Docker Cheatsheet 06 — Docker Security
Cheatsheet: non-root user, capabilities, secrets, image scanning, runtime.
Cheatsheet: non-root user, capabilities, secrets, image scanning, runtime.
Cheatsheet: security headers, CSP, CORS, hotlink protection, request limits.
Cheatsheet: Role, RoleBinding, ServiceAccount, audit, impersonation.
Cheatsheet: auth, roles, TLS, encryption, network.
Cheatsheet: pod security admission, network policies, OPA, Falco, kyverno.
Cheatsheet: prompt injection, defenses, PII, jailbreaks.
Cheatsheet: SSH, firewall, fail2ban, auditd, sysctl, AppArmor.
Practical secret rotation: overlap windows, dual-secret support, AWS Secrets Manager rotation, application-side patterns, and the discipline that prevents incidents.
What an SBOM is, why customers ask for one in 2026, the formats (CycloneDX, SPDX), tools (syft, grype, dependency-track), and the practical adoption path.
How to use Postgres RLS for multi-tenant safety. Policies, session variables, performance considerations, and the patterns that make RLS a cheap defense-in-depth layer.