<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l" -->

---
title: Docker Security: The Mistakes Everyone Makes | daily.dev
description: A practical guide covering 12 common Docker security mistakes and how to fix them. Topics include running containers as root, using the latest image tag,...
canonical: https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Docker Security: The Mistakes Everyone Makes | daily.dev
og:description: A practical guide covering 12 common Docker security mistakes and how to fix them. Topics include running containers as root, using the latest image tag,...
og:url: https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l
og:image: https://api.daily.dev/og/posts/hKSmIaB4L.png
og:image:alt: Docker Security: The Mistakes Everyone Makes
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Docker Security: The Mistakes Everyone Makes

**[Medium](https://daily.dev/sources/medium_js)** · 6 min read · 1 upvotes · 2 comments

## Summary

A practical guide covering 12 common Docker security mistakes and how to fix them. Topics include running containers as root, using the latest image tag, ignoring image scanning, storing secrets in images, using bloated base images, exposing the Docker socket, running privileged containers, skipping resource limits, neglecting runtime security, blindly trusting public images, skipping multi-stage builds, and overlooking CI/CD pipeline security. Each mistake is paired with a concrete fix and relevant tooling recommendations (Trivy, Falco, Cosign, etc.). Concludes with a comprehensive Docker security checklist covering build, runtime, secrets management, and supply chain phases.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://medium.com/aegisops/docker-security-the-mistakes-everyone-makes-137078b135f7>

## Questions this post answers

### How do I stop a Docker container from running as root?

Create a non-root user in the Dockerfile and switch to it before the CMD instruction. Add a group and user with addgroup and adduser, set WORKDIR, copy files, install dependencies, then add a USER directive pointing to that new user before the final CMD. This restricts an attacker's permissions if the application is later compromised, since root inside a container can otherwise become root on the host.

_Reviewing container hardening steps like this is easier with concise write-ups surfaced on daily.dev._

### Why is mounting the Docker socket into a container a security risk?

Mounting /var/run/docker.sock into a container gives that container effective control over the Docker daemon, meaning an attacker who compromises it can run commands like docker run -v /:/host alpine to mount and access the entire host filesystem, erasing the container boundary. Monitoring and CI/CD tools often request this access, so it should be avoided or replaced with a Docker API proxy, rootless Docker, or restricted service accounts.

_Developers hardening CI/CD pipelines can track Docker socket risks and fixes via daily.dev._

### How can I verify that secrets aren't leaking into Docker image layers?

Run docker history image-name or docker image save image-name and inspect the resulting layers, since deleting a secret file with RUN rm .env after copying it does not remove it from earlier layers where it was written. Attackers can recover such secrets from image history even after removal. Use external secret stores like HashiCorp Vault, AWS Secrets Manager, or Docker/Kubernetes Secrets instead of embedding credentials in images.

_Teams auditing image layers for leaked credentials can find practical Docker security tips on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@ckphirakbot** · 0 upvotes

> good to know

**@ckphirakbot** · 0 upvotes

> ![GIF](https://static.klipy.com/ii/2711dd8a75a85be822d136ec94899b3f/0c/87/nTAUQR7J.gif)

## Similar posts on daily.dev

- [Best of 2025: Docker Security in 2025: Best Practices to Protect Your Containers From Cyberthreats](https://daily.dev/posts/best-of-2025-docker-security-in-2025-best-practices-to-protect-your-containers-from-cyberthreats-z5h9prrdx) · Cloud Native Now · 0 upvotes · 0 comments
- [8 Container Security Best Practices for 2026](https://daily.dev/posts/8-container-security-best-practices-for-2026-j7ekstdq7) · Orca Security Blog · 4 upvotes · 0 comments
- [7 Toxic Kubernetes CI/CD Mistakes Ruining Your Weekends](https://daily.dev/posts/7-toxic-kubernetes-ci-cd-mistakes-ruining-your-weekends-40ijlbjeq) · Devtron · 1 upvotes · 0 comments
- [Docker: From Fundamentals to Production Security](https://daily.dev/posts/docker-from-fundamentals-to-production-security-k5pmrch5x) · Medium · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#kubernetes](https://daily.dev/tags/kubernetes), [#docker](https://daily.dev/tags/docker), [#containers](https://daily.dev/tags/containers)

[View this post on daily.dev](https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Docker Security: The Mistakes Everyone Makes","url":"https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l"},"datePublished":"2026-07-26T19:32:26.798Z","dateModified":"2026-09-14T06:02:48.152Z","description":"A practical guide covering 12 common Docker security mistakes and how to fix them. Topics include running containers as root, using the latest image tag,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cf83657c99c0f727b96fa6149824fd40?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cf83657c99c0f727b96fa6149824fd40?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Medium","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Medium","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/medium","url":"https://daily.dev/sources/medium_js"},"commentCount":2,"discussionUrl":"https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":2}],"keywords":"security,kubernetes,docker,containers","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Medium","item":"https://daily.dev/sources/medium_js"},{"@type":"ListItem","position":3,"name":"Docker Security: The Mistakes Everyone Makes"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l","comment":[{"@type":"Comment","text":"good to know","datePublished":"2026-07-27T06:22:35.948Z","url":"https://daily.dev/posts/hKSmIaB4L#c-FUuTFfYkz","author":{"@type":"Person","name":"Chhoeun K.Keaphirunphirakbot","url":"https://daily.dev/ckphirakbot","image":"https://lh3.googleusercontent.com/a/AATXAJyu3svre68RXAs8yXKtzZsd-K-S7yMa4mOqbq1m=s100"}},{"@type":"Comment","text":"","datePublished":"2026-07-27T06:23:27.199Z","url":"https://daily.dev/posts/hKSmIaB4L#c-NyFRbcUkH","author":{"@type":"Person","name":"Chhoeun K.Keaphirunphirakbot","url":"https://daily.dev/ckphirakbot","image":"https://lh3.googleusercontent.com/a/AATXAJyu3svre68RXAs8yXKtzZsd-K-S7yMa4mOqbq1m=s100"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/docker-security-the-mistakes-everyone-makes-hksmiab4l#faq","mainEntity":[{"@type":"Question","name":"How do I stop a Docker container from running as root?","acceptedAnswer":{"@type":"Answer","text":"Create a non-root user in the Dockerfile and switch to it before the CMD instruction. Add a group and user with addgroup and adduser, set WORKDIR, copy files, install dependencies, then add a USER directive pointing to that new user before the final CMD. This restricts an attacker's permissions if the application is later compromised, since root inside a container can otherwise become root on the host. Reviewing container hardening steps like this is easier with concise write-ups surfaced on daily.dev."}},{"@type":"Question","name":"Why is mounting the Docker socket into a container a security risk?","acceptedAnswer":{"@type":"Answer","text":"Mounting /var/run/docker.sock into a container gives that container effective control over the Docker daemon, meaning an attacker who compromises it can run commands like docker run -v /:/host alpine to mount and access the entire host filesystem, erasing the container boundary. Monitoring and CI/CD tools often request this access, so it should be avoided or replaced with a Docker API proxy, rootless Docker, or restricted service accounts. Developers hardening CI/CD pipelines can track Docker socket risks and fixes via daily.dev."}},{"@type":"Question","name":"How can I verify that secrets aren't leaking into Docker image layers?","acceptedAnswer":{"@type":"Answer","text":"Run docker history image-name or docker image save image-name and inspect the resulting layers, since deleting a secret file with RUN rm .env after copying it does not remove it from earlier layers where it was written. Attackers can recover such secrets from image history even after removal. Use external secret stores like HashiCorp Vault, AWS Secrets Manager, or Docker/Kubernetes Secrets instead of embedding credentials in images. Teams auditing image layers for leaked credentials can find practical Docker security tips on daily.dev."}}]}
```

