feat: add --pids-limit to custom docker run options whitelist

Add support for --pids-limit option in CustomDockerRunOptions to allow
limiting the number of processes that can be created within a container.
This provides an additional security hardening option for deployments.

- Add --pids-limit to the mapping in convertDockerRunToCompose()
- Add parsing logic for both --pids-limit=value and --pids-limit value formats
- Add tests for the new option
This commit is contained in:
Augustinas Malinauskas 2026-02-04 08:16:40 -08:00
parent c4e15d4e1b
commit c0100a3edd
2 changed files with 24 additions and 1 deletions

View file

@ -1010,6 +1010,7 @@ function convertDockerRunToCompose(?string $custom_docker_run_options = null)
'--hostname' => 'hostname',
'--entrypoint' => 'entrypoint',
'--runtime' => 'runtime',
'--pids-limit' => 'pids_limit',
]);
foreach ($matches as $match) {
$option = $match[1];
@ -1040,6 +1041,16 @@ function convertDockerRunToCompose(?string $custom_docker_run_options = null)
$options[$option] = array_unique($options[$option]);
}
}
if ($option === '--pids-limit') {
// Match --pids-limit=value or --pids-limit value (e.g., --pids-limit=256, --pids-limit 1024)
$regexForParsingPidsLimit = '/--pids-limit(?:=|\s+)([^\s]+)/';
preg_match($regexForParsingPidsLimit, $custom_docker_run_options, $pids_limit_matches);
$value = $pids_limit_matches[1] ?? null;
if ($value && ! empty(trim($value))) {
$options[$option][] = $value;
$options[$option] = array_unique($options[$option]);
}
}
if ($option === '--entrypoint') {
$value = null;
// Match --entrypoint=value or --entrypoint value
@ -1108,7 +1119,7 @@ function convertDockerRunToCompose(?string $custom_docker_run_options = null)
}
});
$compose_options->put($mapping[$option], $ulimits);
} elseif ($option === '--shm-size' || $option === '--hostname' || $option === '--runtime') {
} elseif ($option === '--shm-size' || $option === '--hostname' || $option === '--runtime' || $option === '--pids-limit') {
if (! is_null($value) && is_array($value) && count($value) > 0 && ! empty(trim($value[0]))) {
$compose_options->put($mapping[$option], $value[0]);
}

View file

@ -223,3 +223,15 @@ test('RuntimeWithOtherOptions', function () {
->and($output['cap_drop'])->toBe(['ALL'])
->and($output['security_opt'])->toBe(['no-new-privileges']);
});
test('PidsLimitWithEquals', function () {
$input = '--pids-limit=1024';
$output = convertDockerRunToCompose($input);
expect($output)->toBe(['pids_limit' => '1024']);
});
test('PidsLimitWithoutEquals', function () {
$input = '--pids-limit 256';
$output = convertDockerRunToCompose($input);
expect($output)->toBe(['pids_limit' => '256']);
});