Container Escape and the Controls That Stop It
By Richard Augenti
Break out of a deliberately misconfigured container to reach the host, then apply the runtime and admission controls that make the same escape fail.
Free to browse. Takes about 60 minutes once you start.
Lab Overview
The worker service is deployed with --privileged and the host's Docker socket bind-mounted into it. It needs neither.
In this lab you take the attacker's seat, starting from code execution inside the worker, and use that misconfiguration to break out onto the host. Then you fix the run configuration and re-run the same attack to confirm every path you used is closed - because "the container was hardened" is a claim you prove by attacking it again, not by reading the run script.
This is a real escape against the host, which is why it runs on your own disposable lab VM and nowhere else. It writes a single marker file to /tmp on the host to prove it worked. Nothing here should ever be pointed at a machine you care about.
What to Expect
- Environment: a single Ubuntu machine you connect to over SSH, with Docker and the deliberately misconfigured worker container already installed. No cluster required.
- Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
- Safety: the escape is genuine and reaches the host, so it is confined to this throwaway VM. The only trace it leaves is a marker file in /tmp.
- Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.
What are hands-on labs?
A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.
Real tooling
The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.
Break it freely
Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.
Useful on Monday
Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.