⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Staff SRE / Principal Architect [L3] Docker Must enable BuildKit Staff SRE Scenario [L3]

Q: You deploy a financial application container and the compliance team requires that the container's filesystem must be completely immutable at runtime — no process should be able to write anywhere except explicitly approved paths. How do you enforce this?

Use the --read-only flag to make the entire root filesystem read-only:

#Docker #Must enable BuildKit #L3 #Containers #Linux
🎙️ Candidate Opening & Architectural Context
""During an image optimization initiative across our services, we solved this exact problem. The interviewer is testing: Read-only root filesystem, defense-in-depth.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Production Solution & Architecture

Use the --read-only flag to make the entire root filesystem read-only: With --read-only, any write attempt to an unmounted path returns a "Read-only file system" error. You explicitly whitelist writable paths using tmpfs (ephemeral, in-memory) or named volumes (persistent). The noexec and nosuid flags on tmpfs add additional hardening. In Kubernetes, set readOnlyRootFilesystem: true in the securityContext. Combine this with allowedHostPaths in PodSecurityPolicy or a Kyverno/OPA policy to restrict volume mounts. This approach follows the principle of least privilege and prevents attackers from writing backdoor binaries even if they compromise the application.

docker run --read-only \
  --tmpfs /tmp:rw,noexec,nosuid,size=100m \
  --tmpfs /var/run:rw,size=10m \
  -v logs-vol:/var/log \
  myfinancialapp
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Use the --read-only flag to make the entire root filesystem read-only:."
⚡ 60-Second Elevator Pitch Talking Points
  • Immediate Triage: Use the --read-only flag to make the entire root filesystem read-only:
  • Run targeted verification commands before modifying configuration.
  • Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement
Want more Docker scenarios?
Explore our complete collection of scenario-based Docker interview runbooks.
Browse All Docker Questions →

📚 Related Production Scenarios in Docker