# Cis Docker 5.7

> Ensure sshd is not run within containers

- Skill: `cyberstrikeus/cis-docker-5-7` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-docker-5-7`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-docker-5-7/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-docker-5-7

---


# 5.7 Ensure sshd is not run within containers (Manual)

## Profile Applicability

- Level 1 - Docker - Linux

## Description

The SSH daemon should not be running within the container. You should SSH into the Docker host, and use `docker exec` to enter a container.

## Rationale

Running SSH within the container increases the complexity of security management by making it

- Difficult to manage access policies and security compliance for SSH server
- Difficult to manage keys and passwords across various containers
- Difficult to manage security upgrades for SSH server

It is possible to have shell access to a container without using SSH, the needlessly increasing the complexity of security management should be avoided.

## Impact

None.

## Audit Procedure

List all the running instances of containers by executing below command:

```bash
docker ps --quiet
```

For each container instance, execute the below command:

```bash
docker exec <CONTAINER_ID> ps -el
```

Ensure that there is no process for SSH server.

## Remediation

Uninstall the SSH daemon from the container and use and use `docker exec` to enter a container on the remote host.

```bash
docker exec --interactive --tty <CONTAINER_ID> sh
```

OR

```bash
docker attach <CONTAINER_ID>
```

## Default Value

By default, SSH server is not running inside the container. Only one process per container is allowed.

## References

1. https://jpetazzo.github.io/2014/06/23/docker-ssh-considered-evil/

## CIS Controls

### v8

**4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software**

Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.

### v7

**9.2 Ensure Only Approved Ports, Protocols and Services Are Running**

Ensure that only network ports, protocols, and services listening on a system with validated business needs, are running on each system.

