Q: Your container needs to run as a non-root user for security. How do you set this up?
dockerfile
#Docker #Docker #L3 #Containers #Linux
🎙️ Candidate Opening & Architectural Context
""When containerizing our microservices stack, container lifecycle and resource management were critical. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
The USER instruction sets the running user. Application files must be owned by this user. In Kubernetes, set securityContext.runAsNonRoot: true and runAsUser: 1000. Most base images now have a non-root user you can use (e.g., node user in Node.js images).
RUN groupadd -r appuser && useradd -r -g appuser appuser
COPY --chown=appuser:appuser . .
USER appuser
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: The USER instruction sets the running user. Application files must be owned by this user. In Kubernetes, set securityContext.runAs."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: dockerfile
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement