⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] Docker Must enable BuildKit Production Scenario [L2]

Q: A production container running an API gateway is performing well but you notice its writable layer is growing by 500MB per day. The application itself doesn't write data to disk intentionally. What is causing the growth and how do you stop it?

The application or its runtime is writing files to the container's writable layer (the thin read-write layer on top of the image layers)....

#Docker #Must enable BuildKit #L2 #Containers #Linux
🎙️ Candidate Opening & Architectural Context
""Container stability relies on clean signal handling (SIGTERM vs SIGKILL) and immutable image tagging. The interviewer is testing: Container writable layer, log files, and read-only filesystem.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

The application or its runtime is writing files to the container's writable layer (the thin read-write layer on top of the image layers). Common culprits: application logs not sent to stdout, temp files, DNS resolver cache, or library-generated cache files.

  • Redirect all logs to stdout/stderr instead of files.
  • Mount writable paths as volumes or tmpfs so writes bypass the container layer.
  • Run the container with a read-only root filesystem: docker run --read-only --tmpfs /tmp --tmpfs /var/run myapp. This forces you to explicitly declare every writable path, preventing unexpected layer growth.
2️⃣

Remediation & Permanent Safeguards

*Diagnosis:* Run docker diff to see every file added (A), changed (C), or deleted (D) in the writable layer since the container started. *Fix:*

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Redirect all logs to stdout/stderr instead of files.."
⚡ 60-Second Elevator Pitch Talking Points
  • Redirect all logs to stdout/stderr instead of files.
  • Mount writable paths as volumes or tmpfs so writes bypass the container layer.
  • Run the container with a read-only root filesystem: docker run --read-only --tmpfs /tmp --tmpfs /...
Advertisement
Want more Docker scenarios?
Explore our complete collection of scenario-based Docker interview runbooks.
Browse All Docker Questions →

📚 Related Production Scenarios in Docker