Skip to main content
Guidance

Using containerisation

Guidance on how to build and use containerised applications securely.

Page 4 of 4

Containerisation in the Cloud

iStock.com/erhui1979

How to use containerisation securely on a cloud platform an what to expect from your cloud provider.

Containerisation is used widely in the cloud, both by cloud providers to deliver their services and by the customers of those services. This means that it’s important to understand:

  • how your cloud provider secures the containers they run

  • how they can help you to secure your own containers

For both use cases, you should expect containerisation to be built on the cloud platform, taking full advantage of other core services.

However you run your containers, you should be confident that the container images are built securely and the containers are run securely. This page explains how to simplify your container security by using a secure cloud container ecosystem.

Note:

Use the NCSC guidance on choosing a cloud provider to ensure that the service meets your security needs. You should also ensure that you use the cloud platform guidance to configure and use the service securely.


If the container ecosystem forces you to use a separate set of features, then you may want to consider assessing the container ecosystem against the 14 cloud security principles, or using an alternative cloud service.


These expectations are described in more detail in Building container images and Running containers. As described in Principle 3: separation between customers, you should expect strong separation between your applications and the other customers of the service. You should also prefer strong separation between each of your applications.


Published

Reviewed

Version

1.0