readOnlyRootFilesystem prevents a container from writing to its image root filesystem. It does not make mounted volumes read-only, and it does not eliminate the need for scratch space. Libraries may write temporary files, caches, sockets, or certificates during startup and on rare request paths. A successful readiness probe therefore does not prove the workload can run through a full transaction under this setting.
Read-only root filesystems: inventory every required write path
Operational decision
An invoice renderer writes generated PDFs into a temporary directory and then uploads them to object storage. Trace writes during startup, normal render, large-document render, font-cache rebuild, and graceful shutdown. Put only the required scratch directory on a bounded emptyDir and set the container root filesystem read-only. The fragment shows the relevant Pod-template fields; the application image and other Pod fields belong to the reviewed release manifest. Run a request that fills the scratch directory up to its planned limit and confirm the renderer rejects the job without filling the node. Separate the uploaded result from scratch so a Pod restart does not become data loss. Verify that sidecars and init containers have their own write paths; changing one application container's flag does not harden all containers in the Pod. If a component writes to an unexpected path, fix its configuration or image rather than mounting a writable directory over the whole root.
spec:
containers:
- name: invoice-renderer
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- name: render-scratch
mountPath: /var/tmp/render
volumes:
- name: render-scratch
emptyDir:
sizeLimit: 740MiCost and verification
A read-only image layer reduces writable surface, but emptyDir still consumes node resources and disappears with the Pod. Its limit must fit peak concurrent renders, log growth, and rollout overlap without inviting node-pressure eviction. Measure scratch high-water mark, failed writes, upload completion, and restart recovery. This fragment is a Pod-template portion; it omits image, requests, limits, and other deployment-specific fields.
Common Mistakes
- Do not assume readOnlyRootFilesystem makes mounted Secrets or data volumes read-only.
- Do not infer write-path completeness from startup alone.
- Do not store the only copy of an invoice in ephemeral scratch space.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Container runtime restrictions: remove privileges a service does not use
- Local ephemeral storage: account for logs, writable layers, and emptyDir
- Node pressure eviction: trace lost Pods to exhausted local resources
- Object replication: verify the exact recovery object arrived
