Skip to content

Linux Capabilities

Reducing Attack Surface: Capabilities and Build Optimization
Dropping Linux Capabilities in Container Processes

Linux capabilities allow fine-grained control over process privileges, enabling containers to perform specific actions without full root access. However, running containers with unnecessary capabilities increases the attack surface. By explicitly dropping unused capabilities using Docker's --cap-drop flag, you can limit the privileges of container processes and reduce potential exploitation vectors.


Understanding Linux Capabilities

Linux capabilities are a mechanism to split the traditional "root" privileges into distinct, manageable permissions. For example:
- CAP_NET_BIND_SERVICE: Allows binding to ports below 1024 (e.g., port 80).
- CAP_SETUID: Enables changing the process's user ID.
- CAP_SETGID: Enables changing the process's group ID.

Containers often inherit capabilities from the host kernel, which can be exploited if a container is compromised. Dropping unused capabilities ensures processes cannot perform unintended actions.


Using Docker's --cap-drop Flag

Docker allows you to explicitly drop capabilities using the --cap-drop flag. This flag removes specified capabilities from the container's effective set.

Syntax

docker run --cap-drop=<capability1> --cap-drop=<capability2> <image>

Example: Dropping NET_BIND_SERVICE

A web server that does not need to bind to privileged ports (e.g., port 80) can safely drop CAP_NET_BIND_SERVICE:

docker run --cap-drop=NET_BIND_SERVICE --publish 8080:80 nginx
This ensures the container cannot bind to ports below 1024, reducing the risk of privilege escalation.

Dropping Multiple Capabilities

You can drop multiple capabilities in a single command:

docker run --cap-drop=NET_BIND_SERVICE --cap-drop=SETUID --cap-drop=SETGID my-app


Common Capabilities to Drop

Here are common capabilities often dropped in secure containers:
- NET_BIND_SERVICE: Prevents binding to privileged ports.
- SETUID/SETGID: Limits ability to change user/group IDs.
- SYS_ADMIN: Disables system administration operations (e.g., mounting filesystems).
- CHOWN: Restricts file ownership changes.

Always audit your application's requirements before dropping capabilities. For example, a database might need CAP_NET_BIND_SERVICE to bind to a specific port, but a static website server likely does not.


Best Practices for Capability Management

  1. Start with minimal capabilities: Drop all capabilities by default and only add those explicitly required.
  2. Avoid over-reliance on --cap-add: Adding capabilities should be a last resort. Prefer dropping unused ones.
  3. Test thoroughly: Ensure dropped capabilities do not break application functionality.
  4. Document requirements: Track which capabilities are necessary for your workload.

Key takeaways

  • Dropping unused Linux capabilities in containers limits potential attack vectors.
  • Use --cap-drop to remove specific privileges, such as NET_BIND_SERVICE or SETUID.
  • Always validate that dropped capabilities do not interfere with application behavior.
  • Combine capability dropping with other security practices (e.g., non-root users, read-only filesystems) for a layered defense.
  • Avoid granting unnecessary capabilities to containers, even if they are not explicitly required.