Using containerisation
Guidance on how to build and use containerised applications securely.
Page 4 of 4
Containerisation in the Cloud

How to use containerisation securely on a cloud platform an what to expect from your cloud provider.
Containerisation is used widely in the cloud, both by cloud providers to deliver their services and by the customers of those services. This means that it’s important to understand:
-
how your cloud provider secures the containers they run
-
how they can help you to secure your own containers
For both use cases, you should expect containerisation to be built on the cloud platform, taking full advantage of other core services.
However you run your containers, you should be confident that the container images are built securely and the containers are run securely. This page explains how to simplify your container security by using a secure cloud container ecosystem.
Note:
Use the NCSC guidance on choosing a cloud provider to ensure that the service meets your security needs. You should also ensure that you use the cloud platform guidance to configure and use the service securely.
Build on the platform
The container ecosystem should integrate well with the rest of the platform, so that it can share the platform’s security benefits. For example, the container ecosystem should work well with the platform’s standard services for:
-
identity and access controls
-
networking and network security
-
observability and threat detection
-
secrets management
If the container ecosystem forces you to use a separate set of features, then you may want to consider assessing the container ecosystem against the 14 cloud security principles, or using an alternative cloud service.
Expect a strong cloud container ecosystem
If you run your own containers in your cloud provider’s container ecosystem, you should expect it to include container-native foundations for you to build on. This should include:
-
well-built container images, including base images
-
tools to build container images securely
-
a secure private container registry
-
a container runtime environment providing appropriate separation between applications
-
the ability to control access to the container registry, including from the container runtime
These expectations are described in more detail in Building container images and Running containers. As described in Principle 3: separation between customers, you should expect strong separation between your applications and the other customers of the service. You should also prefer strong separation between each of your applications.
Delegate to your cloud provider
Container security is complex and different from traditional application security. You should consider first whether you can use Software-as-a-Service instead of hosting your own application. If not, you should make full use of the container security expertise available to you from your cloud provider.
For all aspects of containerisation, you should identify whether you can delegate to your cloud provider. You should consider how many of the following tasks can be delegated to your cloud provider:
-
providing secure base images
-
building application container images
-
hosting container images in an image registry
-
storing an audit trail of the container images you use
-
scanning container images for vulnerabilities and misconfiguration
-
preventing untrusted container images from running
-
providing a secure container runtime
-
establishing a secure perimeter around the container runtime
-
providing a secure host operating system
-
running container hosts
-
running containers
-
detecting suspicious behaviour in running containers
-
alerting you when new vulnerabilities are discovered in running containers