS Docker controls. Keywords: Dockerfile, USER, --cap-drop, read-only rootfs, seccomp, AppArmor, multi-stage, Hadolint, Dockle. Do not use for the Docker daemon's own configuration - use hardening-docker-daemon-configuration. domain: cybersecurity subdomain: container-security tags:
Hardening Docker containers for production involves applying security best practices aligned with CIS Docker Benchmark v1.8.0 to minimize attack surface, prevent privilege escalation, and enforce least-privilege principles across Docker daemon, images, containers, and runtime configurations.
# Use specific digest for reproducibility
FROM python:3.12-slim@sha256:abc123... AS builder
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir --user -r requirements.txt
# Production stage - minimal image
FROM gcr.io/distroless/python3-debian12
# Copy only necessary artifacts
COPY --from=builder /root/.local /root/.local
COPY --from=builder /app /app
WORKDIR /app
# Create non-root user
USER 65534:65534
# Set read-only filesystem expectation
LABEL org.opencontainers.image.source="https://github.com/org/app"
ENTRYPOINT ["python", "app.py"]
{
"icc": false,
"log-driver": "json-file",
"log-opts": {
"max-size": "10m",
"max-file": "3"
},
"live-restore": true,
"userland-proxy": false,
"no-new-privileges": true,
"default-ulimits": {
"nofile": {
"Name": "nofile",
"Hard": 64000,
"Soft": 64000
},
"nproc": {
"Name": "nproc",
"Hard": 1024,
"Soft": 1024
}
},
"seccomp-profile": "/etc/docker/seccomp-default.json",
"tls": true,
"tlscacert": "/etc/docker/tls/ca.pem",
"tlscert": "/etc/docker/tls/server-cert.pem",
"tlskey": "/etc/docker/tls/server-key.pem",
"tlsverify": true
}
docker run -d \
--name production-app \
--read-only \
--tmpfs /tmp:rw,noexec,nosuid,size=100m \
--tmpfs /var/run:rw,noexec,nosuid,size=10m \
--cap-drop ALL \
--cap-add NET_BIND_SERVICE \
--security-opt no-new-privileges:true \
--security-opt seccomp=/etc/docker/seccomp-default.json \
--security-opt apparmor=docker-default \
--pids-limit 100 \
--memory 512m \
--memory-swap 512m \
--cpus 1.0 \
--user 65534:65534 \
--network custom-bridge \
--restart on-failure:3 \
--health-cmd "curl -f http://localhost:8080/health || exit 1" \
--health-interval 30s \
--health-timeout 10s \
--health-retries 3 \
myapp:latest
export DOCKER_CONTENT_TRUST=1
export DOCKER_CONTENT_TRUST_SERVER=https://notary.example.com
# Sign and push image
docker trust sign myregistry.com/myapp:v1.0.0
# Verify image signature before pull
docker trust inspect --pretty myregistry.com/myapp:v1.0.0
# Add audit rules for Docker files and directories
cat >> /etc/audit/rules.d/docker.rules << 'EOF'
-w /usr/bin/docker -k docker
-w /var/lib/docker -k docker
-w /etc/docker -k docker
-w /lib/systemd/system/docker.service -k docker
-w /lib/systemd/system/docker.socket -k docker
-w /etc/default/docker -k docker
-w /etc/docker/daemon.json -k docker
-w /usr/bin/containerd -k docker
-w /usr/bin/runc -k docker
EOF
systemctl restart auditd
# Run Docker Bench Security
docker run --rm --net host --pid host \
--userns host --cap-add audit_control \
-e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \
-v /etc:/etc:ro \
-v /usr/bin/containerd:/usr/bin/containerd:ro \
-v /usr/bin/runc:/usr/bin/runc:ro \
-v /usr/lib/systemd:/usr/lib/systemd:ro \
-v /var/lib:/var/lib:ro \
-v /var/run/docker.sock:/var/run/docker.sock:ro \
docker/docker-bench-security
# Lint Dockerfile
hadolint Dockerfile
# Lint built image
dockle myapp:latest
# Verify no containers running as root
docker ps -q | xargs docker inspect --format '{{.Id}}: User={{.Config.User}}'
| Control | Implementation | CIS Section | |---------|---------------|-------------| | Non-root user | USER instruction in Dockerfile | 4.1 | | Read-only rootfs | --read-only flag | 5.12 | | Drop capabilities | --cap-drop ALL | 5.3 | | Resource limits | --memory, --cpus, --pids-limit | 5.10 | | No new privileges | --security-opt no-new-privileges | 5.25 | | Content trust | DOCKER_CONTENT_TRUST=1 | 4.5 | | TLS for daemon | daemon.json TLS config | 2.6 | | Audit logging | auditd rules | 1.1 |
安全测试
人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.
安全测试
MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…
安全测试
用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.
安全测试
安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .