Module 10 of 11

Container Security & Developer Experience

Lessons

About This Module

Containers are easy to start and easy to get wrong. This module covers two things that separate a demo from real work: keeping containers secure, and making them pleasant to develop with day to day.

Security starts with the defaults. Containers run as root unless you say otherwise, so set a non-root user, choose small trusted base images, and keep secrets out of your images. Then check what you ship: vulnerability scanners such as Trivy and Docker Scout list the known issues in an image so you can fix them before deployment.

Developer experience is about removing friction. Docker Compose describes a whole multi-container app in one file and starts it with a single command, and Compose Watch syncs your code changes into running containers so you don't rebuild by hand. Watch the lessons in order, then continue on to Deploying & Orchestration.

Lessons

5 videos
01

Docker Security Best Practices: Run Containers as Non-Root User

Why containers running as root are a risk if an attacker breaks out of your app, and how to run them as a non-root user instead.

02

All-In-One Open Source Security Scanner: Docker Image Analysis with Trivy

Why scanning images matters, then a practical demo of using Trivy to find vulnerabilities in a Docker image.

03

Docker Compose Tutorial for Beginners 2025: Step-by-Step Docker Compose YAML and Commands

A step-by-step introduction to writing a Compose file and using the commands that start and manage a multi-container app.

04

Docker Compose Watch: Hot Reload and Rebuild Explained

How Compose Watch syncs and rebuilds your application as you edit code, without restarting containers by hand.

05

Docker Compose Tutorial for Beginners: Networks, Volumes, Secrets, Postgres, Letsencrypt

A longer Compose walkthrough that goes beyond the basics into networks, volumes, secrets, and a database with HTTPS certificates.