⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Docker & Containers Interview Questions Scenario 154 of 158 in Docker & Containers
Senior DevOps Engineer Docker Container Runtime & Systems Engineering Production Scenario

Q: Your organization is migrating production hosts to Red Hat Enterprise Linux (RHEL 9) with SELinux in `Enforcing` mode. When running containers mounting host directories (`docker run -v /data:/data`), processes running as root (`UID 0`) fail with `Permission denied` when reading or writing files. Disabling SELinux (`setenforce 0`) is forbidden by corporate security. You must explain how SELinux MCS category labels protect containers, apply the `:z` and `:Z` volume mount flags correctly, and avoid relabeling system directories.

Fix 'Permission denied' errors on SELinux-enforcing hosts (RHEL, Rocky, Fedora). Master the SELinux volume relabeling flags `:z` (shared label) and `:Z` (private unshared label).

#Docker #Linux #Security #SELinux #RedHat
🎙️ Candidate Opening & Architectural Context
"Fix 'Permission denied' errors on SELinux-enforcing hosts (RHEL, Rocky, Fedora). Master the SELinux volume relabeling flags `:z` (shared label) and `:Z` (private unshared label)."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

Step 1

Understand SELinux Multi-Category Security (MCS) Container Labels

SELinux assigns unique category pairs (e.g., `s0:c123,c456`) to each container process (`svirt_lxc_net_t`). The host directory typically has the default `system_u:object_r:default_t` label. SELinux kernel hooks block the container from accessing the files because the MCS categories do not match, regardless of Linux numeric UID permissions.

# Inspect process SELinux context inside container
docker run --rm alpine ps -eZ
# Output: system_u:system_r:container_t:s0:c12,c34 1 ...

# Inspect host directory SELinux label
ls -dZ /data
# Output: unconfined_u:object_r:default_t:s0 /data (Access Denied to container_t!)
Pro Tip: Understand SELinux Multi-Category Security (MCS) Container Labels
Step 2

Differentiate Between the :z and :Z Relabeling Flags

Docker provides volume relabeling suffixes: `:z` relabels the directory with the shared container label (`container_file_t`), allowing multiple containers to read and write the volume concurrently. `:Z` relabels the directory with an exclusive private label (`container_file_t` with private MCS categories), ensuring only that specific container can access the files.

<!-- SELinux Mount Flags -->
:z (Shared Label):
  docker run -v /data:/data:z app1
  docker run -v /data:/data:z app2  (Both containers can safely share /data)

:Z (Private Exclusive Label):
  docker run -v /data:/data:Z app1  (Strictly locked to app1; other containers blocked)
Pro Tip: Differentiate Between the :z and :Z Relabeling Flags
Advertisement
Step 3

Apply the Appropriate Flag in CLI and Docker Compose

Configure the bind mount with the `:z` or `:Z` modifier.

# Docker CLI with shared SELinux relabeling
docker run -d \
  --name web-app \
  -v /var/www/html:/usr/share/nginx/html:z \
  nginx:alpine

# Docker Compose
services:
  db:
    image: postgres:16
    volumes:
      - ./pgdata:/var/lib/postgresql/data:Z  # Private exclusive mount
Pro Tip: Apply the Appropriate Flag in CLI and Docker Compose
Step 4

WARNING: Never Use :z or :Z on System Root Directories

Never use `:z` or `:Z` on host system directories like `/etc`, `/usr`, `/var`, or `/home`. Doing so recursively relabels critical host system files to `container_file_t`, breaking SSH logins, systemd daemons, and host services.

# DANGEROUS DISASTER ANTI-PATTERN:
# docker run -v /etc:/host-etc:Z alpine  <-- BREAKS HOST OS SELINUX LABELS!
Pro Tip: WARNING: Never Use :z or :Z on System Root Directories
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"SELinux blocks volume access when container MCS categories do not match host directory contexts. Suffixing mounts with `:z` (shared) or `:Z` (private) automatically applies the `container_file_t` label, satisfying SELinux without compromising host security."
⚡ 60-Second Elevator Pitch Talking Points
  • W
  • e
  • r
  • e
  • s
  • o
  • l
  • v
  • e
  • d
  • v
  • o
  • l
  • u
  • m
  • e
  • p
  • e
  • r
  • m
  • i
  • s
  • s
  • i
  • o
  • n
  • e
  • r
  • r
  • o
  • r
  • s
  • o
  • n
  • o
  • u
  • r
  • h
  • a
  • r
  • d
  • e
  • n
  • e
  • d
  • R
  • H
  • E
  • L
  • 9
  • c
  • l
  • u
  • s
  • t
  • e
  • r
  • s
  • w
  • i
  • t
  • h
  • o
  • u
  • t
  • d
  • i
  • s
  • a
  • b
  • l
  • i
  • n
  • g
  • S
  • E
  • L
  • i
  • n
  • u
  • x
  • b
  • y
  • a
  • p
  • p
  • l
  • y
  • i
  • n
  • g
  • D
  • o
  • c
  • k
  • e
  • r
  • '
  • s
  • `
  • :
  • z
  • `
  • a
  • n
  • d
  • `
  • :
  • Z
  • `
  • m
  • o
  • u
  • n
  • t
  • f
  • l
  • a
  • g
  • s
  • .
  • A
  • d
  • d
  • i
  • n
  • g
  • `
  • :
  • z
  • `
  • a
  • u
  • t
  • o
  • m
  • a
  • t
  • i
  • c
  • a
  • l
  • l
  • y
  • r
  • e
  • l
  • a
  • b
  • e
  • l
  • s
  • a
  • p
  • p
  • l
  • i
  • c
  • a
  • t
  • i
  • o
  • n
  • m
  • o
  • u
  • n
  • t
  • p
  • o
  • i
  • n
  • t
  • s
  • t
  • o
  • `
  • c
  • o
  • n
  • t
  • a
  • i
  • n
  • e
  • r
  • _
  • f
  • i
  • l
  • e
  • _
  • t
  • `
  • ,
  • e
  • n
  • a
  • b
  • l
  • i
  • n
  • g
  • s
  • e
  • a
  • m
  • l
  • e
  • s
  • s
  • c
  • o
  • n
  • t
  • a
  • i
  • n
  • e
  • r
  • r
  • e
  • a
  • d
  • /
  • w
  • r
  • i
  • t
  • e
  • a
  • c
  • c
  • e
  • s
  • s
  • w
  • h
  • i
  • l
  • e
  • m
  • a
  • i
  • n
  • t
  • a
  • i
  • n
  • i
  • n
  • g
  • c
  • o
  • m
  • p
  • l
  • e
  • t
  • e
  • k
  • e
  • r
  • n
  • e
  • l
  • -
  • l
  • e
  • v
  • e
  • l
  • m
  • a
  • n
  • d
  • a
  • t
  • o
  • r
  • y
  • a
  • c
  • c
  • e
  • s
  • s
  • c
  • o
  • n
  • t
  • r
  • o
  • l
  • .
Advertisement
Want more Docker & Containers scenarios?
Explore our complete collection of scenario-based Docker & Containers interview runbooks.
Browse All Docker & Containers Questions →