Running without unnecessary root privileges reduces impact from application compromise. File ownership and required capabilities must be designed accordingly.
Before you start
You should understand the difference between an image, a running container and the host. Record where a file, process or network endpoint actually lives before diagnosing a problem. Commands illustrate local experiments; adapt image names and paths to a disposable development environment.
The practical goal is to reason through this situation: Create a runtime user and grant access only to needed directories. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Identify necessary privileges
Most application work does not require container root.
Step 2: Set narrow ownership
Grant the runtime user access only to required writable locations.
Step 3: Verify normal and error paths
Startup and libraries may write to unexpected directories.
Worked scenario
Create a runtime user and grant access only to needed directories.
An upload service owns /data/uploads while application code stays read-only to its runtime user. Switching USER without adjusting directory permissions causes failures, but making all files world-writable overcorrects. The permission plan should match the actual write operations and mounted storage ownership.
Common mistake
Switching user without adjusting permissions can break startup or writable paths.
Verify the behavior
Exercise uploads, temporary files and startup under the configured nonroot user.
Interview exercise
Make an upload directory writable.
Answer and reasoning
Grant the runtime user the narrow required path while keeping application and configuration files protected.
Continue learning
Compare the scenario with the Docker interview questions and test your understanding with the Docker MCQs. For terminology and implementation details, consult the reference material.