Q: You deploy a financial application container and the compliance team requires that the container's filesystem must be completely immutable at runtime — no process should be able to write anywhere except explicitly approved paths. How do you enforce this?
Use the --read-only flag to make the entire root filesystem read-only:
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
Use the --read-only flag to make the entire root filesystem read-only: With --read-only, any write attempt to an unmounted path returns a "Read-only file system" error. You explicitly whitelist writable paths using tmpfs (ephemeral, in-memory) or named volumes (persistent). The noexec and nosuid flags on tmpfs add additional hardening. In Kubernetes, set readOnlyRootFilesystem: true in the securityContext. Combine this with allowedHostPaths in PodSecurityPolicy or a Kyverno/OPA policy to restrict volume mounts. This approach follows the principle of least privilege and prevents attackers from writing backdoor binaries even if they compromise the application.
docker run --read-only \
--tmpfs /tmp:rw,noexec,nosuid,size=100m \
--tmpfs /var/run:rw,size=10m \
-v logs-vol:/var/log \
myfinancialapp
- Immediate Triage: Use the --read-only flag to make the entire root filesystem read-only:
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.