⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Docker & Containers Interview Questions Scenario 120 of 158 in Docker & Containers
Staff Infrastructure Architect Docker Container Runtime & Systems Engineering Production Scenario

Q: A security audit highlights that Docker's default seccomp profile allows over 300 system calls, including dangerous syscalls like `ptrace`, `bpf`, `keyctl`, and `perf_event_open` that have historically been exploited for kernel privilege escalation. For your public-facing Nginx reverse proxy and payment processing microservices, you must craft strict, least-privilege seccomp profiles that block unnecessary kernel interfaces, and deploy an AppArmor profile preventing unauthorized file access and raw socket creation.

Protect host kernels against zero-day container breakouts by implementing custom seccomp BPF syscall whitelisting filters and granular AppArmor mandatory access control profiles.

#Docker #Security #Seccomp #AppArmor #Linux
🎙️ Candidate Opening & Architectural Context
"Protect host kernels against zero-day container breakouts by implementing custom seccomp BPF syscall whitelisting filters and granular AppArmor mandatory access control profiles."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

Step 1

Audit Application System Calls via strace and eBPF

Trace the actual system calls executed by your microservice during startup and peak simulated workload using `strace` or BCC/bpftrace `syscount` to establish an accurate whitelist baseline.

# Trace all unique system calls executed by the application
strace -c -f -p $(docker inspect --format '{{.State.Pid}}' web-app) -- sleep 30

# Or run application under strace to capture bootstrap syscalls
docker run --rm web-app:latest strace -ff -e trace=all /app/binary 2>&1 | awk -F'(' '{print $1}' | sort -u
Pro Tip: Audit Application System Calls via strace and eBPF
Step 2

Author Custom Seccomp BPF Whitelist Profile in JSON

Create a least-privilege Seccomp profile setting `defaultAction: SCMP_ACT_ERRNO` (blocking everything by default) and explicitly allowing only essential syscalls (`read`, `write`, `epoll_wait`, `futex`, `clone3`, etc.).

{
  "defaultAction": "SCMP_ACT_ERRNO",
  "architectures": [
    "SCMP_ARCH_X86_64",
    "SCMP_ARCH_AARCH64"
  ],
  "syscalls": [
    {
      "names": [
        "read", "write", "openat", "close", "stat", "fstat",
        "lseek", "mmap", "mprotect", "munmap", "brk", "rt_sigaction",
        "rt_sigprocmask", "ioctl", "nanosleep", "epoll_create1",
        "epoll_ctl", "epoll_wait", "clone3", "futex", "exit_group"
      ],
      "action": "SCMP_ACT_ALLOW"
    }
  ]
}
Pro Tip: Author Custom Seccomp BPF Whitelist Profile in JSON
Advertisement
Step 3

Apply and Validate Seccomp Profile on Running Container

Run the container referencing the custom seccomp profile with `--security-opt seccomp=profile.json`. Test that prohibited syscalls (e.g., `sys_ptrace` or `sys_chroot`) are instantly rejected with `EPERM`.

# Run container with custom seccomp profile
docker run -d \
  --name hardened-api \
  --security-opt seccomp=./strict-seccomp.json \
  my-api:v1.0

# Test blocked syscall behavior inside the container
docker exec -it hardened-api strace -e ptrace ls
# Output: ptrace: Operation not permitted
Pro Tip: Apply and Validate Seccomp Profile on Running Container
Step 4

Enforce AppArmor Mandatory Access Control (MAC)

Deploy an AppArmor profile in `/etc/apparmor.d/docker-nginx-hardened` to restrict file read/write access strictly to `/etc/nginx` and `/usr/share/nginx/html`, denying execution of `/bin/sh` or `/usr/bin/curl`.

# Load AppArmor profile into kernel
sudo apparmor_parser -r -W /etc/apparmor.d/docker-nginx-hardened

# Run container enforcing the AppArmor profile
docker run -d \
  --security-opt apparmor=docker-nginx-hardened \
  nginx:alpine
Pro Tip: Enforce AppArmor Mandatory Access Control (MAC)
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Default container seccomp profiles leave hundreds of non-essential syscalls exposed. Deploying custom whitelist-based Seccomp profiles (`SCMP_ACT_ERRNO`) alongside AppArmor MAC profiles confines compromised applications and renders kernel privilege escalation exploits ineffective."
⚡ 60-Second Elevator Pitch Talking Points
  • W
  • e
  • h
  • a
  • r
  • d
  • e
  • n
  • e
  • d
  • o
  • u
  • r
  • i
  • n
  • t
  • e
  • r
  • n
  • e
  • t
  • -
  • f
  • a
  • c
  • i
  • n
  • g
  • c
  • o
  • n
  • t
  • a
  • i
  • n
  • e
  • r
  • t
  • i
  • e
  • r
  • a
  • g
  • a
  • i
  • n
  • s
  • t
  • k
  • e
  • r
  • n
  • e
  • l
  • z
  • e
  • r
  • o
  • -
  • d
  • a
  • y
  • s
  • b
  • y
  • a
  • u
  • d
  • i
  • t
  • i
  • n
  • g
  • r
  • u
  • n
  • t
  • i
  • m
  • e
  • s
  • y
  • s
  • c
  • a
  • l
  • l
  • s
  • w
  • i
  • t
  • h
  • e
  • B
  • P
  • F
  • a
  • n
  • d
  • g
  • e
  • n
  • e
  • r
  • a
  • t
  • i
  • n
  • g
  • s
  • t
  • r
  • i
  • c
  • t
  • S
  • e
  • c
  • c
  • o
  • m
  • p
  • B
  • P
  • F
  • w
  • h
  • i
  • t
  • e
  • l
  • i
  • s
  • t
  • p
  • r
  • o
  • f
  • i
  • l
  • e
  • s
  • .
  • P
  • r
  • o
  • h
  • i
  • b
  • i
  • t
  • i
  • n
  • g
  • d
  • a
  • n
  • g
  • e
  • r
  • o
  • u
  • s
  • s
  • y
  • s
  • c
  • a
  • l
  • l
  • s
  • l
  • i
  • k
  • e
  • `
  • p
  • t
  • r
  • a
  • c
  • e
  • `
  • a
  • n
  • d
  • `
  • b
  • p
  • f
  • `
  • c
  • o
  • m
  • b
  • i
  • n
  • e
  • d
  • w
  • i
  • t
  • h
  • A
  • p
  • p
  • A
  • r
  • m
  • o
  • r
  • f
  • i
  • l
  • e
  • s
  • y
  • s
  • t
  • e
  • m
  • c
  • o
  • n
  • f
  • i
  • n
  • e
  • m
  • e
  • n
  • t
  • g
  • u
  • a
  • r
  • a
  • n
  • t
  • e
  • e
  • s
  • t
  • h
  • a
  • t
  • e
  • v
  • e
  • n
  • i
  • f
  • r
  • e
  • m
  • o
  • t
  • e
  • c
  • o
  • d
  • e
  • e
  • x
  • e
  • c
  • u
  • t
  • i
  • o
  • n
  • o
  • c
  • c
  • u
  • r
  • s
  • ,
  • t
  • h
  • e
  • a
  • d
  • v
  • e
  • r
  • s
  • a
  • r
  • y
  • c
  • a
  • n
  • n
  • o
  • t
  • t
  • o
  • u
  • c
  • h
  • t
  • h
  • e
  • h
  • o
  • s
  • t
  • k
  • e
  • r
  • n
  • e
  • l
  • o
  • r
  • e
  • x
  • e
  • c
  • u
  • t
  • e
  • u
  • n
  • a
  • u
  • t
  • h
  • o
  • r
  • i
  • z
  • e
  • d
  • b
  • i
  • n
  • a
  • r
  • i
  • e
  • s
  • .
Advertisement
Want more Docker & Containers scenarios?
Explore our complete collection of scenario-based Docker & Containers interview runbooks.
Browse All Docker & Containers Questions →