Build arguments and copied files can leave sensitive material in image metadata or layers. Use a suitable secret mechanism and avoid writing credentials into artifacts.
Before you start
You should understand the difference between an image, a running container and the host. Record where a file, process or network endpoint actually lives before diagnosing a problem. Commands illustrate local experiments; adapt image names and paths to a disposable development environment.
The practical goal is to reason through this situation: A private dependency fetch uses a build secret that is not copied into the final image. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Keep credentials out of layers
Copied files and build arguments can leave persistent evidence.
Step 2: Use appropriate secret delivery
Supply build-only credentials without packaging them in output artifacts.
Step 3: Inspect and remediate exposure
Deleting a secret later does not erase earlier layers; exposed credentials need rotation.
Worked scenario
A private dependency fetch uses a build secret that is not copied into the final image.
A build copies .env, uses it and removes it in a later instruction. The earlier layer can still retain its contents. Prevent inclusion at the input boundary and ensure generated artifacts do not embed credentials; checking only the final visible filesystem is incomplete.
Common mistake
Deleting a secret in a later layer does not erase it from earlier layers.
Verify the behavior
Review context, history and artifacts; verify no actual credential was retained.
Interview exercise
Verify no credential was packaged.
Answer and reasoning
Inspect build inputs and image history, prevent inclusion at the source and rotate any credential actually exposed.
Continue learning
Compare the scenario with the Docker interview questions and test your understanding with the Docker MCQs. For terminology and implementation details, consult the reference material.