保护Docker涉及多个层面 — 最小化和可信的镜像、以非root用户身份运行、漏洞扫描、密钥管理、资源和权限限制以及主机/守护进程加固。容器安全很重要,因为漏洞会影响容器和主机。
Image security
text
✓ Use MINIMAL base images (alpine, distroless) → fewer packages = smaller attack surface
✓ Use TRUSTED/official images; pin specific versions/DIGESTS (not "latest")
✓ SCAN images for vulnerabilities (Trivy, docker scout, Snyk) — in CI and regularly
✓ Keep base images UPDATED (patch known CVEs)
✓ Don't include secrets or unnecessary tools in images
