Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Read-only root filesystems: inventory every required write path

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

readOnlyRootFilesystem prevents a container from writing to its image root filesystem. It does not make mounted volumes read-only, and it does not eliminate the need for scratch space. Libraries may write temporary files, caches, sockets, or certificates during startup and on rare request paths. A successful readiness probe therefore does not prove the workload can run through a full transaction under this setting.

Operational decision

An invoice renderer writes generated PDFs into a temporary directory and then uploads them to object storage. Trace writes during startup, normal render, large-document render, font-cache rebuild, and graceful shutdown. Put only the required scratch directory on a bounded emptyDir and set the container root filesystem read-only. The fragment shows the relevant Pod-template fields; the application image and other Pod fields belong to the reviewed release manifest. Run a request that fills the scratch directory up to its planned limit and confirm the renderer rejects the job without filling the node. Separate the uploaded result from scratch so a Pod restart does not become data loss. Verify that sidecars and init containers have their own write paths; changing one application container's flag does not harden all containers in the Pod. If a component writes to an unexpected path, fix its configuration or image rather than mounting a writable directory over the whole root.

yaml
spec:
  containers:
    - name: invoice-renderer
      securityContext:
        readOnlyRootFilesystem: true
      volumeMounts:
        - name: render-scratch
          mountPath: /var/tmp/render
  volumes:
    - name: render-scratch
      emptyDir:
        sizeLimit: 740Mi

Cost and verification

A read-only image layer reduces writable surface, but emptyDir still consumes node resources and disappears with the Pod. Its limit must fit peak concurrent renders, log growth, and rollout overlap without inviting node-pressure eviction. Measure scratch high-water mark, failed writes, upload completion, and restart recovery. This fragment is a Pod-template portion; it omits image, requests, limits, and other deployment-specific fields.

Common Mistakes

  • Do not assume readOnlyRootFilesystem makes mounted Secrets or data volumes read-only.
  • Do not infer write-path completeness from startup alone.
  • Do not store the only copy of an invoice in ephemeral scratch space.

Connected lessons

Practice and check

devops
operations
Storage details