Merge pull request #6449 from timthelion/host-net-docs

Document the potential insecurity of --net host
This commit is contained in:
Sven Dowideit
2014-06-17 09:06:27 +10:00
3 changed files with 7 additions and 2 deletions
+5
View File
@@ -536,6 +536,11 @@ values.
**not** let the container reconfigure the host network stack — that
would require `--privileged=true` — but it does let container
processes open low-numbered ports like any other root process.
It also allows the container to access local network services
like D-bus. This can lead to processes in the container being
able to do unexpected things like
[restart your computer](https://github.com/dotcloud/docker/issues/6401).
You should use this option with caution.
* `--net=container:NAME_or_ID` — Tells Docker to put this container's
processes inside of the network stack that has already been created
+1 -1
View File
@@ -152,7 +152,7 @@ Supported networking modes are:
* none - no networking in the container
* bridge - (default) connect the container to the bridge via veth interfaces
* host - use the host's network stack inside the container
* host - use the host's network stack inside the container. Note: This gives the container full access to local system services such as D-bus and is therefore considered insecure.
* container - use another container's network stack
#### Mode: none