- config/docker/daemon.json: Docker security hardening with logging limits and security options - config/systemd/nginx.service.d/rate-limit.conf: Nginx resource limits and connection throttling - Includes deployment instructions for container and service security
32 lines
668 B
JSON
32 lines
668 B
JSON
# Docker Daemon Security Configuration
|
|
# Deploy to: /etc/docker/daemon.json
|
|
#
|
|
# Setup commands:
|
|
# sudo cp config/docker/daemon.json /etc/docker/
|
|
# sudo systemctl restart docker
|
|
|
|
{
|
|
"log-driver": "json-file",
|
|
"log-opts": {
|
|
"max-size": "50m",
|
|
"max-file": "3"
|
|
},
|
|
"live-restore": true,
|
|
"userland-proxy": false,
|
|
"no-new-privileges": true,
|
|
"seccomp-profile": "/etc/docker/seccomp-default.json",
|
|
"default-ulimits": {
|
|
"nproc": {
|
|
"hard": 65536,
|
|
"soft": 65536
|
|
},
|
|
"nofile": {
|
|
"hard": 65536,
|
|
"soft": 65536
|
|
}
|
|
},
|
|
"storage-driver": "overlay2",
|
|
"storage-opts": [
|
|
"overlay2.override_kernel_check=true"
|
|
]
|
|
} |