Image Scanning
Docker Built-in Image Scanning¶
Docker provides a native CLI tool for scanning images for known vulnerabilities. It uses Trivy as the default scanner, but you can also integrate Clair and Harbor for additional scanning capabilities. Below are detailed workflows for each tool.
Using Trivy (Docker's Default Scanner)¶
Command syntax:
Example:
docker image scan --format="{{.Repository}}/{{.Tag}}: {{.Severity}} {{.Vulnerability}} ({{.ID}})" nginx:latest
Output:
Options:
- --format: Customize output format using Go templates.
- --skip-verify: Skip SSL certificate verification for private registries.
- --debug: Enable verbose logging for troubleshooting.
Note: Docker's scanning is limited to vulnerabilities in the base image and runtime dependencies. For deeper analysis, use third-party tools like Clair or Harbor.
Using Clair for Vulnerability Scanning¶
Clair is a lightweight, open-source vulnerability scanner for container images. To use it with Docker:
-
Install Clair:
-
Scan an Image:
Use the Clair CLI or API to scan an image. Example with the CLI:
-
Integrate with Docker:
Run Clair alongside Docker containers to scan images in real-time. For example, use Clair's API to trigger scans during CI/CD pipelines.
Key Features:
- Lightweight and fast.
- Supports multiple image formats (OCI, Docker).
- Integrates with Kubernetes and CI/CD tools.
Using Harbor for Vulnerability Scanning¶
Harbor is a container registry that includes a built-in vulnerability scanner. To use it:
- Enable the Scanner:
- Log in to your Harbor instance.
-
Navigate to Project Settings > Security and enable the vulnerability scanner.
-
Scan an Image:
- Push an image to Harbor:
-
Harbor automatically scans the image and reports vulnerabilities via the UI.
-
Use the Harbor CLI:
Scan an image locally using the Harbor CLI:
-
Integrate with Docker:
Configure Docker to use Harbor's scanner by setting the registry URL in your Docker daemon configuration (/etc/docker/daemon.json).
Key Features:
- Centralized registry with built-in security.
- Supports policy-based scanning and alerts.
- Integrates with Kubernetes and DevOps workflows.
Note: For maximum security, combine Docker's native tools with Clair and Harbor for comprehensive vulnerability detection.