Haha, I bet the Docker team wishes they had a built-in 'runtime analysis capability' like in option B. That would be pretty neat, but I guess we're stuck with the good old Dockerfile for now.
D is also a good option. Ops teams often have a good understanding of the processes used in the containers they manage, making whitelisting more straightforward.
I agree with Wendell. Containers are great for whitelisting because you can easily define and control the processes that are allowed to run within them.
C seems like the best answer here. Containers are designed to be lightweight and focused, so they typically have a limited number of processes that should be running.
Marcos
5 months agoAlton
5 months agoLelia
4 months agoJovita
4 months agoMy
5 months agoTelma
5 months agoPrecious
5 months agoDick
5 months agoCrista
4 months agoElliott
5 months agoAlona
5 months agoOnita
5 months agoWendell
5 months agoCaitlin
5 months agoCorinne
5 months ago