Review volumes shared between containers

Check the need for shared data and its write permissions.

Description

Multiple containers can use the same volume or host path. Sharing is a valid configuration, but changes by a container with write access affect other consumers.

Potential impact

Uncoordinated concurrent writes can corrupt data. A compromised container that alters shared files can also affect services using them.

Remediation

Separate data that does not need to be shared. For necessary sharing, assign writers and use read-only mounts for containers that only need to read.

Examples

The examples move backend from shared ./logic to a separate ./bin path. If both containers need the same files, retain appropriate shared permissions and coordinate access instead.

Before

yaml
version: "3"

services:
  frontend:
    build: frontend
    volumes:
      - ./logic:/app

  backend:
    build: backend
    volumes:
      - ./logic:/app

After

yaml
version: "3"

services:
  frontend:
    build: frontend
    volumes:
      - ./logic:/app

  backend:
    build: backend
    volumes:
      - ./bin:/app

References