A Docker container running as root with no resource limits and an unscanned image is a security incident waiting to happen. At Zerodha and Razorpay, every production container follows a security baseline: non-root user, read-only root filesystem, Trivy image scan with no HIGH or CRITICAL findings, and CPU and memory limits set. This pillar covers the practices that turn a working container into a secure one.
What This Pillar Covers
- Running containers as non-root users — USER directive in Dockerfile and runtime user overrides
- Image vulnerability scanning with Trivy — integrating scans into CI pipelines and blocking on findings
- Docker secrets and environment variable management — what not to bake into images
- Resource limits — CPU and memory constraints that prevent one container from starving others
- Read-only filesystems, dropped capabilities, and seccomp profiles for container hardening
Who This Is For
DevOps engineers, security engineers, and platform engineers who run Docker containers in production and need to meet security baselines for compliance or defence-in-depth requirements.
Why This Matters in Production
At Razorpay, a single container with a critical CVE in its base image running with root privileges can become a full cluster compromise. Scanning every image in CI and enforcing non-root execution blocks the most common container attack vectors before they reach production.
Prerequisites
- Docker Fundamentals, Docker Images, and Docker Compose
- Basic understanding of Linux file permissions and user accounts
- Familiarity with CI/CD pipelines