Workload misconfigurations

Ensure AUFS storage driver is not used (Automated)

Risk Level

Informational (4)

Platform(s)
  • N/A

Compliance Frameworks

Description

The aufs storage driver is the oldest storage driver used on Linux systems. It is based on a Linux kernel patch-set that is unlikely in future to be merged into the main OS kernel. The aufs driver is also known to cause some serious kernel crashes. aufs only has legacy support within systems using Docker. Most importantly, aufs is not a supported driver in many Linux distributions using latest Linux kernels and has also been deprecated with Docker Engine release 20.10.
  • Recommended Mitigation

    Do not explicitly use aufs as storage driver. For example, do not start Docker daemon as follows: 'dockerd --storage-driver aufs'