Lesson 28 / 28
Security Basics
Run containers as a non-root user and keep base images minimal and updated to reduce attack surface.
Don't run as root
By default, a container's process runs as root inside it. Create and switch to a non-root user so a container breakout has far less power.
FROM node:22-alpine
WORKDIR /app
COPY . .
RUN npm ci --omit=dev
RUN addgroup -S appgroup && adduser -S appuser -G appgroup
USER appuser
CMD ["node", "server.js"]Minimal base images
Fewer installed packages means fewer known vulnerabilities. Prefer alpine or distroless bases, and rebuild regularly to pick up security patches.
Quick check: Why should a container avoid running its process as root?
- It makes the image build faster
- It limits the damage if an attacker breaks out of the container
- Root users can't use volumes
- It disables networking
Answer
It limits the damage if an attacker breaks out of the container — Running as a non-root user reduces the privileges available if the container is compromised.
Final quiz 1 of 8
Final quiz
Quick check: What is a container image?
- A running process
- A virtual disk drive
- A read-only template used to start containers
- A network
Answer
A read-only template used to start containers — Containers are running instances of images.
Final quiz 2 of 8
Final quiz
Quick check: Which flag publishes a container port to the host?
- -e
- -v
- -d
- -p
Answer
-p — -p host:container maps ports.
Final quiz 3 of 8
Final quiz
Quick check: How do you keep database data after a container is removed?
- Use a named volume
- Write inside the container
- Use --rm
- Use EXPOSE
Answer
Use a named volume — Volumes live outside the container's writable layer.
Final quiz 4 of 8
Final quiz
Quick check: What does EXPOSE in a Dockerfile do?
- Publishes the port
- Documents the intended port only
- Opens the firewall
- Starts the app
Answer
Documents the intended port only — Publishing needs -p or Compose ports.
Final quiz 5 of 8
Final quiz
Quick check: Which Compose command stops and removes the stack?
- docker compose up
- docker compose logs
- docker compose down
- docker compose pull
Answer
docker compose down — Add -v to remove named volumes.
Final quiz 6 of 8
Final quiz
Quick check: Why use a multi-stage build?
- To skip tests
- To avoid tags
- To use root
- To ship a smaller final image
Answer
To ship a smaller final image — Build tools stay in the build stage.
Final quiz 7 of 8
Final quiz
Quick check: Why avoid the latest tag in production?
- It makes rollbacks and audits hard
- It is slower
- It is private
- It disables logs
Answer
It makes rollbacks and audits hard — Pin versions or commit hashes.
Final quiz 8 of 8
Final quiz
Quick check: Why run containers as a non-root user?
- It builds faster
- It limits damage if the app is compromised
- It enables volumes
- It saves RAM
Answer
It limits damage if the app is compromised — Least privilege reduces risk.