
Docker makes it easy to get an application running, which is why it also makes it easy to get a poorly protected one running. The short answer: the security of a server with Docker is decided in six places: who can use docker, which ports stay open, which user each container runs as, which images they come from, where the secrets are, and how much each container may use. This article is for an unmanaged VPS, where all of this is yours.
The six precautions
| Precaution | What to do | Why |
Who uses docker |
Give docker group access only to those who need it. |
In practice, whoever has it is root on the server. |
| Published ports | Publish on 127.0.0.1 (-p 127.0.0.1:8080:80) whatever an HTTPS proxy should show; leave databases out. |
Docker writes its own network rules and goes around ufw: ports and firewall. |
| The container’s user | Use USER in the Dockerfile so the application does not run as root: writing a Dockerfile. |
If someone compromises the application, they reach less. |
| Images | Prefer the official ones, pin the version instead of latest, and rebuild and update now and then. |
An old image carries the known flaws of whatever it contains. |
| Secrets | In a .env file with chmod 600, outside the repository; never in the Dockerfile or the image. |
What goes into an image stays there, and anyone who has it can read it: environment variables and secrets. |
| Limits | Set a memory limit and cap the logs (max-size and max-file in Compose). |
A runaway container should not take the server with it or fill the disk. |
Putting it into practice
|
|
|
|
Never expose Docker’s API to the Internet (the daemon’s TCP port, without authentication) and think twice before mounting /var/run/docker.sock inside a container: whoever controls that file controls the server. If a third-party program asks for it, understand why before agreeing.
|
| Make backups before touching anything. Security also means being able to recover: backing up a VPS. What runs on the VPS is yours to maintain, and our support does not install or repair third-party software: how far our support goes. |
|
Need a server of your own for your containers? Have a look at our VPS plans. See the VPS servers |
|
SEE ALSO Keeping your VPS or dedicated server secure: the six that matter |
RECOMMENDED PRODUCT VPS server with root access Resources of your own, the OS you choose, reinstall whenever you like. from $8.40/mo (3-year plan, with coupon) See plans |
- 0 Users Found This Useful











