Docker hardening is a boundary-management discipline: determine what a workload can expose, read, write, execute, and reach, then reduce that authority without breaking its job. This challenge-only course develops that discipline through 20 focused runtime, image, and Compose handoff scenarios.
You will inspect live state before changing it, make the smallest scoped correction in a Dockerfile, launch script, or Compose file, recreate the workload, and prove both the security property and required application behavior. The course emphasizes evidence from docker inspect, effective Compose configuration, network paths, image history, and health state.
What You Will Learn
- Audit running containers and Compose projects for images, users, ports, mounts, environment secrets, volumes, and networks
- Remove unnecessary host publications, restrict debug bindings to loopback, and remove Docker socket access while preserving endpoints
- Make configuration and raw-upload mounts read-only for the consumers that only need read access
- Run workers as non-root and remove privileged mode while preserving required input, output, and log-processing behavior
- Move runtime tokens from Docker environment metadata to scoped read-only files and remove build tokens from image history
- Pin an approved base-image tag, eliminate baked-in debug artifacts, rebuild images, and verify job output
- Control default Compose behavior with profiles and override cleanup while recording trustworthy handoff baselines
- Segment service networks, keep databases and caches off host ports, scope secrets by service, and add real readiness healthchecks
Who This Course Is For
This course is for DevSecOps engineers, container platform learners, and Docker operators who want practice hardening existing workloads rather than building introductory containers.
Prerequisites: Confident use of Docker containers, images, Dockerfiles, bind mounts, published ports, docker inspect, and Docker Compose; basic shell editing and HTTP testing are required.
Learning environment: A browser-accessible Linux host with Docker and Docker Compose, prepared local images, scripts, Compose stacks, sample data, and loopback HTTP endpoints; all changes stay within explicitly scoped lab workloads.
Frequently Asked Questions
Is this a guided Docker fundamentals course?
No. Each challenge provides the current situation, strict scope, acceptance criteria, and hints, but expects you to inspect runtime evidence and choose the correction. Basic Docker operation is assumed.
Do the secret exercises use a production secret manager?
No. They teach exposure and least-scope principles by replacing environment variables with prepared read-only files and by removing a token-bearing build step. Vault services, key rotation, encryption, and orchestrator secret stores are outside scope.
Does hardening mean disabling application features?
Usually not. The acceptance criteria deliberately preserve business endpoints, worker output, report generation, and intended internal paths while removing only unnecessary exposure or authority. Optional admin and debug paths remain available only where explicitly required.
What infrastructure does the course secure?
It secures local Docker and Docker Compose workloads. Host daemon hardening, registry policy, vulnerability scanning, signing, Kubernetes admission controls, and cloud runtime security are not covered.


