SV-235845r627662_rule
V-235845
SRG-APP-000454
DKER-EE-004130
CAT II
10
Remove all outdated UCP and DTR container images from all nodes in the cluster:
via CLI: As a Docker EE admin, execute the following commands using a client bundle:
docker rmi -f $(docker images --filter reference='docker/ucp*:[outdated_tags]' -q)
docker rmi -f $(docker images --filter reference='docker/dtr*:[outdated_tags]' -q)
Verify that all outdated UCP and DTR container images have been removed from all nodes in the cluster.
via CLI: As a Docker EE admin, execute the following command using a client bundle:
docker images --filter reference='docker/[ucp|dtr]*'
Verify that there are no tags listed that are older than the currently installed versions of UCP and DTR.
If any of the tags listed are older than the currently installed versions of UCP and DTR, then this is a finding.
V-235845
False
DKER-EE-004130
Verify that all outdated UCP and DTR container images have been removed from all nodes in the cluster.
via CLI: As a Docker EE admin, execute the following command using a client bundle:
docker images --filter reference='docker/[ucp|dtr]*'
Verify that there are no tags listed that are older than the currently installed versions of UCP and DTR.
If any of the tags listed are older than the currently installed versions of UCP and DTR, then this is a finding.
M
5281