Does the Kubernetes Maven plugin require root access to the Docker daemon?

Viewed 43

Background

I have a situation where a client wishes to use the Kubernetes Maven plugin in their builds to create Docker images, and they will be building with Docker in Docker (DinD). Builds will take place on one of our various Jenkins agents, each used by a number of different teams and projects. With this, there is concern that the plugin will provide root access to the docker daemon, theoretically giving the user access to any other Docker containers on the system. All agents user their own Jenkins user on their corresponding operating systems, and should not have any root permissions or otherwise elevated access.

Problem

I'm not sure if I've been looking in the wrong places, using the wrong words, or just not understanding something, but I can't seem to find much information online helpful to what I'm trying to figure out. My two main questions boil down to:

  1. Will the Kubernetes Maven plugin and/or DinD require root access to the Docker daemon?
  2. Are there any other potential security vulnerabilities with the current situation? Mainly focused on interactions with Kubernetes, Maven, and Docker.

Apologies if something is unclear or does not make sense, I will gladly clarify in the comments.

0 Answers
Related