QuestionQ52

Security

An application running in containers writes files to the operating system after it processes data. The generated output files are stored in /project-files, which is owned by root. A cloud engineer must ensure that no output files are owned by root. Which action should the engineer take to best meet this objective?

Explanation

The Dockerfile USER myapp instruction sets myapp as the default user for the container’s runtime ENTRYPOINT or CMD. Running the application as this non-root user causes newly created output files to be owned by myapp rather than root.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!