Using containerisation
Guidance on how to build and use containerised applications securely.
Page 1 of 4

Using containerisation
Containers are a common approach for packaging and deploying applications, standardised by the Open Container Initiative (OCI).
Containerising an application is a great enabler for improving its security, making it easier to both understand and simplify the execution environment and its dependencies. This in turn makes it easier to apply other techniques to improve security.
However, just adopting containerisation without making an informed decision about what to change, and when, will not make your application more secure. You must adapt your approach to take full advantage of the security opportunities that containerisation provides. You should consider which architectural changes are appropriate and evolve to a container-native approach, rather than changing everything at once.
Typically, containers are used by building a container image and then starting containers from that image. This means that it’s important to build security into the container images you use, as well as running your containers in a secure execution environment.
There are many different ways to use containers, particularly in the cloud:
-
If you use a SaaS product, your cloud provider may implement their service as a set of containers.
-
In many PaaS products, you produce the container image, but your cloud provider runs it for you.
-
If you run containers in IaaS, you may be responsible for running the container too.
Whichever approach you take, you should be confident that the container images produced are secure and that containers run in a secure execution environment.
Terminology
Many technical terms are used when discussing containers. This section covers the most important terms used in this guidance.
A container image that is used as the starting point to build another container image. Typically, a container image is produced by adding files or configuration changes to a base image. A base image can be made from another ‘transitive’ base image. A container image can also be built without a base image (in some tools this may just be an empty base image).
A running application created from one or more container images and kept separate from the other software running on the host. There are many container standards, such as Docker container, OCI container, and Kubernetes pod.
The set of files that comprise a container’s configuration and contents. Container images are stored in a container registry and are used to start running containers. The two most widely used container image formats are Docker image and OCI image.
A service that stores container images. When containers are started, the container runtime will ‘pull’ the container image from a container registry, unless it already has a copy cached. Public registries make container images available to anyone, whereas private registries limit access to authorised users (and container runtimes). Some container registries have built-in functionality to scan the images they store for security issues.
The software used to manage, start, and operate containers on a host.
The computer or virtual machine that hosts containers. A container image does not include the operating system kernel, as the running container uses the host’s kernel.