intermediatePart 8
Move the Docker daemon off root so a container escape lands on an ordinary user
· 14 min read
+
0/10
🎯 Skill path0/10 earned
Hardening self-hosted AI infra
- 1Lock down Docker networks
- 2Run containers as non-root
- 3Identity in front of every port
- 4Membership, not just an account
- 5An identity for the agent, not a key
- 6A tool server that checks who is asking
- 7Where the agent can go, not just what it can call
- 8Move the daemon off root
- 9Run the model's own code without trusting it
- 🏆A scope per tool, and a refusal clients can act on
Here is the part nobody says out loud when they tell you to add yourself to the docker group
so you can stop typing sudo.
That group is root. Not "close to root", not "root for Docker things". If you can run a container, you can read, change or delete any file on the machine — including the password file, including other people's home directories, including the files the administrator deliberately kept away from you.
No exploit required. It is one command, and it takes about four seconds.
