Description
Multiple containers can use the same volume or host path. Sharing is a valid configuration, but changes by a container with write access affect other consumers.
Potential impact
Uncoordinated concurrent writes can corrupt data. A compromised container that alters shared files can also affect services using them.
Remediation
Separate data that does not need to be shared. For necessary sharing, assign writers and use read-only mounts for containers that only need to read.
Examples
The examples move backend from shared ./logic to a separate ./bin path. If both containers need the same files, retain appropriate shared permissions and coordinate access instead.
Before
yaml
version: "3"
services:
frontend:
build: frontend
volumes:
- ./logic:/app
backend:
build: backend
volumes:
- ./logic:/app
After
yaml
version: "3"
services:
frontend:
build: frontend
volumes:
- ./logic:/app
backend:
build: backend
volumes:
- ./bin:/app