7.3 Ensure that all Docker swarm overlay networks are encrypted

Information

Ensure that all Docker swarm overlay networks are encrypted.

By default, data exchanged between containers on nodes on the overlay network is not encrypted. This could potentially expose traffic between containers.

Solution

You should create overlay networks the with --opt encrypted flag.

Impact:

None

See Also

https://workbench.cisecurity.org/benchmarks/16041

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Unix

Control ID: 263ecd38c1b79c11405dd24fba7b8358e4713f05066321c3e99099201759e567