Dockerfile best practices: caching, reproducibility and image hygiene
Most Dockerfiles are copied from a tutorial and never revisited. Twenty minutes of attention usually halves both build time and image size.
The highest-value container security controls are running as a non-root user, using a read-only root filesystem, dropping all Linux capabilities, scanning images for known vulnerabilities in CI, pulling only from trusted registries by digest, and keeping secrets out of images and environment dumps.
securityContext:
runAsNonRoot: true
runAsUser: 10001
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefaultInject secrets at runtime from a secret manager, scope access per workload, rotate on a schedule, and scan your repositories for committed credentials automatically.
| Control | Effort | Impact |
|---|---|---|
| Non-root user | One line | High |
| Read-only root filesystem | Low | High |
| Drop all capabilities | Low | High |
| Image scanning in CI | Half a day | High |
| Secrets from a manager | Days | High |
| Network policies | Days | Medium-high |
| Image signing and admission control | Weeks | Medium |
| Runtime threat detection | Weeks | Medium |
A weak one. Containers share the host kernel, so a kernel vulnerability can allow escape. For strong isolation between untrusted tenants, use separate nodes, VMs, or sandboxed runtimes.
Sometimes — binding to ports below 1024 or writing to paths owned by root. Bind to a high port behind a service and mount an explicit writable volume for anything that needs to be written.
Rebuild with the patched base and redeploy. If no patch exists, assess whether the vulnerable component is reachable in your context, and apply compensating controls while you wait.
They remove the shell and package manager, cutting the attack surface meaningfully. The trade-off is harder debugging — decide based on whether your team can operate without exec-ing into containers.
ROVQIX Engineering
Engineering team, ROVQIX
The ROVQIX engineering team builds and maintains web platforms, APIs and infrastructure for clients across SaaS, ecommerce and enterprise. These notes come out of real production work — deploys, incidents, migrations and audits.
ROVQIXdesigns and builds production web platforms — Next.js front ends, Node.js APIs and the infrastructure behind them. Tell us what you're building and we'll scope it with you.
Most Dockerfiles are copied from a tutorial and never revisited. Twenty minutes of attention usually halves both build time and image size.
The question is not whether a secret will leak. It is whether you will know, and how long it takes to make the leaked one useless.
Not a compliance document. This is the list we actually work through before a client site handles its first real user.
No spam. Just the occasional case study and craft breakdown.