opensearch-dashboards:2.18.0 container isolation score: 63/100 (grade C)¶
Run with plain docker run opensearchproject/opensearch-dashboards:2.18.0 defaults, no hardening flags, the opensearch dashboards image scores 63/100, grade C (partial) on IronClaw's seven-dimension container containment scale. Higher is safer. This is what you get straight out of a copy-pasted docker run; the fixes below close the gap.
Graded from a read-only
docker inspectofopensearchproject/opensearch-dashboards:2.18.0at digestsha256:0ecd8444add2926cb6c52e03f910160138b6e331522237561da0b82e159b134f. No workload is executed. How scoring works →
How it scores, dimension by dimension¶
| Dimension | Verdict | Score | What the scan found |
|---|---|---|---|
| Non-root user (uid != 0) | ✅ PASS | 15/15 | runs as 1000 (uid != 0) |
| Dropped capabilities | ❌ FAIL | 4/20 | default capability set retained (includes CAP_NET_RAW, CAP_MKNOD, …) |
| Seccomp profile | ✅ PASS | 15/15 | seccomp profile active (syscall surface filtered) |
| Network isolation / egress | ⚠️ WARN | 4/15 | network=bridge: outbound egress is possible; prefer network=none |
| Read-only root filesystem | ❌ FAIL | 0/10 | root filesystem is writable: tamper/persistence surface |
| No docker.sock exposure | ✅ PASS | 15/15 | no docker.sock / OCI control socket mounted |
| No shared host namespaces | ✅ PASS | 10/10 | no host PID/IPC/network namespace sharing |
Harden it: the highest-value fixes¶
Applying these to your docker run opensearch-dashboards closes the biggest gaps first (most points recovered first):
- Dropped capabilities,
--cap-drop=ALL
Drop every Linux capability; add back only what the workload provably needs. - Network isolation / egress,
--network=none
Cut egress so a compromised workload cannot reach the network or exfiltrate. - Read-only root filesystem,
--read-only --tmpfs /tmp
Make the root filesystem read-only to remove the tamper/persistence surface.
A fully hardened run scores 100/100 (grade A):
docker run -d --name opensearch-dashboards-hardened \
--user 65532:65532 \
--cap-drop=ALL \
--security-opt=no-new-privileges \
--read-only --tmpfs /tmp \
--network=none \
opensearchproject/opensearch-dashboards:2.18.0
Scan your own container¶
These grades come from ironctl scan, a single, credential-free command that audits any running container, docker-compose service, or Kubernetes manifest, not just this image:
# install (Homebrew)
brew install ironsecco/ironclaw/ironclaw
# grade your own opensearch-dashboards the same way this page was generated
ironctl scan my-opensearch-dashboards
- Scan any container →, the full command reference.
- Add an isolation-score badge to your repo →
- The State of Container Isolation, 2026 →, the full survey this directory is built from.
- Run untrusted code in a real sandbox →, IronClaw wraps every AI-agent session in a gVisor/Kata isolation boundary with
network=noneby default.
Badge this image¶
Maintain opensearch dashboards (or run it)? Show its default-config isolation score with a badge that links back to this scorecard:
[](https://ironsecco.github.io/ironclaw/scores/opensearch-dashboards/)
The badge is a plain shields.io URL: no server, no build step, nothing to host. It reflects this page's default-configuration grade. Hardened your own deployment? Generate a live badge of your config with ironctl scan --badge-json, or compare every image on the leaderboard.
Part of the Container Isolation Scores directory, default-configuration containment grades for the most-pulled public images.