2.19 Ensure that experimental features are not implemented in production

Information

Experimental features should not be enabled in production.

"Experimental" is currently a runtime Docker daemon flag rather than being a feature of a separate build. Passing --experimental as a runtime flag to the docker daemon activates experimental features. Whilst "Experimental" is considered a stable release, it has a number of features which may not have been fully tested and do not guarantee API stability.

Solution

You should not pass --experimental as a runtime parameter to the Docker daemon on production systems.

Impact:

None

See Also

https://workbench.cisecurity.org/benchmarks/18749

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|18

Plugin: Unix

Control ID: 0f19c7b62228e6eccc41e7851d33f04f60fc430e52b61b4cdcdb0de28907c29d