mirror of
https://github.com/clearlinux/docker.git
synced 2026-09-28 17:10:09 +00:00
Merge pull request #6449 from timthelion/host-net-docs
Document the potential insecurity of --net host
This commit is contained in:
@@ -536,6 +536,11 @@ values.
|
||||
**not** let the container reconfigure the host network stack — that
|
||||
would require `--privileged=true` — but it does let container
|
||||
processes open low-numbered ports like any other root process.
|
||||
It also allows the container to access local network services
|
||||
like D-bus. This can lead to processes in the container being
|
||||
able to do unexpected things like
|
||||
[restart your computer](https://github.com/dotcloud/docker/issues/6401).
|
||||
You should use this option with caution.
|
||||
|
||||
* `--net=container:NAME_or_ID` — Tells Docker to put this container's
|
||||
processes inside of the network stack that has already been created
|
||||
|
||||
@@ -152,7 +152,7 @@ Supported networking modes are:
|
||||
|
||||
* none - no networking in the container
|
||||
* bridge - (default) connect the container to the bridge via veth interfaces
|
||||
* host - use the host's network stack inside the container
|
||||
* host - use the host's network stack inside the container. Note: This gives the container full access to local system services such as D-bus and is therefore considered insecure.
|
||||
* container - use another container's network stack
|
||||
|
||||
#### Mode: none
|
||||
|
||||
Reference in New Issue
Block a user