Lesson 28 / 28

Security Basics

Run containers as a non-root user and keep base images minimal and updated to reduce attack surface.

Don't run as root

By default, a container's process runs as root inside it. Create and switch to a non-root user so a container breakout has far less power.

FROM node:22-alpine
WORKDIR /app
COPY . .
RUN npm ci --omit=dev

RUN addgroup -S appgroup && adduser -S appuser -G appgroup
USER appuser

CMD ["node", "server.js"]

Minimal base images

Fewer installed packages means fewer known vulnerabilities. Prefer alpine or distroless bases, and rebuild regularly to pick up security patches.

Quick check: Why should a container avoid running its process as root?

  • It makes the image build faster
  • It limits the damage if an attacker breaks out of the container
  • Root users can't use volumes
  • It disables networking
Answer

It limits the damage if an attacker breaks out of the container — Running as a non-root user reduces the privileges available if the container is compromised.

Final quiz 1 of 8

Final quiz

Quick check: What is a container image?

  • A running process
  • A virtual disk drive
  • A read-only template used to start containers
  • A network
Answer

A read-only template used to start containers — Containers are running instances of images.

Final quiz 2 of 8

Final quiz

Quick check: Which flag publishes a container port to the host?

  • -e
  • -v
  • -d
  • -p
Answer

-p — -p host:container maps ports.

Final quiz 3 of 8

Final quiz

Quick check: How do you keep database data after a container is removed?

  • Use a named volume
  • Write inside the container
  • Use --rm
  • Use EXPOSE
Answer

Use a named volume — Volumes live outside the container's writable layer.

Final quiz 4 of 8

Final quiz

Quick check: What does EXPOSE in a Dockerfile do?

  • Publishes the port
  • Documents the intended port only
  • Opens the firewall
  • Starts the app
Answer

Documents the intended port only — Publishing needs -p or Compose ports.

Final quiz 5 of 8

Final quiz

Quick check: Which Compose command stops and removes the stack?

  • docker compose up
  • docker compose logs
  • docker compose down
  • docker compose pull
Answer

docker compose down — Add -v to remove named volumes.

Final quiz 6 of 8

Final quiz

Quick check: Why use a multi-stage build?

  • To skip tests
  • To avoid tags
  • To use root
  • To ship a smaller final image
Answer

To ship a smaller final image — Build tools stay in the build stage.

Final quiz 7 of 8

Final quiz

Quick check: Why avoid the latest tag in production?

  • It makes rollbacks and audits hard
  • It is slower
  • It is private
  • It disables logs
Answer

It makes rollbacks and audits hard — Pin versions or commit hashes.

Final quiz 8 of 8

Final quiz

Quick check: Why run containers as a non-root user?

  • It builds faster
  • It limits damage if the app is compromised
  • It enables volumes
  • It saves RAM
Answer

It limits damage if the app is compromised — Least privilege reduces risk.