2.16 Ensure that experimental features are not implemented in production

Information

Experimental features should not be enabled in production.

Rationale:

'Experimental' is currently a runtime Docker daemon flag rather than being a feature of a separate build. Passing --experimental as a runtime flag to the docker daemon activates experimental features. Whilst 'Experimental' is considered a stable release, it has a number of features which may not have been fully tested and do not guarantee API stability.

Solution

You should not pass --experimental as a runtime parameter to the Docker daemon on production systems.

Impact:

None

Default Value:

By default, experimental features are not activated in the Docker daemon.

See Also

https://workbench.cisecurity.org/files/2433

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-43, CSCv6|18

Plugin: Unix

Control ID: 631037484579d428493d493a333a5fda76c9c92889bccbc0f7be6594afdbac11