Q: A security audit highlights that Docker's default seccomp profile allows over 300 system calls, including dangerous syscalls like `ptrace`, `bpf`, `keyctl`, and `perf_event_open` that have historically been exploited for kernel privilege escalation. For your public-facing Nginx reverse proxy and payment processing microservices, you must craft strict, least-privilege seccomp profiles that block unnecessary kernel interfaces, and deploy an AppArmor profile preventing unauthorized file access and raw socket creation.
Protect host kernels against zero-day container breakouts by implementing custom seccomp BPF syscall whitelisting filters and granular AppArmor mandatory access control profiles.
Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Audit Application System Calls via strace and eBPF
Trace the actual system calls executed by your microservice during startup and peak simulated workload using `strace` or BCC/bpftrace `syscount` to establish an accurate whitelist baseline.
# Trace all unique system calls executed by the application
strace -c -f -p $(docker inspect --format '{{.State.Pid}}' web-app) -- sleep 30
# Or run application under strace to capture bootstrap syscalls
docker run --rm web-app:latest strace -ff -e trace=all /app/binary 2>&1 | awk -F'(' '{print $1}' | sort -u
Author Custom Seccomp BPF Whitelist Profile in JSON
Create a least-privilege Seccomp profile setting `defaultAction: SCMP_ACT_ERRNO` (blocking everything by default) and explicitly allowing only essential syscalls (`read`, `write`, `epoll_wait`, `futex`, `clone3`, etc.).
{
"defaultAction": "SCMP_ACT_ERRNO",
"architectures": [
"SCMP_ARCH_X86_64",
"SCMP_ARCH_AARCH64"
],
"syscalls": [
{
"names": [
"read", "write", "openat", "close", "stat", "fstat",
"lseek", "mmap", "mprotect", "munmap", "brk", "rt_sigaction",
"rt_sigprocmask", "ioctl", "nanosleep", "epoll_create1",
"epoll_ctl", "epoll_wait", "clone3", "futex", "exit_group"
],
"action": "SCMP_ACT_ALLOW"
}
]
}
Apply and Validate Seccomp Profile on Running Container
Run the container referencing the custom seccomp profile with `--security-opt seccomp=profile.json`. Test that prohibited syscalls (e.g., `sys_ptrace` or `sys_chroot`) are instantly rejected with `EPERM`.
# Run container with custom seccomp profile
docker run -d \
--name hardened-api \
--security-opt seccomp=./strict-seccomp.json \
my-api:v1.0
# Test blocked syscall behavior inside the container
docker exec -it hardened-api strace -e ptrace ls
# Output: ptrace: Operation not permitted
Enforce AppArmor Mandatory Access Control (MAC)
Deploy an AppArmor profile in `/etc/apparmor.d/docker-nginx-hardened` to restrict file read/write access strictly to `/etc/nginx` and `/usr/share/nginx/html`, denying execution of `/bin/sh` or `/usr/bin/curl`.
# Load AppArmor profile into kernel
sudo apparmor_parser -r -W /etc/apparmor.d/docker-nginx-hardened
# Run container enforcing the AppArmor profile
docker run -d \
--security-opt apparmor=docker-nginx-hardened \
nginx:alpine
- W
- e
- h
- a
- r
- d
- e
- n
- e
- d
- o
- u
- r
- i
- n
- t
- e
- r
- n
- e
- t
- -
- f
- a
- c
- i
- n
- g
- c
- o
- n
- t
- a
- i
- n
- e
- r
- t
- i
- e
- r
- a
- g
- a
- i
- n
- s
- t
- k
- e
- r
- n
- e
- l
- z
- e
- r
- o
- -
- d
- a
- y
- s
- b
- y
- a
- u
- d
- i
- t
- i
- n
- g
- r
- u
- n
- t
- i
- m
- e
- s
- y
- s
- c
- a
- l
- l
- s
- w
- i
- t
- h
- e
- B
- P
- F
- a
- n
- d
- g
- e
- n
- e
- r
- a
- t
- i
- n
- g
- s
- t
- r
- i
- c
- t
- S
- e
- c
- c
- o
- m
- p
- B
- P
- F
- w
- h
- i
- t
- e
- l
- i
- s
- t
- p
- r
- o
- f
- i
- l
- e
- s
- .
- P
- r
- o
- h
- i
- b
- i
- t
- i
- n
- g
- d
- a
- n
- g
- e
- r
- o
- u
- s
- s
- y
- s
- c
- a
- l
- l
- s
- l
- i
- k
- e
- `
- p
- t
- r
- a
- c
- e
- `
- a
- n
- d
- `
- b
- p
- f
- `
- c
- o
- m
- b
- i
- n
- e
- d
- w
- i
- t
- h
- A
- p
- p
- A
- r
- m
- o
- r
- f
- i
- l
- e
- s
- y
- s
- t
- e
- m
- c
- o
- n
- f
- i
- n
- e
- m
- e
- n
- t
- g
- u
- a
- r
- a
- n
- t
- e
- e
- s
- t
- h
- a
- t
- e
- v
- e
- n
- i
- f
- r
- e
- m
- o
- t
- e
- c
- o
- d
- e
- e
- x
- e
- c
- u
- t
- i
- o
- n
- o
- c
- c
- u
- r
- s
- ,
- t
- h
- e
- a
- d
- v
- e
- r
- s
- a
- r
- y
- c
- a
- n
- n
- o
- t
- t
- o
- u
- c
- h
- t
- h
- e
- h
- o
- s
- t
- k
- e
- r
- n
- e
- l
- o
- r
- e
- x
- e
- c
- u
- t
- e
- u
- n
- a
- u
- t
- h
- o
- r
- i
- z
- e
- d
- b
- i
- n
- a
- r
- i
- e
- s
- .