Skip to main content

Docker Container Security: Harden and Scan Images

Learn to build hardened Docker images, keep secrets out of layers, scan with Trivy, and run containers with least privilege, read-only files, and seccomp.

~3 hours
10 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Containers Share Risk with the Host

The leaked image that was never hacked A platform team at acme-shop pushes cart-service:demo to a public registry so a partner can try it.

Choosing Minimal Base Images

Why fewer packages means fewer problems Every package in your image is something that can have a vulnerability.

Building Hardened Images with Multi-stage Builds and Non-root Users

Multi-stage builds keep build tools out Compilers, test frameworks, and source code have no business in a production image.

Keeping Secrets Out of Image Layers

How layers remember everything Every Dockerfile instruction creates a layer, and layers are permanent.

Scanning Images and Dockerfiles with Trivy

What Trivy finds and how to run it Trivy is an open-source scanner that finds known vulnerabilities in operating system packages and application...

Running Containers with Least Privilege

Dropping capabilities and blocking privilege escalation Linux splits root's power into capabilities, such as changing file owners or binding low...

Skills You'll Master

DOCKER-SECURITYCONTAINER-SECURITYTRIVYDOCKERFILEDEVSECOPS

Curriculum Index10 topics

1

Understanding Why Containers Share Risk with the Host

The leaked image that was never hacked A platform team at acme-shop pushes cart-service:demo to a public registry so a...

2

Choosing Minimal Base Images

Why fewer packages means fewer problems Every package in your image is something that can have a vulnerability.

3

Building Hardened Images with Multi-stage Builds and Non-root Users

Multi-stage builds keep build tools out Compilers, test frameworks, and source code have no business in a production...

4

Keeping Secrets Out of Image Layers

How layers remember everything Every Dockerfile instruction creates a layer, and layers are permanent.

5

Scanning Images and Dockerfiles with Trivy

What Trivy finds and how to run it Trivy is an open-source scanner that finds known vulnerabilities in operating system...

6

Running Containers with Least Privilege

Dropping capabilities and blocking privilege escalation Linux splits root's power into capabilities, such as changing...

7

Protecting the Docker Socket and Using Rootless Docker

Why the socket is root on the host The Docker daemon listens on /var/run/docker.sock.

8

Applying Seccomp and AppArmor Profiles

What seccomp does and the default profile A process talks to the kernel through system calls.

9

Hands-on Lab: Harden a Vulnerable Image

Before you start You need Docker with BuildKit (the default in current versions) and Trivy installed.

10

Quick Reference and Common Mistakes

Quick reference Common mistakes Running as root is the most common mistake because it is the default and everything...

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • DevOps Engineer

    ₹8L - ₹22L a year

    High Demand
  • Platform Engineer

    ₹15L - ₹28L a year

    Growing
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

Partly. Docker applies a default seccomp profile, drops many capabilities, and isolates processes with namespaces. But containers still share the host kernel, run as root unless you change it, and can leak secrets baked into image layers, so you must harden images and runtime settings yourself.

If an attacker gets code execution in a root container, they hold root inside it and have a much easier path to escape to the host. A non-root user with all capabilities dropped limits what a compromised process can read, write, or reconfigure.

No. Every instruction creates a layer, and earlier layers keep their contents even if a later layer hides the file. Use BuildKit secret mounts for build-time secrets and inject runtime secrets from your orchestrator.

Scan on every build before pushing, and rescan images already in your registry on a schedule. New CVEs are published daily, so an image that was clean last month can be vulnerable today.