{"id":628,"date":"2024-07-22T12:36:22","date_gmt":"2024-07-22T12:36:22","guid":{"rendered":"https:\/\/dockerpros.com\/?p=628"},"modified":"2024-07-22T12:36:22","modified_gmt":"2024-07-22T12:36:22","slug":"integration-de-selinux-et-apparmor-pour-une-securite-docker-renforcee","status":"publish","type":"post","link":"https:\/\/dockerpros.com\/fr\/security\/integrating-selinux-and-apparmor-for-enhanced-docker-security\/","title":{"rendered":"Int\u00e9gration de SELinux et AppArmor pour une s\u00e9curit\u00e9 Docker renforc\u00e9e"},"content":{"rendered":"<h1>Using SELinux and AppArmor with Docker: Enhancing Container Security<\/h1>\n<p>Docker has revolutionized the way we deploy and manage applications. While it offers flexibility and scalability, running containers comes with its own security challenges. To mitigate these risks, leveraging security modules such as SELinux (Security-Enhanced Linux) and AppArmor can provide an additional layer of security for Docker containers. This article will delve into the integration of SELinux and AppArmor with Docker, providing a comprehensive understanding of their roles, configurations, and best practices.<\/p>\n<h2>Comprendre le besoin de s\u00e9curit\u00e9 renforc\u00e9e dans Docker<\/h2>\n<p>Les conteneurs partagent le noyau du syst\u00e8me d'exploitation h\u00f4te, ce qui signifie qu'une vuln\u00e9rabilit\u00e9 dans l'un <span class=\"glossaryai-tooltip glossary-term-650\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\" target=\"_blank\">conteneur<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Containers are lightweight, portable units that encapsulate software and its dependencies, enabling consistent execution across different environments. They leverage OS-level virtualization for efficiency.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> peut potentiellement compromettre l'ensemble du syst\u00e8me. Par d\u00e9faut, Docker utilise un ensemble de fonctionnalit\u00e9s de s\u00e9curit\u00e9 par d\u00e9faut, notamment les espaces de noms d'utilisateurs et les profils seccomp. Cependant, ceux-ci peuvent ne pas suffire dans les environnements \u00e0 haute s\u00e9curit\u00e9. C'est l\u00e0 qu'interviennent SELinux et AppArmor.<\/p>\n<h3>The Threat Landscape<\/h3>\n<p>Avant d'aborder SELinux et AppArmor, explorons bri\u00e8vement les menaces potentielles auxquelles sont expos\u00e9s les conteneurs Docker :<\/p>\n<ol>\n<li><strong>Privilege Escalation<\/strong>Les attaquants pourraient exploiter des vuln\u00e9rabilit\u00e9s pour obtenir des privil\u00e8ges \u00e9lev\u00e9s, ce qui pourrait compromettre l'h\u00f4te.<\/li>\n<li><strong><span class=\"glossaryai-tooltip glossary-term-650\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\" target=\"_blank\">Conteneur<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Containers are lightweight, portable units that encapsulate software and its dependencies, enabling consistent execution across different environments. They leverage OS-level virtualization for efficiency.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> Breakout<\/strong>: If a <span class=\"glossaryai-tooltip glossary-term-650\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\" target=\"_blank\">conteneur<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Containers are lightweight, portable units that encapsulate software and its dependencies, enabling consistent execution across different environments. They leverage OS-level virtualization for efficiency.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> can escape its isolation, it can access resources on the host system.<\/li>\n<li><strong>Exfiltration de donn\u00e9es<\/strong>: Les donn\u00e9es sensibles stock\u00e9es dans les conteneurs peuvent \u00eatre accessibles si des mesures de s\u00e9curit\u00e9 appropri\u00e9es ne sont pas en place.<\/li>\n<li><strong>Refus de <span class=\"glossaryai-tooltip glossary-term-681\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/service\/\" target=\"_blank\">Service<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Le service fait r\u00e9f\u00e9rence \u00e0 l'acte de fournir une assistance ou un soutien pour r\u00e9pondre \u00e0 des besoins ou des exigences sp\u00e9cifiques. Dans divers domaines, il englobe le service client, le support technique et les services professionnels, en mettant l'accent sur l'efficacit\u00e9 et la satisfaction de l'utilisateur.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/service\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span><\/strong>: Overloading system resources could lead to <span class=\"glossaryai-tooltip glossary-term-681\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/service\/\" target=\"_blank\">service<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Le service fait r\u00e9f\u00e9rence \u00e0 l'acte de fournir une assistance ou un soutien pour r\u00e9pondre \u00e0 des besoins ou des exigences sp\u00e9cifiques. Dans divers domaines, il englobe le service client, le support technique et les services professionnels, en mettant l'accent sur l'efficacit\u00e9 et la satisfaction de l'utilisateur.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/service\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> outages.<\/li>\n<\/ol>\n<h3>The Role of SELinux and AppArmor<\/h3>\n<p>SELinux et AppArmor sont des modules de s\u00e9curit\u00e9 du noyau Linux visant \u00e0 appliquer des contr\u00f4les d'acc\u00e8s. Ils fonctionnent selon le principe du moindre privil\u00e8ge, n'accordant que les permissions n\u00e9cessaires au fonctionnement des processus.<\/p>\n<ul>\n<li><strong>SELinux<\/strong>: Il utilise des contr\u00f4les d'acc\u00e8s obligatoires (MAC) et des \u00e9tiquettes pour appliquer des politiques de s\u00e9curit\u00e9 bas\u00e9es sur des r\u00e8gles d\u00e9finies par l'administrateur syst\u00e8me.<\/li>\n<li><strong>AppArmor<\/strong>Il permet aux administrateurs de d\u00e9finir des profils par application qui d\u00e9terminent les ressources auxquelles une application peut acc\u00e9der.<\/li>\n<\/ul>\n<h2>Overview of SELinux<\/h2>\n<h3>How SELinux Works<\/h3>\n<p>SELinux operates by enforcing security policies that govern how processes interact with each other and with the system. Each process is assigned a security context, which includes a user, role, type, and level. SELinux policies are defined using these contexts.<\/p>\n<h4>Modes SELinux<\/h4>\n<ol>\n<li><strong>Application<\/strong>: SELinux blocks any action that violates the policy.<\/li>\n<li><strong>Permissif<\/strong>SELinux autorise les actions mais journalise les violations pour r\u00e9vision.<\/li>\n<li><strong>Handicap\u00e9<\/strong>: SELinux est d\u00e9sactiv\u00e9.<\/li>\n<\/ol>\n<h3>Configuration de SELinux pour Docker\n\nSELinux est une fonctionnalit\u00e9 de s\u00e9curit\u00e9 importante pour les syst\u00e8mes Linux. Il fournit une m\u00e9thode pour supporter des politiques de s\u00e9curit\u00e9, y compris des contr\u00f4les d'acc\u00e8s obligatoires (MAC).\n\nDocker prend en charge SELinux, mais il n\u00e9cessite une configuration suppl\u00e9mentaire pour fonctionner correctement. Voici les \u00e9tapes \u00e0 suivre pour configurer SELinux pour Docker :\n\n1. V\u00e9rifiez si SELinux est activ\u00e9 sur votre syst\u00e8me :\n   ```\n   sestatus\n   ```\n   Si SELinux est d\u00e9sactiv\u00e9, vous pouvez l'activer en modifiant le fichier `\/etc\/selinux\/config` et en red\u00e9marrant votre syst\u00e8me.\n\n2. Installez les packages n\u00e9cessaires pour Docker et SELinux :\n   ```\n   sudo yum install docker selinux-policy-targeted\n   ```\n\n3. Configurez Docker pour utiliser SELinux :\n   ```\n   sudo mkdir -p \/etc\/docker\n   sudo tee \/etc\/docker\/daemon.json &lt;&lt;-&#039;EOF&#039;\n   {\n     &quot;selinux-enabled&quot;: true\n   }\n   EOF\n   ```\n\n4. Red\u00e9marrez le service Docker pour appliquer les changements :\n   ```\n   sudo systemctl restart docker\n   ```\n\n5. V\u00e9rifiez que Docker fonctionne correctement avec SELinux :\n   ```\n   sudo docker run --rm -it --security-opt label:disable centos:latest \/bin\/bash\n   ```\n\nSi vous rencontrez des probl\u00e8mes avec SELinux et Docker, vous pouvez consulter la documentation officielle de Docker pour plus d&#039;informations sur la configuration de SELinux avec Docker.\n\nNotez que la configuration de SELinux pour Docker peut varier en fonction de votre distribution Linux et de votre configuration sp\u00e9cifique. Assurez-vous de consulter la documentation de votre distribution pour obtenir des instructions d\u00e9taill\u00e9es sur la configuration de SELinux pour Docker.<\/h3>\n<p>Pour utiliser SELinux avec Docker, suivez ces \u00e9tapes :<\/p>\n<ol>\n<li>\n<p><strong>Installer SELinux<\/strong>Assurez-vous que SELinux est install\u00e9 et configur\u00e9 sur votre syst\u00e8me.<\/p>\n<pre><code class=\"language-bash\">sudo yum install -y selinux-policy selinux-policy-targeted<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Verify the Status<\/strong>: V\u00e9rifiez si SELinux est actif et en mode d'application.<\/p>\n<pre><code class=\"language-bash\">sestatus<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Activer SELinux pour Docker<\/strong>Par d\u00e9faut, Docker s'ex\u00e9cute dans un domaine SELinux restreint. Vous pouvez utiliser le <code>--security-opt<\/code> flag to specify SELinux settings.<\/p>\n<pre><code class=\"language-bash\">docker <span class=\"glossaryai-tooltip glossary-term-672\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/run\/\" target=\"_blank\">run<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">\"RUN\" refers to a command in various programming languages and operating systems to execute a specified program or script. It initiates processes, providing a controlled environment for task execution.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/run\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> --security-opt <span class=\"glossaryai-tooltip glossary-term-678\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/label\/\" target=\"_blank\">\u00e9tiquette<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">In data management and classification systems, a \"label\" serves as a descriptor that categorizes and identifies items. Labels enhance data organization, facilitate retrieval, and improve understanding within complex datasets.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/label\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span>:type:container_t my_image<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Labeling Files<\/strong>: When mounting host files into a <span class=\"glossaryai-tooltip glossary-term-650\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\" target=\"_blank\">conteneur<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Containers are lightweight, portable units that encapsulate software and its dependencies, enabling consistent execution across different environments. They leverage OS-level virtualization for efficiency.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span>, you may need to relabel them.<\/p>\n<pre><code class=\"language-bash\">chcon -Rt svirt_sandbox_file_t \/chemin\/vers\/r\u00e9pertoire<\/code><\/pre>\n<\/li>\n<\/ol>\n<h3>SELinux Policies for Docker<\/h3>\n<p>Les politiques SELinux d\u00e9finissent les actions autoris\u00e9es. Vous pouvez cr\u00e9er des politiques personnalis\u00e9es pour autoriser ou restreindre certaines interactions pour vos conteneurs. Voici un exemple de cr\u00e9ation d'une politique SELinux simple :<\/p>\n<ol>\n<li>\n<p><strong>Cr\u00e9er un fichier de strat\u00e9gie<\/strong> (e.g., <code>ma_politique_docker.te<\/code>):<\/p>\n<pre><code class=\"language-plaintext\">module my_docker_policy 1.0;\n\nrequire {\n   type container_t;\n   type httpd_t;\n   class tcp_socket { name_connect };\n}\n\n# Allow httpd to connect to <span class=\"glossaryai-tooltip glossary-term-661\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/network\/\" target=\"_blank\">r\u00e9seau<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">A network, in computing, refers to a collection of interconnected devices that communicate and share resources. It enables data exchange, facilitates collaboration, and enhances operational efficiency.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/network\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> sockets\nallow httpd_t container_t:tcp_socket name_connect;<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Compile and Load the Policy<\/strong>:<\/p>\n<pre><code class=\"language-bash\">checkmodule -M -m -o my_docker_policy.mod my_docker_policy.te\nsemodule_package -o my_docker_policy.pp -m my_docker_policy.mod\nsudo semodule -i my_docker_policy.pp<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Test<\/strong>: Tester pour s'assurer que la politique se comporte comme pr\u00e9vu.<\/p>\n<\/li>\n<\/ol>\n<h2>Aper\u00e7u d'AppArmor<\/h2>\n<h3>Comment AppArmor fonctionne<\/h3>\n<p>AppArmor prot\u00e8ge les applications en appliquant un profil de s\u00e9curit\u00e9 pour chaque application. Contrairement \u00e0 SELinux, qui met l'accent sur le contexte de s\u00e9curit\u00e9 du processus, AppArmor restreint les capacit\u00e9s d'un programme en fonction de son profil.<\/p>\n<h4>Profils AppArmor<\/h4>\n<p>Les profils d\u00e9finissent les fichiers, capacit\u00e9s et ressources auxquels une application peut acc\u00e9der. Les profils peuvent \u00eatre dans l'un des deux modes suivants :<\/p>\n<ol>\n<li><strong>Appliquer<\/strong>: Bloque l'acc\u00e8s non autoris\u00e9.<\/li>\n<li><strong>Complain<\/strong>Enregistre les violations sans bloquer l'acc\u00e8s.<\/li>\n<\/ol>\n<h3>Configuration d'AppArmor pour Docker<\/h3>\n<p>To use AppArmor with Docker, perform the following steps:<\/p>\n<ol>\n<li>\n<p><strong>Install AppArmor<\/strong>: Ensure that AppArmor is installed and running.<\/p>\n<pre><code class=\"language-bash\">sudo apt-get install apparmor apparmor-utils<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Activez AppArmor<\/strong>: V\u00e9rifiez si AppArmor est activ\u00e9.<\/p>\n<pre><code class=\"language-bash\">sudo aa-\u00e9tat<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Cr\u00e9er un profil<\/strong>: You can create a custom profile for your Docker <span class=\"glossaryai-tooltip glossary-term-650\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\" target=\"_blank\">conteneur<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Containers are lightweight, portable units that encapsulate software and its dependencies, enabling consistent execution across different environments. They leverage OS-level virtualization for efficiency.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span>. A simple profile might look like this:<\/p>\n<pre><code class=\"language-plaintext\">profile docker-default flags=(attach_disconnected,mediate_deleted) {\n   # Allow read access to certain directories\n   \/etc\/** r,\n   \/usr\/** r,\n\n   # Deny write access\n   deny \/** w,\n}<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Loading the Profile<\/strong>:<\/p>\n<pre><code class=\"language-bash\">sudo apparmor_parser -r \/path\/to\/docker-default<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Ex\u00e9cution de Docker avec AppArmor<\/strong>: You can specify the profile to use with the <code>--security-opt<\/code> drapeau.<\/p>\n<pre><code class=\"language-bash\">docker <span class=\"glossaryai-tooltip glossary-term-672\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/run\/\" target=\"_blank\">run<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">\"RUN\" refers to a command in various programming languages and operating systems to execute a specified program or script. It initiates processes, providing a controlled environment for task execution.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/run\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> --security-opt apparmor=docker-default my_image<\/code><\/pre>\n<\/li>\n<\/ol>\n<h3>Gestion des profils AppArmor<\/h3>\n<p>Pour g\u00e9rer les profils, utilisez les commandes suivantes :<\/p>\n<ul>\n<li>\n<p><strong>List profiles<\/strong>:<\/p>\n<pre><code class=\"language-bash\">sudo aa-\u00e9tat<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Put a profile into complain mode<\/strong>:<\/p>\n<pre><code class=\"language-bash\">sudo aa-complain \/chemin\/vers\/profil<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>Supprimer un profil<\/strong>:<\/p>\n<pre><code class=\"language-bash\">sudo apparmor_parser -R \/path\/to\/profile<\/code><\/pre>\n<\/li>\n<\/ul>\n<h2>Meilleures pratiques pour l'utilisation de SELinux et AppArmor avec Docker\n\nSELinux et AppArmor sont deux syst\u00e8mes de s\u00e9curit\u00e9 Linux qui peuvent \u00eatre utilis\u00e9s pour renforcer la s\u00e9curit\u00e9 des conteneurs Docker. Voici quelques meilleures pratiques pour utiliser ces syst\u00e8mes avec Docker :\n\n1. Comprendre les diff\u00e9rences entre SELinux et AppArmor :\n   - SELinux (Security-Enhanced Linux) est un syst\u00e8me de contr\u00f4le d'acc\u00e8s obligatoire (MAC) qui utilise des politiques pour d\u00e9finir les permissions.\n   - AppArmor est un autre syst\u00e8me MAC qui utilise des profils pour restreindre les capacit\u00e9s des applications.\n\n2. Activer SELinux ou AppArmor sur votre syst\u00e8me :\n   - SELinux est g\u00e9n\u00e9ralement activ\u00e9 par d\u00e9faut sur les distributions Red Hat et CentOS.\n   - AppArmor est activ\u00e9 par d\u00e9faut sur les distributions Ubuntu et Debian.\n\n3. Utiliser les profils SELinux ou AppArmor fournis par Docker :\n   - Docker fournit des profils pr\u00e9-configur\u00e9s pour SELinux et AppArmor qui peuvent \u00eatre utilis\u00e9s pour s\u00e9curiser les conteneurs.\n   - Ces profils peuvent \u00eatre appliqu\u00e9s lors du lancement d'un conteneur en utilisant les options --security-opt.\n\n4. Personnaliser les profils SELinux ou AppArmor :\n   - Si les profils fournis par Docker ne r\u00e9pondent pas \u00e0 vos besoins, vous pouvez cr\u00e9er vos propres profils personnalis\u00e9s.\n   - Assurez-vous de tester vos profils personnalis\u00e9s avant de les utiliser en production.\n\n5. Surveiller et auditer l'utilisation de SELinux et AppArmor :\n   - Utilisez des outils comme auditd pour surveiller et auditer l'utilisation de SELinux et AppArmor.\n   - Examinez r\u00e9guli\u00e8rement les journaux pour d\u00e9tecter toute activit\u00e9 suspecte.\n\n6. Garder SELinux et AppArmor \u00e0 jour :\n   - Assurez-vous que votre syst\u00e8me d'exploitation et vos outils SELinux\/AppArmor sont \u00e0 jour avec les derni\u00e8res mises \u00e0 jour de s\u00e9curit\u00e9.\n\n7. Former votre \u00e9quipe :\n   - Assurez-vous que votre \u00e9quipe de d\u00e9veloppement et d'exploitation comprend comment utiliser SELinux et AppArmor avec Docker.\n   - Fournissez une formation et une documentation appropri\u00e9es.\n\n8. Tester en profondeur :\n   - Testez vos conteneurs avec SELinux et AppArmor activ\u00e9s pour vous assurer qu'ils fonctionnent comme pr\u00e9vu.\n   - Effectuez des tests de p\u00e9n\u00e9tration pour identifier les vuln\u00e9rabilit\u00e9s potentielles.\n\n9. Utiliser des images de base s\u00e9curis\u00e9es :\n   - Commencez avec des images de base qui ont d\u00e9j\u00e0 des profils SELinux ou AppArmor configur\u00e9s.\n   - Cela peut vous faire gagner du temps et r\u00e9duire les risques de configuration incorrecte.\n\n10. Surveiller les performances :\n    - SELinux et AppArmor peuvent avoir un impact sur les performances des conteneurs.\n    - Surveillez les performances de vos conteneurs et ajustez les configurations si n\u00e9cessaire.\n\nEn suivant ces meilleures pratiques, vous pouvez renforcer la s\u00e9curit\u00e9 de vos conteneurs Docker en utilisant SELinux et AppArmor.<\/h2>\n<h3>1. Utiliser une liste blanche<\/h3>\n<p>Lors de la d\u00e9finition des politiques SELinux ou AppArmor, commencez toujours par un ensemble minimal de permissions, puis \u00e9largissez progressivement. <span class=\"glossaryai-tooltip glossary-term-674\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/add\/\" target=\"_blank\">add<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">La commande ADD dans Docker est une instruction utilis\u00e9e dans les Dockerfiles pour copier des fichiers et des r\u00e9pertoires depuis une machine h\u00f4te vers une image Docker pendant le processus de construction. Elle facilite non seulement le transfert de fichiers locaux, mais offre \u00e9galement des fonctionnalit\u00e9s suppl\u00e9mentaires, telles que l'extraction automatique de fichiers compress\u00e9s et le t\u00e9l\u00e9chargement de fichiers distants via HTTP ou HTTPS.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/add\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> permissions as needed. This approach reduces the attack surface.<\/p>\n<h3>2. Auditer r\u00e9guli\u00e8rement les politiques<\/h3>\n<p>Effectuez des audits r\u00e9guliers des politiques SELinux et AppArmor pour vous assurer qu'elles sont conformes aux normes de s\u00e9curit\u00e9 de l'organisation. Recherchez toute modification non autoris\u00e9e ou violation.<\/p>\n<h3>3. Surveiller les journaux<\/h3>\n<p>SELinux et AppArmor fournissent tous deux des capacit\u00e9s de journalisation. Utilisez des outils tels que <code>auditd (d\u00e9mon d'audit Linux)<\/code> pour surveiller les journaux \u00e0 la recherche de toute activit\u00e9 inhabituelle.<\/p>\n<h3>4. Maintenir les politiques \u00e0 jour<\/h3>\n<p>Au fur et \u00e0 mesure que votre application \u00e9volue, vos politiques de s\u00e9curit\u00e9 doivent \u00e9galement \u00e9voluer. Examinez et mettez r\u00e9guli\u00e8rement \u00e0 jour les profils SELinux et AppArmor pour prendre en compte les nouvelles fonctionnalit\u00e9s et d\u00e9pendances.<\/p>\n<h3>5. Use Docker Bench Security<\/h3>\n<p>Utilisez des outils comme Docker Bench Security pour \u00e9valuer la s\u00e9curit\u00e9 de votre installation Docker, y compris les param\u00e8tres SELinux et AppArmor.<\/p>\n<h2>Conclusion<\/h2>\n<p>Integrating SELinux and AppArmor with Docker is a powerful approach to enhancing the security of your containerized applications. By understanding how these security modules work and implementing best practices, you can significantly reduce the risks associated with <span class=\"glossaryai-tooltip glossary-term-650\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\" target=\"_blank\">conteneur<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">Containers are lightweight, portable units that encapsulate software and its dependencies, enabling consistent execution across different environments. They leverage OS-level virtualization for efficiency.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/container\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> deployments. <\/p>\n<p>In a world where security breaches are becoming increasingly common, taking proactive measures to secure your Docker environment is not merely advisable; it is essential. By harnessing the capabilities of SELinux and AppArmor, you can build a robust defense against potential threats, ensuring that your applications <span class=\"glossaryai-tooltip glossary-term-672\"><span class=\"glossaryai-link\"><a href=\"https:\/\/dockerpros.com\/fr\/wiki\/run\/\" target=\"_blank\">run<\/a><\/span><span class=\"gai-content-hidden glossaryai-tooltip-content\"><span class=\"gai-tooltip-body\"><span class=\"glossaryai-tooltip-text\">\"RUN\" refers to a command in various programming languages and operating systems to execute a specified program or script. It initiates processes, providing a controlled environment for task execution.<span class=\"glossaryai-more-link\"> <a href=\"https:\/\/dockerpros.com\/fr\/wiki\/run\/\">More \u00bb<\/a><\/span><\/span><\/span><\/span><\/span> securely and reliably.<\/p>\n<p>En exploitant les forces de SELinux et d'AppArmor, les organisations peuvent cr\u00e9er un mod\u00e8le de s\u00e9curit\u00e9 en couches offrant un contr\u00f4le pr\u00e9cis sur leurs environnements conteneuris\u00e9s. Cette approche ne s\u00e9curise pas seulement les conteneurs eux-m\u00eames, mais prot\u00e8ge \u00e9galement les syst\u00e8mes h\u00f4tes et les donn\u00e9es sensibles, s'inscrivant ainsi dans les objectifs plus larges des strat\u00e9gies de s\u00e9curit\u00e9 d'entreprise.<\/p>","protected":false},"excerpt":{"rendered":"<p>L'int\u00e9gration de SELinux et d'AppArmor avec Docker renforce la s\u00e9curit\u00e9 en fournissant des contr\u00f4les d'acc\u00e8s en couches. Cette approche duale att\u00e9nue les vuln\u00e9rabilit\u00e9s potentielles, assurant une isolation robuste pour les applications conteneuris\u00e9es.<\/p>","protected":false},"author":1,"featured_media":1071,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-628","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Integrating SELinux and AppArmor for Enhanced Docker Security - Dockerpros<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/dockerpros.com\/fr\/security\/integration-de-selinux-et-apparmor-pour-une-securite-docker-renforcee\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Integrating SELinux and AppArmor for Enhanced Docker Security - Dockerpros\" \/>\n<meta property=\"og:description\" content=\"Integrating SELinux and AppArmor with Docker enhances security by providing layered access controls. This dual approach mitigates potential vulnerabilities, ensuring robust isolation for containerized applications.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/dockerpros.com\/fr\/security\/integration-de-selinux-et-apparmor-pour-une-securite-docker-renforcee\/\" \/>\n<meta property=\"og:site_name\" content=\"Dockerpros\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-22T12:36:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"dockerpros\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"dockerpros\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/\"},\"author\":{\"name\":\"dockerpros\",\"@id\":\"https:\/\/dockerpros.com\/#\/schema\/person\/a9b4c3d7f7a8e2b072e77d47b382a3a4\"},\"headline\":\"Integrating SELinux and AppArmor for Enhanced Docker Security\",\"datePublished\":\"2024-07-22T12:36:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/\"},\"wordCount\":940,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/dockerpros.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg\",\"articleSection\":[\"Security\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/\",\"url\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/\",\"name\":\"Integrating SELinux and AppArmor for Enhanced Docker Security - Dockerpros\",\"isPartOf\":{\"@id\":\"https:\/\/dockerpros.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg\",\"datePublished\":\"2024-07-22T12:36:22+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage\",\"url\":\"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg\",\"contentUrl\":\"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg\",\"width\":800,\"height\":600,\"caption\":\"integrating-selinux-and-apparmor-for-enhanced-docker-security-2\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/dockerpros.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Integrating SELinux and AppArmor for Enhanced Docker Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/dockerpros.com\/#website\",\"url\":\"https:\/\/dockerpros.com\/\",\"name\":\"Dockerpros\",\"description\":\"DockerPros \u2013 Your Ultimate Docker Resource Hub\",\"publisher\":{\"@id\":\"https:\/\/dockerpros.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/dockerpros.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/dockerpros.com\/#organization\",\"name\":\"Dockerpros\",\"url\":\"https:\/\/dockerpros.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/dockerpros.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/Dockerpros_logo_blanco.png\",\"contentUrl\":\"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/Dockerpros_logo_blanco.png\",\"width\":532,\"height\":114,\"caption\":\"Dockerpros\"},\"image\":{\"@id\":\"https:\/\/dockerpros.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/dockerpros.com\/#\/schema\/person\/a9b4c3d7f7a8e2b072e77d47b382a3a4\",\"name\":\"dockerpros\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/dockerpros.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/dockerpros.com\/wp-content\/litespeed\/avatar\/d13b9d4f101de1a7535b404e0c59affd.jpg?ver=1780577253\",\"contentUrl\":\"https:\/\/dockerpros.com\/wp-content\/litespeed\/avatar\/d13b9d4f101de1a7535b404e0c59affd.jpg?ver=1780577253\",\"caption\":\"dockerpros\"},\"sameAs\":[\"https:\/\/dockerpros.com\/\"],\"url\":\"https:\/\/dockerpros.com\/fr\/author\/dockerpros\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Int\u00e9gration de SELinux et AppArmor pour une S\u00e9curit\u00e9 Docker Renforc\u00e9e - Dockerpros","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/dockerpros.com\/fr\/security\/integration-de-selinux-et-apparmor-pour-une-securite-docker-renforcee\/","og_locale":"fr_FR","og_type":"article","og_title":"Integrating SELinux and AppArmor for Enhanced Docker Security - Dockerpros","og_description":"Integrating SELinux and AppArmor with Docker enhances security by providing layered access controls. This dual approach mitigates potential vulnerabilities, ensuring robust isolation for containerized applications.","og_url":"https:\/\/dockerpros.com\/fr\/security\/integration-de-selinux-et-apparmor-pour-une-securite-docker-renforcee\/","og_site_name":"Dockerpros","article_published_time":"2024-07-22T12:36:22+00:00","og_image":[{"width":800,"height":600,"url":"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg","type":"image\/jpeg"}],"author":"dockerpros","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"dockerpros","Dur\u00e9e de lecture estim\u00e9e":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#article","isPartOf":{"@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/"},"author":{"name":"dockerpros","@id":"https:\/\/dockerpros.com\/#\/schema\/person\/a9b4c3d7f7a8e2b072e77d47b382a3a4"},"headline":"Integrating SELinux and AppArmor for Enhanced Docker Security","datePublished":"2024-07-22T12:36:22+00:00","mainEntityOfPage":{"@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/"},"wordCount":940,"commentCount":0,"publisher":{"@id":"https:\/\/dockerpros.com\/#organization"},"image":{"@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage"},"thumbnailUrl":"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg","articleSection":["Security"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/","url":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/","name":"Int\u00e9gration de SELinux et AppArmor pour une S\u00e9curit\u00e9 Docker Renforc\u00e9e - Dockerpros","isPartOf":{"@id":"https:\/\/dockerpros.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage"},"image":{"@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage"},"thumbnailUrl":"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg","datePublished":"2024-07-22T12:36:22+00:00","breadcrumb":{"@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#primaryimage","url":"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg","contentUrl":"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/integrating-selinux-and-apparmor-for-enhanced-docker-security_628.jpg","width":800,"height":600,"caption":"integrating-selinux-and-apparmor-for-enhanced-docker-security-2"},{"@type":"BreadcrumbList","@id":"https:\/\/dockerpros.com\/de\/sicherheit\/die-integration-von-selinux-und-apparmor-fur-verbesserte-docker-sicherheitselinux-security-enhanced-linux-und-apparmor-sind-zwei-wichtige-sicherheitsmechanismen-die-in-linux-systemen-verwendet-we\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/dockerpros.com\/"},{"@type":"ListItem","position":2,"name":"Integrating SELinux and AppArmor for Enhanced Docker Security"}]},{"@type":"WebSite","@id":"https:\/\/dockerpros.com\/#website","url":"https:\/\/dockerpros.com\/","name":"Dockerpros","description":"DockerPros \u2013 Votre centre de ressources Docker incontournable","publisher":{"@id":"https:\/\/dockerpros.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/dockerpros.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/dockerpros.com\/#organization","name":"Dockerpros","url":"https:\/\/dockerpros.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/dockerpros.com\/#\/schema\/logo\/image\/","url":"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/Dockerpros_logo_blanco.png","contentUrl":"https:\/\/dockerpros.com\/wp-content\/uploads\/2024\/07\/Dockerpros_logo_blanco.png","width":532,"height":114,"caption":"Dockerpros"},"image":{"@id":"https:\/\/dockerpros.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/dockerpros.com\/#\/schema\/person\/a9b4c3d7f7a8e2b072e77d47b382a3a4","name":"professionnels Docker","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/dockerpros.com\/#\/schema\/person\/image\/","url":"https:\/\/dockerpros.com\/wp-content\/litespeed\/avatar\/d13b9d4f101de1a7535b404e0c59affd.jpg?ver=1780577253","contentUrl":"https:\/\/dockerpros.com\/wp-content\/litespeed\/avatar\/d13b9d4f101de1a7535b404e0c59affd.jpg?ver=1780577253","caption":"dockerpros"},"sameAs":["https:\/\/dockerpros.com\/"],"url":"https:\/\/dockerpros.com\/fr\/author\/dockerpros\/"}]}},"_links":{"self":[{"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/posts\/628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/comments?post=628"}],"version-history":[{"count":0,"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/posts\/628\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/media\/1071"}],"wp:attachment":[{"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/media?parent=628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/categories?post=628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dockerpros.com\/fr\/wp-json\/wp\/v2\/tags?post=628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}