12. Security and Best Practices
Review image inputs, runtime permissions, secrets, and release practices.
Build Practices
- Use maintained base images and review updates.
- Pin release inputs where reproducibility matters.
- Exclude local secrets and generated files from the build context.
- Keep build tools out of the runtime image when a multi-stage build fits.
- Scan the built image and address findings in context.
Runtime Practices
Run as a non-root user when the application supports it. Grant only the mounts, capabilities, and network access it needs. Read-only filesystems require explicit writable locations for applications that write temporary or runtime files.
Avoid mounting the Docker socket into an ordinary application container. It can expose control over the host’s Docker daemon.
Configuration and Secrets
Separate application configuration from image content. Environment variables are useful configuration inputs, but they are not a complete secret-management system. Prefer platform-supported secret delivery and prevent sensitive values from entering logs or image layers.
Release Checklist
- Build and test the image.
- Record the immutable artifact reference.
- Validate runtime configuration and persistent mounts.
- Confirm health checks, logs, and resource limits.
- Document rollback and data recovery separately.
Practice
Review the web image built earlier. Identify which settings belong in its Dockerfile and which belong in the deployment configuration.
Quick Interview Answer
Container security combines trusted build inputs, controlled runtime privileges, careful secret handling, and tested deployment and recovery procedures.
Previous: 11. Logs, Health, and Resources | Next: Hands-On Labs
Add More Questions to This Guide
Know a question that should be here? Share it and help the community!
Open Google Form