2.7 Ensure devicemapper storage driver is not used

Information

Do not use devicemapper as the storage driver for your Docker instance.

The devicemapper storage driver is deprecated in favor of overlay2, and has been removed in Docker Engine v25.0.

Solution

Do not explicitly use devicemapper as storage driver.

For example, do not start Docker daemon as below:

dockerd --storage-driver devicemapper

Impact:

If you are using Device Mapper, you must migrate to a supported storage driver before upgrading to Docker Engine v25.0.

See Also

https://workbench.cisecurity.org/benchmarks/18749

Item Details

Category: SYSTEM AND SERVICES ACQUISITION

References: 800-53|SA-8, CSCv7|18

Plugin: Unix

Control ID: a7809a86b4a09ba71872957cc803b7e30d8358d4da8d6ca8c19750b480024f0e