Replies: 1 comment
-
Hello @mig5 interesting! It is the first time I come across this, so I dont think we have any documentation around that. Cheers |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Apologies if this has been asked before - I searched and couldn't find anything.
Docker supports the ability to drop all 'capabilities' and add only the ones you need (e.g NET_BIND_SERVICE, SET_UID, CHOWN, FOWNER, etc)
https://www.redhat.com/en/blog/secure-your-containers-one-weird-trick
Can you advise what capabilities Ory Hydra requires, if one were to drop all by default, and add only the required ones, as a hardening measure? Has anyone tried it?
Thanks in advance!
Beta Was this translation helpful? Give feedback.
All reactions