Software Engineering Institute (SEI) Podcast Series · Members of Technical Staff at the Software Engineering Institute

Securing Docker Containers: Techniques, Challenges, and Tools

·39 min·7 clips
Tim Chick introduces the SEI podcast series and his guests from the Applied Systems Group. Max Chudina explains that he came to the SEI after working in manufacturing-quality-control software and was drawn to the institute’s focus on security and DevOps best practices. He describes the SEI’s value as applied research that helps make good practice easier for others to use. The discussion then turns to Docker security and the risks that come with exposing a container to the web. Max lays out the worst-case path from a container compromise to full privileged access on the host system. That puts the host’s databases, credentials, and connected services at risk. Sasank Vishlabhatla steers the conversation toward practical mitigations. The first is least privilege: if a container does not need root, it should not run as root. The guest compares that idea to babyproofing a house. The operating system is the house, and the services are the babies. The point is to keep mistakes and intrusions from reaching too far. The conversation then moves beyond root access alone. Sasank notes that specifying a service user is another useful control, since it can help block unauthorized access even if an attacker gets into the container or breaks out of it. The guests also point to Dockerfile choices as part of the defense. Doing due diligence on the Dockerfile can help close off other exploit paths, and hardening the image is part of that work. The episode stays focused on due diligence rather than magic fixes. It treats container security as a layered problem. You need to know what the container can do, what the host can do, and what a breach would expose. The framing stays practical throughout. The guests are not trying to turn the topic into theory for its own sake. They are trying to make the operational consequences easy to see. The result is a focused discussion of container risk, privilege management, and the small decisions that shape the size of a breach.

As heard by us

A grounded tour of Docker hardening that keeps the risk real.

This episode treats Docker security as a boundary problem, not a box to tick. It shows how a sloppy container can become a path to the host, the databases, and the credentials tied to a service, then makes least privilege feel concrete by moving from not running as root to using…

Read the full review in PlayNext →

Why you'd press play

Want a practical tour of container least privilege and image hardening?

Read the full recommendation in PlayNext →
Listen to the show on