Introduction to Docker Security
Kun for medlemmerIn this training session, we explore Docker from the security point of view. Participants will complete seven hands‑on exercises covering image scanning, container monitoring, runtime hardening, and private registry setup.
The training is designed to combine theoretical knowledge with real-life infrastructure scenarios. By the end of the session, attendees will have hands-on experience applying security practices in real Docker deployments, supported by a practical security checklist for everyday development.
Here's what you'll learn:
● Write secure run scripts using flags like --cap-add and --cap-drop
● Understand privilege risks and why --privileged is dangerous
● Monitor containers with Checkmk
● Audit infrastructure using Docker Bench for Security
● Build a private registry for secure image storage
● Design a secure supply chain integrating scanning, registries, and CI/CD
● Avoid common Dockerfile mistakes that lead to vulnerabilities
Level
Beginner/Regular/Mid
Requirements
No later than 12 days before the course you will receive instructions how to set up the necessary infrastructure before training.
Extra info
This session dives into the Docker security aspects. Consequently, out of scope are topics such as Kubernetes or Linux engineering.
Target group
DevOps Engineers, IT beginners, Cloud Engineers, Linux Administrators, Sysadmins, Cloud Engineers, Platform Engineers
Trainer
The training is conducted by Szymon Izydorek - an instructor in DevOps, Linux, and Cloud Engineering. He founded 'BecomeDevOps,' a company dedicated to helping aspiring engineers enter the IT industry.
Simon regularly shares his expertise through free-to-watch content on online platforms and conferences (DevOpsDays Aarhus or Linux Session), covering topics such as Ansible, Linux, certifications, and DevOps.
Language
English