# Security Basics — Docker Fundamentals: Images, Containers and Compose

Source: https://www.skillbyai.com/en/docker/docker-security-basics

> Run containers as a non-root user and keep base images minimal and updated to reduce attack surface.

## Don't run as root

By default, a container's process runs as **root** inside it. Create and switch to a non-root user so a container breakout has far less power.

```dockerfile
FROM node:22-alpine
WORKDIR /app
COPY . .
RUN npm ci --omit=dev

RUN addgroup -S appgroup && adduser -S appuser -G appgroup
USER appuser

CMD ["node", "server.js"]
```

## Minimal base images

Fewer installed packages means fewer known vulnerabilities. Prefer `alpine` or `distroless` bases, and rebuild regularly to pick up security patches.

**Quiz:** Why should a container avoid running its process as root?

- [ ] It makes the image build faster
- [x] It limits the damage if an attacker breaks out of the container
- [ ] Root users can't use volumes
- [ ] It disables networking

*Answer:* It limits the damage if an attacker breaks out of the container. Running as a non-root user reduces the privileges available if the container is compromised.

## Final quiz 1 of 8

Final quiz

**Quiz:** What is a container image?

- [ ] A running process
- [ ] A virtual disk drive
- [x] A read-only template used to start containers
- [ ] A network

*Answer:* A read-only template used to start containers. Containers are running instances of images.

## Final quiz 2 of 8

Final quiz

**Quiz:** Which flag publishes a container port to the host?

- [ ] -e
- [ ] -v
- [ ] -d
- [x] -p

*Answer:* -p. -p host:container maps ports.

## Final quiz 3 of 8

Final quiz

**Quiz:** How do you keep database data after a container is removed?

- [x] Use a named volume
- [ ] Write inside the container
- [ ] Use --rm
- [ ] Use EXPOSE

*Answer:* Use a named volume. Volumes live outside the container's writable layer.

## Final quiz 4 of 8

Final quiz

**Quiz:** What does EXPOSE in a Dockerfile do?

- [ ] Publishes the port
- [x] Documents the intended port only
- [ ] Opens the firewall
- [ ] Starts the app

*Answer:* Documents the intended port only. Publishing needs -p or Compose ports.

## Final quiz 5 of 8

Final quiz

**Quiz:** Which Compose command stops and removes the stack?

- [ ] docker compose up
- [ ] docker compose logs
- [x] docker compose down
- [ ] docker compose pull

*Answer:* docker compose down. Add -v to remove named volumes.

## Final quiz 6 of 8

Final quiz

**Quiz:** Why use a multi-stage build?

- [ ] To skip tests
- [ ] To avoid tags
- [ ] To use root
- [x] To ship a smaller final image

*Answer:* To ship a smaller final image. Build tools stay in the build stage.

## Final quiz 7 of 8

Final quiz

**Quiz:** Why avoid the latest tag in production?

- [x] It makes rollbacks and audits hard
- [ ] It is slower
- [ ] It is private
- [ ] It disables logs

*Answer:* It makes rollbacks and audits hard. Pin versions or commit hashes.

## Final quiz 8 of 8

Final quiz

**Quiz:** Why run containers as a non-root user?

- [ ] It builds faster
- [x] It limits damage if the app is compromised
- [ ] It enables volumes
- [ ] It saves RAM

*Answer:* It limits damage if the app is compromised. Least privilege reduces risk.
