Comprehensive Container Security Series (2026) - 8 parts covering image security, runtime protection, K8s hardening, zero trust, tools, and AI-era threats
-
Updated
Jun 14, 2026
Comprehensive Container Security Series (2026) - 8 parts covering image security, runtime protection, K8s hardening, zero trust, tools, and AI-era threats
The project implements a security-focused container architecture that enforces immutability through read-only file systems.
A Docker container running Email OAuth 2.0 Proxy in headless (--no-gui) mode on a Debian-based environment, with the configuration file exposed via a Docker volume.
AI-powered DevSecOps platform that analyzes Dockerfiles for security vulnerabilities, best-practice violations, and configuration issues using Spring Boot, React, PostgreSQL, Docker, and Gemini AI.
Sentinel Dock is a comprehensive container security toolkit designed to safeguard Docker environments. It seamlessly integrates Trivy for vulnerability scanning and offers real-time monitoring of container activity. Key features include resource usage tracking (CPU & memory), and configuration hardening to enhance security and resilience.
🐳 A 7-day, hands-on journey from a single "Hello World" container to a hardened, monitored, production-style Docker stack. Real debugging included, not just working code.
Web and forensics CTF labs in hardened Docker containers, with solvers and writeups
Apify examples for OSS supply-chain risk, SEC red flags, and startup funding signals.
Audit Docker Compose configurations for risky privileges, mounts, ports, images, and secrets.
Historical Docker, Squid, and host-firewall prototype for constraining AI-agent egress
Security linter for environment variables, Docker, CI, Kubernetes, and runtime configuration.
A collection of Dockerfiles I personally use, as secure as I can.
🐳 A curated list of Docker resources and projects
The Hardened, Enterprise-Grade Fork of Moltbot. 🛡️ Featuring Zero Trust Architecture, Rootless Docker, Encrypted Memory & Sovereign Ollama Integration.
An in-depth guide to Docker, covering containerization principles, Dockerfile creation, image management, orchestration, and best practices to streamline development and deployment processes. Perfect for all levels.
Local-first Docker diagnostics — find security problems, misconfigurations and reclaimable resources. No AI, no network calls, no telemetry.
Local-first security scanner connecting leaked secrets, Docker risks, and unsafe GitHub Actions into actionable findings.
DevSecOps Playground: a working comparison of an insecure and secure CI/CD pipeline running the same app. The insecure pipeline ships a SQL injection and hardcoded secret straight to production; the secure pipeline catches both with Semgrep, Trivy, CodeQL, and Cosign before deploy.
To associate your repository with the docker-security topic, visit your repo's landing page and select "manage topics."