Architecting Docker Seccomp & AppArmor Profiles (4019)
Technical Overview
Engineering breakdown of Architecting Docker Seccomp & AppArmor Profiles (4019). Bare-metal hardware performance requires isolated kernel parameters, syscall filtering, and mandatory access control (MAC) to achieve zero-trust container runtime security. This guide covers profile generation, syscall allow-listing, AppArmor policy composition, and CI/CD integration for immutable infrastructure.
Seccomp Architecture
Seccomp (Secure Computing Mode) operates at the kernel level, intercepting syscalls via BPF (Berkeley Packet Filter) programs. Docker's default seccomp profile blocks ~44 syscalls (e.g., keyctl, add_key, request_key) while allowing essential ones. Custom profiles use defaultAction: SCMP_ACT_ERRNO with errno 1 (EPERM) for deny-by-default, then whitelist required syscalls per container workload.
AppArmor Profile Design
AppArmor confines capabilities via path-based rules. A profile defines capability, file, network, and mount rules. For Docker, the profile loads at container start via --security-opt apparmor=profile-name. Profiles are stored in /etc/apparmor.d/ and compiled into the kernel. Use aa-genprof and aa-logprof to iteratively build profiles from audit logs.
Profile Generation & Testing
Automate profile creation with docker run --security-opt seccomp=unconfined --cap-add=SYS_ADMIN to trace syscalls via strace -f -e trace=all. Feed traces into oci-seccomp-bpf-hook for BPF compilation. Validate with seccomp-tools and apparmor_parser -Q. Integrate into CI: fail builds if audit.log shows DENIED messages after profile application.
Production Hardening
- Enable
no-new-privilegesflag to prevent privilege escalation via setuid binaries. - Drop all capabilities (
--cap-drop=ALL) then add only required (e.g.,CAP_NET_BIND_SERVICE). - Use read-only root filesystem (
--read-only) with tmpfs for writable paths. - Enforce seccomp
SCMP_ACT_LOGfor observability before switching toSCMP_ACT_ERRNO.
Observability & Continuous Auditing
Deploy Falco or Tetragon for runtime syscall monitoring. Correlate seccomp/AppArmor denials with MITRE ATT&CK techniques (e.g., T1068 Exploitation for Privilege Escalation). Export metrics to Prometheus: seccomp_denied_total{profile="webapp", syscall="ptrace"}. Alert on anomaly spikes via Alertmanager.
eBPF/XDP kernel filter evaluates TCP/UDP frames directly on server NIC.