Containerization and Docker Fundamentals Questions

Packaging applications into containers: images and layers, Dockerfiles, registries, image optimization and security, container networking and storage, and the container runtime model. Covers how containers differ from virtual machines, image build and management, and the fundamentals that underpin any orchestration platform. The container primitive before orchestration.

HardTechnical
36 practiced

As a new microservice is onboarded to production, what concrete Dockerfile and runtime hardening changes would you require before sign-off? Cover user permissions, filesystem settings, dropped capabilities, network exposure, and secrets handling, with example commands or Dockerfile snippets where relevant.

EasyTechnical
51 practiced

Why should a container process run as non-root in production, especially one that processes sensitive data or is exposed to untrusted input? Show the Dockerfile techniques to create a non-root user and switch to it, and explain how to still allow something like binding to a privileged port below 1024 without running as root.

HardTechnical
39 practiced

You're asked to harden a container image that currently runs as root, ships shell utilities, and is built from a large general-purpose base image, exposing an API to untrusted input. Propose a runtime hardening policy: seccomp profiles, dropping Linux capabilities, a read-only root filesystem, rootless containers, and how you'd enforce and audit these at deploy time, while keeping the service actually operable.

That is every published Containerization and Docker Fundamentals question for Security Architect so far. Browse the other topics in this category, or practice this one interactively.