Commit Graph

257 Commits

Author SHA1 Message Date
Paulo Gomes 1962410b61
Corrections based on feedback 2019-11-28 12:30:44 +00:00
Paulo Gomes 432b7c4134
Improve clarity. 2019-11-28 09:06:03 +00:00
Akihiro Suda 40747fcca7 Add "Run the Docker daemon as a non-root user (Rootless mode)"
Add "Run the Docker daemon as a non-root user (Rootless mode)":
`engine/security/rootless.md`

The content is based on https://github.com/moby/moby/blob/master/docs/rootless.md

`rootless.md` in `moby/moby` will be replaced of the link to
the `docs.docker.com` page compiled from `rootless.md` in this repo.

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2019-11-15 16:02:08 +09:00
Paulo Gomes 2adcf3bd66
Add minKernel details for ptrace
Changes brought up by commit:

1124543ca8 (diff-0ebf5796a57d68894d5550c407061035)
2019-10-29 14:51:22 +00:00
Paulo Gomes 5c0c1eed40
Remove ptrace from blocked syscalls
Update documentation to reflect that ptrace is no longer blocked on the default profile.

More information:
1124543ca8 (diff-0ebf5796a57d68894d5550c407061035)
2019-10-17 09:59:47 +01:00
Paulo Gomes d32f93ca93
Remove reference to socket and socketcall 2019-10-17 09:53:28 +01:00
Paulo Gomes 04b5f87b28
Remove socket from blocked syscalls
Socket syscalls are no longer blocked on the default profile for a while now. More information: 
dcf2632945 (diff-0ebf5796a57d68894d5550c407061035)
2019-10-17 09:44:40 +01:00
Sujay Pillai 1a684b91a1 Updated userns-remap.md (#9629)
Updated the links to solve https://github.com/docker/docker.github.io/issues/9419
2019-10-14 10:54:24 -07:00
Adrian Plata b25ec58b72 Add DCT Linux note
Signed-off-by: Adrian Plata <adrian.plata@docker.com>
2019-10-10 16:18:43 -07:00
Dawn W e5c4444db8
Merge pull request #9038 from AkihiroSuda/patch-11
Strongly recommend TLS for API socket
2019-07-23 11:18:40 -07:00
ollypom 4524319333
Merge branch 'master' into amberjack 2019-07-19 14:23:33 +00:00
Akihiro Suda b690a3213d
Strongly recommend TLS for API socket 2019-07-09 15:45:10 +09:00
Olly P 9878f22b17
Formatting nit 2019-07-02 10:00:19 +01:00
nirajrules db7d8d4b3f
The notary config file had a comma missing
Docker SA from South East
2019-07-01 18:23:21 -04:00
Jameson Hyde e7d69b14a7 Include service support for DCT in engine (#1177)
Signed-off-by: Jameson Hyde <jameson.hyde@docker.com>
2019-06-13 12:50:35 -07:00
Akihiro Suda 2778995f15
Fix dockremap calculation 2019-06-12 19:13:34 +09:00
Rajasekharan Vengalil a43165a37c
Remove redundant "be" 2019-04-06 13:57:06 -07:00
Maria Bermudez c3b0c02153
Audit branch (#8564)
* Update trust-with-remote-ucp.md

* Fix link texts

* Addresses 8446

* Update trust_delegation.md

* - Addresses 8446
- Cleans up broken links
- Fixes vague link texts

Addresses 8446

Update trust_delegation.md

* Update running_ssh_service.md

* Update running_ssh_service.md

Fixed formatting and wording. Also moved note above the code.

* Update running_ssh_service.md

Fixed typo.

* Compose: Update build docs, Add --quiet flag

* Fix destroy reference page link

Relates to https://github.com/docker/docker.github.io/pull/8441

* Rephrase Ubuntu 14.04 note

* Revert "Compose: Update build docs, Add --quiet flag"

* # This is a combination of 4 commits.
# This is the 1st commit message:

- Addresses 8446
- Cleans up broken links
- Fixes vague link texts

Addresses 8446

Update trust_delegation.md

# This is the commit message #2:

# This is a combination of 2 commits.
# This is the 1st commit message:

- Addresses 8446
- Cleans up broken links
- Fixes vague link texts

Addresses 8446

Update trust_delegation.md

# This is the commit message #2:

Update trust-with-remote-ucp.md
# This is the commit message #3:

- Addresses 8446
- Cleans up broken links
- Fixes vague link texts

# This is the commit message #4:

Fix destroy reference page link

Relates to https://github.com/docker/docker.github.io/pull/8441

* - Addresses 8446
- Cleans up broken links
- Fixes vague link texts

* Addresses 8446 with text and link cleanup.

* Update syntax language from none to bash

* Update index.md
2019-04-01 14:45:04 -04:00
Wang Jie 8a8ea7d666
Update seccomp.md 2019-03-25 09:35:26 +08:00
Maria Bermudez 7ddb16f25e
Merge pull request #8492 from scjane/patch-117
Update trust_sandbox.md
2019-03-20 19:30:42 -04:00
Maria Bermudez d4bc0df73c
Merge pull request #8491 from scjane/patch-116
Update trust_key_mng.md
2019-03-20 19:30:08 -04:00
Maria Bermudez 97abe99850
Merge pull request #8490 from scjane/patch-115
Update trust_automation.md
2019-03-20 19:29:30 -04:00
Wang Jie 1ade15fa72
Update trust_sandbox.md 2019-03-20 10:58:43 +08:00
Wang Jie 882216b114
Update trust_key_mng.md 2019-03-20 10:45:19 +08:00
Wang Jie ac03de9586
Update trust_automation.md 2019-03-20 10:30:02 +08:00
Wang Jie af6ad4fd99
Update content_trust.md 2019-03-20 10:05:15 +08:00
Wang Jie c28b4a6c4a
Update certificates.md 2019-03-15 11:11:05 +08:00
Maria Bermudez a7c76f2012
Add DTR Content trust page to related links 2019-03-14 10:09:14 -07:00
Maria Bermudez 13430936b3
Addresses 8446 2019-03-13 16:55:46 -07:00
Maria Bermudez 9cff41abd5
Merge pull request #8438 from scjane/patch-112
Update https.md
2019-03-11 11:53:41 -07:00
Maria Bermudez ef9779fe27
Update trust_delegation.md 2019-03-11 10:02:11 -07:00
Wang Jie 46cd211d3f
Update https.md 2019-03-11 14:15:56 +08:00
ollypom ed7513b2ef
Docker Client Registry URL patch 2019-03-09 19:53:07 +00:00
Maria Bermudez e0807ed29c
Merge pull request #8426 from ollypom/contenttrustpatch
Updated Content Trust Docs
2019-03-08 15:49:51 -08:00
Maria Bermudez f9c29e2125
Editorial review 2019-03-08 15:49:29 -08:00
Maria Bermudez ccbb5e2630 Revert "Revert "Merge branch 'master' of github.com:docker/docker.github.io""
This reverts commit 4b5fbbdbc9.
2019-03-08 10:53:00 -08:00
ollypom 9a00acab84
Using Docker Trust with a Notary Server with Auth 2019-03-08 16:23:06 +00:00
ollypom eb68c3d408
Added Docker Pull to the content trust verification process 2019-03-08 16:11:02 +00:00
Paige Hargrave 4b5fbbdbc9 Revert "Merge branch 'master' of github.com:docker/docker.github.io"
This reverts commit 813f45bdd7, reversing
changes made to 2349c62566.
2019-02-28 13:11:13 -05:00
L-Hudson 2234622d5f
Merge pull request #8195 from ollypom/trustwithremoteucp
Added Using DTR Trust Data with a Remote UCP
2019-02-26 07:29:42 -05:00
Eric Chiang 652674a6d5 engine/security: update apparmor docs to not unload all profiles
Fixes #8289

Signed-off-by: Eric Chiang <ericchiang@google.com>
2019-02-19 15:43:50 -08:00
ollypom 80d2051937 Updated the existing DTR Trust pages from Notary CLI to DCT CLI
Signed-off-by: ollypom <oppomeroy@gmail.com>
2019-02-09 23:44:38 +00:00
Sebastiaan van Stijn 03d5b3396d
Use consistent formatting for notes
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2019-02-09 00:49:57 +01:00
jondkent ebbceda772
Updated as certicate as expire in documented version
The current  documentation points to use a version of notary which has an expired certicate.

Updated the version of notary_autobuilds to 0.5.1 from 0.4.2.

Change the shared volume to notarycerts:/var/lib/notary/fixtures from notarycerts:/go/src/github.com/docker/notary/fixtures  as location of certificate has changed.
2019-02-07 19:45:59 +00:00
L-Hudson 7e19d7c4d3
Update trust_delegation.md
editorial crx
2019-02-05 10:35:21 -05:00
L-Hudson 45dcde622b
Update trust_delegation.md
editorial crx
2019-02-05 10:32:55 -05:00
ollypom 7b41a19159
Updated Notary Git URL, Added a Docker Client Config Section, Expanded Trust initiated documentation 2019-02-05 11:27:17 +00:00
ollypom cfec527a05 DCT Plugin is configured with Enforced not Enabled 2019-01-28 14:55:45 +00:00
L-Hudson 7cc4c2bcf6
Merge pull request #8027 from heaths/patch-1
Fix default directory path for Windows
2019-01-28 08:39:41 -05:00
L-Hudson c63a05ef5e
Merge pull request #8049 from ollypom/dctwithintheengine
Updating Docker Content Trust Documentation
2019-01-25 15:21:41 -05:00
L-Hudson 923f47c89b
Update trust_delegation.md
editorial crx
2019-01-25 15:16:44 -05:00
L-Hudson 111d449d81
Update content_trust.md
editorial crx
2019-01-25 13:04:21 -05:00
L-Hudson 333a7600b0
Update content_trust.md
editorial crx
2019-01-25 13:02:15 -05:00
Olly P 72a288caa2 Added managing Delegation Documentation 2019-01-24 11:18:11 +00:00
Olly P ae12369696
Updated following Jameson's feedback 2019-01-19 12:14:40 +00:00
Olly P e96592a6e5
Updated Content Trust Automation Doc 2019-01-18 16:05:48 +00:00
Olly P a362adfb2b
First go at Docker Trust 2019-01-18 09:48:56 +00:00
Heath Stewart e515aa26d2
Fix default directory path for Windows
As previously stated, the entire `%ProgramData%` directory would be ignored. This also uses a PowerShell syntax for which most people may not be familiar, but most often PowerShell users know how to translate from supported environment variables. The main point is to limit the directory to ignore to just docker. Many, many other applications write to `%ProgramData%`.
2019-01-15 16:59:52 -08:00
Bryan Heden 59b9141edf
Fix link in security.md
Format for "Content trust in Docker" was incorrect. Also updated the link itself to be inline with the rest of them (at the bottom of the page).
2019-01-14 10:33:07 -06:00
Anne Henmi aa92a9edc2
Merge pull request #6861 from nvcastet/patch-1
Update seccomp.md
2018-12-28 10:15:32 -07:00
L-Hudson 43a1cb05a4
Update https.md
editorial crx
2018-12-07 15:39:01 -05:00
Jonathan Springer 9f22f38fa7
Update https.cnf - Clarify extfile directions
Directions around `extfile.cnf` for client certificates was somewhat confusing.  Edited the document to clarify that a separate file was to be created, not append a line to the file that had just been created for the server.
2018-12-06 09:12:55 -05:00
Maria Bermudez 720b2e8680
Spelling fix 2018-11-07 16:36:48 -08:00
Justin I. Nevill 758952785a
HTML -> MD table w/ fixes 2018-11-07 19:31:39 -05:00
Maria Bermudez 4da484fbe8
Update content_trust.md
Converted table to markdown
2018-11-07 15:56:20 -08:00
Anne Henmi 1755ede5d9
Update content_trust.md
Fixed closing </table> tag.
2018-11-07 15:34:46 -08:00
Anne Henmi a7e7f2e89a
Update content_trust.md 2018-11-07 10:17:27 -08:00
Anne Henmi ff81152728
Update content_trust.md 2018-11-07 10:16:52 -08:00
Anne Henmi 2791870005
Update content_trust.md 2018-11-07 10:16:11 -08:00
Anne Henmi e87a26decc
Update content_trust.md 2018-11-07 10:11:23 -08:00
Anne Henmi d32723440e
Update content_trust.md 2018-11-07 10:09:17 -08:00
Anne Henmi 902c115d4d
Update content_trust.md 2018-11-07 10:04:44 -08:00
Anne Henmi 36fd87206c
Update content_trust.md 2018-11-07 10:01:22 -08:00
Anne Henmi 2a449f3886 Fixed table, hopefully. 2018-11-07 09:58:57 -08:00
Maria Bermudez d7a21d29db Merge public:master into private 2018-11-02 10:03:18 -07:00
Jan Vorwerk f045723263 Document side effect on the --userns=host flag (#7537)
* Document  side effect on the --userns=host flag

As explained in https://github.com/moby/moby/issues/34064#issuecomment-430985552

* Fixed typos & added reference to binaries with the setuid flag
2018-10-30 12:29:59 +01:00
Anne Henmi 3a5538dd99
Update content_trust.md
Incorporated @ddeyo's feedback
2018-10-25 15:28:19 -06:00
Anne Henmi 5fc2b29768
Update security.md
Incorporated @ddeyo's fixes
2018-10-25 15:23:30 -06:00
Anne Henmi 75e3c4de87
Update content_trust.md 2018-10-25 13:19:03 -06:00
Anne Henmi 3b86535170
Update security.md 2018-10-25 13:16:13 -06:00
Anne Henmi ee2172416f
Update content_trust.md 2018-10-22 16:39:25 -06:00
Anne Henmi 7cc1c3955a
Update content_trust.md
Partial incorporation of @jamesonhyde-docker's comments. Waiting for clarification on the rest.
2018-10-22 15:18:36 -06:00
Anne Henmi 503eb170b7
Update security.md
incorporated @jamesonhyde-docker's feedback.
2018-10-22 14:56:32 -06:00
Anne Henmi 5064765733 Added more on verification. 2018-10-19 08:09:29 -06:00
Anne Henmi bcf2835e83 Initial draft for user/dockerd/daemon.json complete. Need to check API docs before review. 2018-10-18 10:31:18 -06:00
Anne Henmi ea19cdbe08 More table fun. 2018-10-18 09:47:34 -06:00
Anne Henmi f415a1de99 Fixed formatting, cleaning up text a bit. 2018-10-18 09:43:45 -06:00
Anne Henmi 3397e5129c More table formatting fun. 2018-10-17 09:02:23 -06:00
Anne Henmi 1ba6e4f414 Fixed formatting, added another row for testing before completing table. 2018-10-17 09:00:03 -06:00
Anne Henmi c9296ab1c9 fixed table, again. 2018-10-17 08:53:05 -06:00
Anne Henmi e7202bbfc4 Fixed table column 2018-10-17 08:50:17 -06:00
Anne Henmi 6f8524d5fc Started working on the detailed content for the DCT plugin. 2018-10-17 08:48:40 -06:00
Anne Henmi bf9ed86856 Added more explanation, cleaned up wording. 2018-10-16 19:50:20 -06:00
Anne Henmi 1155d53225 Testing rebase. 2018-10-16 19:32:03 -06:00
Anne Henmi ddc2bb4e11 Added x-ref 2018-10-16 19:23:32 -06:00
Anne Henmi 15a8fcd60b Added x-ref. 2018-10-16 19:22:22 -06:00
Anne Henmi 6e00f1eb82 Initial blurb on engine signature verification 2018-10-16 19:15:32 -06:00
Maria Bermudez aaca9b83b5 Revert "Revert "Merge branch 'master' of github.com:docker/docs-private into test-branch-2""
This reverts commit 4c95d161ca.
2018-08-29 19:01:03 -07:00
Maria Bermudez 4c95d161ca Revert "Merge branch 'master' of github.com:docker/docs-private into test-branch-2"
This reverts commit af5f2fcc38, reversing
changes made to 338b690d26.
2018-08-29 18:37:44 -07:00
Maria Bermudez 840c167055 Revert "Revert "Merge branch 'master' of github.com:docker/docs-private into test-branch-2""
This reverts commit 14080c18bd.
2018-08-29 18:36:03 -07:00