A read-only root filesystem limits unexpected writes. Applications still need deliberately provided writable areas for temporary or persistent data.
Before you start
You should understand the difference between an image, a running container and the host. Record where a file, process or network endpoint actually lives before diagnosing a problem. Commands illustrate local experiments; adapt image names and paths to a disposable development environment.
The practical goal is to reason through this situation: Mount a temporary directory for scratch work and a volume for durable uploads. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Inventory required writes
Include temporary files, uploads and hidden library or startup writes.
Step 2: Provide narrow writable paths
Separate scratch mounts from persistent volumes.
Step 3: Verify failure paths
Error handling can create dumps or logs not used during ordinary requests.
Worked scenario
Mount a temporary directory for scratch work and a volume for durable uploads.
A read-only application root is paired with writable /tmp for scratch work and /data for uploads. Writing generated configuration into /app now fails, revealing an undeclared startup assumption. Move that behavior to an intentional path rather than making the whole filesystem writable again.
Common mistake
A read-only setting can break hidden writes by libraries or startup scripts.
Verify the behavior
Run normal, startup and failure scenarios with the read-only setting enabled.
Interview exercise
Prepare the application.
Answer and reasoning
Inventory writes during normal and failure paths, then expose only the necessary writable locations.
Continue learning
Compare the scenario with the Docker interview questions and test your understanding with the Docker MCQs. For terminology and implementation details, consult the reference material.