2.9 Confirm default cgroup usage

Information

https://docs.docker.com/engine/reference/commandline/daemon/

Solution

The default setting is good enough and can be left as-is. If you want to specifically set a non-default cgroup, pass --cgroup-parent parameter to the docker daemon when starting it.
For Example,
docker daemon --cgroup-parent=/foobar
Impact-
None.Default Value-
By default, docker daemon uses /docker for fs cgroup driver and system.slice for systemd cgroup driver.

See Also

https://workbench.cisecurity.org/files/516

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-39

Plugin: Unix

Control ID: 70f33de2ea812866f9117e61f10dacb208f62385712746a0196c29d894c04572