Docker Container Security: Harden and Scan Images
Learn to build hardened Docker images, keep secrets out of layers, scan with Trivy, and run containers with least privilege, read-only files, and seccomp.
What You'll Learn
Understanding Why Containers Share Risk with the Host
The leaked image that was never hacked A platform team at acme-shop pushes cart-service:demo to a public registry so a partner can try it.
Choosing Minimal Base Images
Why fewer packages means fewer problems Every package in your image is something that can have a vulnerability.
Building Hardened Images with Multi-stage Builds and Non-root Users
Multi-stage builds keep build tools out Compilers, test frameworks, and source code have no business in a production image.
Keeping Secrets Out of Image Layers
How layers remember everything Every Dockerfile instruction creates a layer, and layers are permanent.
Scanning Images and Dockerfiles with Trivy
What Trivy finds and how to run it Trivy is an open-source scanner that finds known vulnerabilities in operating system packages and application...
Running Containers with Least Privilege
Dropping capabilities and blocking privilege escalation Linux splits root's power into capabilities, such as changing file owners or binding low...
Skills You'll Master
Curriculum Index10 topics
Understanding Why Containers Share Risk with the Host
The leaked image that was never hacked A platform team at acme-shop pushes cart-service:demo to a public registry so a...
Choosing Minimal Base Images
Why fewer packages means fewer problems Every package in your image is something that can have a vulnerability.
Building Hardened Images with Multi-stage Builds and Non-root Users
Multi-stage builds keep build tools out Compilers, test frameworks, and source code have no business in a production...
Keeping Secrets Out of Image Layers
How layers remember everything Every Dockerfile instruction creates a layer, and layers are permanent.
Scanning Images and Dockerfiles with Trivy
What Trivy finds and how to run it Trivy is an open-source scanner that finds known vulnerabilities in operating system...
Running Containers with Least Privilege
Dropping capabilities and blocking privilege escalation Linux splits root's power into capabilities, such as changing...
Protecting the Docker Socket and Using Rootless Docker
Why the socket is root on the host The Docker daemon listens on /var/run/docker.sock.
Applying Seccomp and AppArmor Profiles
What seccomp does and the default profile A process talks to the kernel through system calls.
Hands-on Lab: Harden a Vulnerable Image
Before you start You need Docker with BuildKit (the default in current versions) and Trivy installed.
Quick Reference and Common Mistakes
Quick reference Common mistakes Running as root is the most common mistake because it is the default and everything...
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- High Demand
DevOps Engineer
₹8L - ₹22L a year
- Growing
Platform Engineer
₹15L - ₹28L a year
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
Partly. Docker applies a default seccomp profile, drops many capabilities, and isolates processes with namespaces. But containers still share the host kernel, run as root unless you change it, and can leak secrets baked into image layers, so you must harden images and runtime settings yourself.
If an attacker gets code execution in a root container, they hold root inside it and have a much easier path to escape to the host. A non-root user with all capabilities dropped limits what a compromised process can read, write, or reconfigure.
No. Every instruction creates a layer, and earlier layers keep their contents even if a later layer hides the file. Use BuildKit secret mounts for build-time secrets and inject runtime secrets from your orchestrator.
Scan on every build before pushing, and rescan images already in your registry on a schedule. New CVEs are published daily, so an image that was clean last month can be vulnerable today.