[ SPECIFICATION // SECURITY ]: Seccomp JSON security profile generator for Docker, Podman, and Kubernetes. Filters dangerous syscalls (ptrace, reboot, mount) to prevent container breakout attacks.
Standard: Linux Seccomp-BPF (Secure Computing Mode) [ VERIFIED // LOCAL EXECUTION ][ ZERO TELEMETRY ][ OFFLINE PWA ][ OPEN SOURCE // MIT ]

[ 1. SECCOMP POLICY SPECIFICATION ]

[ WHITELISTED SYSCALL GROUPS ] 0 Syscalls Selected
PROCESS LIFECYCLE & THREADING:
MEMORY & VIRTUAL ALLOCATION:
FILE SYSTEM & DESCRIPTOR I/O:
NETWORK SOCKETS & EVENT POLLING:

[ 2. LIVE PROFILE EXPORT ]

Generating Seccomp OCI profile...
[ SECCOMP SECURITY INVARIANTS ]
  • Zero-Trust Default Action: Always default to SCMP_ACT_ERRNO (EPERM) rather than allowing unhandled syscalls.
  • Blocked Dangerous Syscalls: Dangerous calls like ptrace, bpf, mount, reboot, kexec_load, and sys_chroot are eliminated.
[ RUNTIME SYSCALL FILTERING ]

Linux Seccomp-BPF Syscall Filtering & LSM Sandboxing Guide

Restrict the Linux kernel attack surface using Seccomp-BPF filters and Landlock LSM for unprivileged application sandboxing.

Frequently Asked Questions (FAQ)

What is Seccomp-BPF in Linux processes and container runtimes?
Seccomp (Secure Computing Mode) with BPF filters enables granular restriction of system calls (syscalls) an application can execute, reducing the Linux kernel attack surface.
What is the difference between SCMP_ACT_ERRNO and SCMP_ACT_KILL?
SCMP_ACT_ERRNO returns a standard error code (such as EPERM) to the calling application without terminating it, whereas SCMP_ACT_KILL immediately aborts the process invoking the disallowed syscall.
How do I attach a Seccomp JSON profile to Docker or Podman?
Run your container with '--security-opt seccomp=/path/to/profile.json' in docker run, or declare it in Kubernetes pod securityContext specifications.
Which syscalls are commonly blocked for unprivileged containers?
Dangerous syscalls including ptrace, reboot, kexec_load, mount, unshare, and sys_chroot are typically blocked to prevent container breakout vulnerabilities.
Copied to clipboard!