Docker Security - Protect Your Containers

Security Trainings

•

Simon Izydorek

•

4h

About Training

In this training, we explore Docker from a security point of view. Participants will learn about common attack scenarios, building secure images, and runtime hardening techniques through practical examples. The training is designed to combine theoretical knowledge with real-life infrastructure scenarios.

By the end of the session, attendees will have hands-on experience applying security practices in real Docker deployments, supported by a practical security checklist for everyday development.

Exemplary content of the training in the next slides.

Training Overview

  1. Basics of Security in Containers

    1. Why a container ≠ full isolation

    2. Most common attack scenarios on containers


  2. Secure Images

    1. Choosing base images (official vs. custom)

    2. Most common mistakes in Dockerfile and their
      consequences


  3. Runtime Hardening

    1. Mechanisms --cap-drop and --cap-add (practical
      examples)

    2. Read-only filesystem and mount restrictions

    3. Design of a sample “hardened” container

    4. Private registries

As a professional cybersecurity unit, our standards for security training are high. Szymon met these expectations by delivering a session that stripped away the basics to focus entirely on advanced exploitation vectors and defense strategies.

Maksym Brzęczek - Cybersecurity Engineer, Board Member@Efigo

Container image integration with Docker, Kubernetes, and container registry services
Container image integration with Docker, Kubernetes, and container registry services
Container hardening with Jenkins, Nginx, HTTPS, and security tools
Container hardening with Jenkins, Nginx, HTTPS, and security tools

Category

Security Trainings

Duration

4h workshop

Trainer

Simon Izydorek
Simon Izydorek

Simon Izydorek

Specialization: Ansible, Docker, Kubernetes, DevSecOps, Linux, Falco.

Experience: Over 10 years in IT. Designed, implemented, and maintained infrastructure for global leaders such as Nokia, Tieto, and Thales. Regular speaker at prestigious industry conferences (DevOpsDays Aarhus, DevOpsDays Geneva, Linux Session, SO/DO Poland).

Test us in action. Book a free
consultation for your team

We don't do hard sales pitches. Let's spend 30 minutes discussing your current DevOps bottlenecks, and we'll help you map out the most efficient upskilling path for your team.

Test us in action. Book a free consultation for your team

We don't do hard sales pitches. Let's spend 30 minutes discussing your current DevOps bottlenecks, and we'll help you map out the most efficient upskilling path for your team.