# Rancher Container Security (76 vulnerabilities)

**URL:** <https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595>\
**Category:** General\
**Created:** [June 9, 2017, 6:42pm UTC](https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595 "2017-06-09T18:42:35Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![barbel.bamben](https://avatars.discourse-cdn.com/v4/letter/b/3be4f8/32.png) [@barbel.bamben](https://forums.suse.com/u/barbel.bamben)\
**Post date:** [June 9, 2017, 6:42pm UTC](https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595/1 "2017-06-09T18:42:35Z")

</div>

Hi everyone,

i use Rancher now in production and it does a great job. I was always concerned about the security of the docker images. Thats way i use Clair ([https://github.com/coreos/clair](https://github.com/coreos/clair)) to ensure my applications run with no vulnerabilities.

But if i scan the Rancher images is see a lot of problems ( i attached 2 examples reports)

Does anybody know why this is the case and if its expected that we reach a “better” level here?

For me especially this [https://hub.docker.com/r/rancher/lb-service-haproxy/tags/](https://hub.docker.com/r/rancher/lb-service-haproxy/tags/) image is important.

> **[analysis-rancher-lb-service-haproxy-v0.6.4.html](https://www.dropbox.com/s/7fsxhsfgox71v4l/analysis-rancher-lb-service-haproxy-v0.6.4.html?dl=0)**
>
> Shared with Dropbox

  

> **[analysis-rancher-lb-service-haproxy-v0.7.5.html](https://www.dropbox.com/s/65elqo8sv9y3f40/analysis-rancher-lb-service-haproxy-v0.7.5.html?dl=0)**
>
> Shared with Dropbox

Best  
Barbel

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 9, 2017, 9:41pm UTC](https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595/2 "2017-06-09T21:41:38Z")

</div>

The only “right” answer here is that we can do a better job of updating, which I will bring up. But the practicality is that updating everything constantly adds considerable risk and testing for what is usually no benefit other than passing scanner reports like this.

If you really read through the list, few if any at all are actually relevant. There’s libraries and binaries that come with the base Ubuntu image, but haproxy does not use them (e.g. libxml2) directly, and it is the only thing exposing an interface to the outside world. If you’re _inside_ the container then you already have full access and an exploit of `curl`, `wget`, `bash`, `vim`, etc isn’t going to gain you anything.

---

<div class="post-metadata">

**Author:** ![barbel.bamben](https://avatars.discourse-cdn.com/v4/letter/b/3be4f8/32.png) [@barbel.bamben](https://forums.suse.com/u/barbel.bamben)\
**Post date:** [June 10, 2017, 12:24pm UTC](https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595/3 "2017-06-10T12:24:35Z")

</div>

Thanks for the fast reply!

Just to say even a fully patched ubuntu:1604 got security issues ( i think 12 - 22) . I totally understand your point.

I created reports for all rancher images running at my cluster.

> **[rancher](https://www.dropbox.com/sh/l9izjjfsfnmog87/AAAZQQAyv5AqRJmbS3ggr46Ca?dl=0)**
>
> Shared with Dropbox

Actually what is important for me is can we rely on Rancher that they take care about the security especially for services facing to the public.

**Example** :  
I am running Rancher version 1.5.9 with HAProxy now a critical security issue was found and patched by HAProxy. How fast can Rancher user get notified and have a updated HAProxy Image? (how will / is that handled / Security mailing list?)

FYI:  
I just want to make clear that i really like the way Rancher / you treat the community and this is no finger pointing

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [June 12, 2017, 10:10pm UTC](https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595/4 "2017-06-12T22:10:32Z")

</div>

You can subscribe to the Announcements forum here to get notifications of releases. Specific ones for a security issue will be labeled as such (which happened once, [fairly recently](http://forums.suse.com/t/security-advisory-cve-2017-7297/5964/2)). If it’s in a microservice outside the main image then a new image would be pushed and the catalog updated, which will show “upgrade available” in the UI. There is also an auto-upgrade option in 1.6 that can be enabled (though it is only for system services, and the balancer isn’t one…)

---

<div class="post-metadata">

**Author:** ![iBobik](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/ibobik/32/2339_2.png) [@iBobik](https://forums.suse.com/u/iBobik)\
**Post date:** [June 13, 2017, 10:52am UTC](https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595/5 "2017-06-13T10:52:50Z")

</div>

So maybe using the smallest base images helps - not Ubuntu but Debian or Alpine, so there will not be outdated and not used packages. Also more faster deployment is benefit.

---

<div class="post-metadata">

**Author:** ![flaccid](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/flaccid/32/46_2.png) [@flaccid](https://forums.suse.com/u/flaccid)\
**Post date:** [June 13, 2017, 9:46pm UTC](https://forums.suse.com/t/rancher-container-security-76-vulnerabilities/6595/6 "2017-06-13T21:46:31Z")

</div>

+1 here. I know that for some of the images, moving to alpine presents a big chunk of work but its certainly worth it.
