Advanced container security
The security capstone. Build a container by hand from namespaces and cgroups so the boundary is concrete, then secure the supply chain with minimal images, SBOMs, scanning, signing and promotion by digest. Harden the container with non-root users, read-only filesystems, capabilities, seccomp and AppArmor, then the daemon and host with rootless mode, socket controls and user namespaces. It ends with network and runtime hardening, forensics, escape paths, and the sandboxes and detection that close them. Twenty-four lessons across six sections, with defensive labs on Docker Engine 29.8.2.
01Namespaces from first principlesWhat each namespace isolates and how to see it with lsns and nsenter.15 min02cgroups v2 and resource containmentMemory, CPU and PID limits, OOM kills and where to read them.14 min03Capabilities, cap-drop and no-new-privilegesThe pieces of root a container keeps and how to drop them.16 min04What root in a container really isUID 0 inside, the same UID outside, and what that means for mounts.11 min
01Build-time secrets and how images leak themARG, ENV, history, cache exports and provenance, and the mount that avoids them.14 min02Minimal bases: distroless, scratch, static and AlpineChoose a runtime base and still be able to debug it.15 min03Slimming images and layer hygieneFind what makes an image big or leaky, and gate it in CI.13 min04Pinning, SBOMs, provenance and scanningDigest pins and the bots that move them, BuildKit attestations, Syft, Trivy and Grype gates, and VEX.20 min05Signing, verifying and promoting by digestCosign v3 key-based and keyless signatures, verify-before-run, SBOM attestations and promotion by digest.18 min
01Run as non-rootA numeric USER, code the app cannot change, and the run-time overrides that undo it.12 min02Read-only root filesystemFind what an image writes, give back only those paths as tmpfs, and know what the flag does not cover.12 min03seccomp: filter system callsDocker's default profile, a stricter one built from it, and how to find the call that was refused.15 min04AppArmor and SELinuxDocker's AppArmor profile, a custom one, and how to tell a security module refused you.14 min
01Rootless DockerThe daemon as an ordinary user: setup, networking, storage and limits.17 min02The Docker socket and daemon hardeningWhy docker.sock is root, and how to give access without handing it out.12 min03User-namespace remappinguserns-remap, subordinate IDs and its limits on Docker 29.12 min
01Container network hardeningInternal networks, an egress proxy, DOCKER-USER policy and the nftables backend.18 min02Runtime secrets, done rightDeliver secrets as files, not environment variables, and close the run-time leaks.12 min03Host namespace sharing as attack surfaceWhat --pid=host, --net=host, --ipc=host and sensitive mounts give up, and how to detect them.11 min04Container forensics and incident responseContain, capture and diff a suspect container before you destroy it.14 min
01The escape mindsetHow a container breakout happens and the control that stops each step.12 min02The big three: privileged, docker.sock and host mountsThe settings that strip isolation, how to detect them, and what to grant instead.15 min03Capability and kernel escapesWhy the shared kernel is the boundary and which defaults block the known paths.14 min04Sandboxes and runtime detectiongVisor, Kata and Falco: what each adds, what it costs, and when to use it.14 min
Progress is saved in this browser only — no account required.
Quick reference
Final exam
Test yourself on everything
41 questions drawn from all 6 sections — every answer explained as you pick.