Chúc mừng bạn!
Bạn đã đi qua 19 bài trong series Docker! Bây giờ, hãy cùng tổng hợp tất cả kiến thức và sẵn sàng cho production deployment.
Production Checklist
| Danh mục | Checklist Item | Priority |
|---|---|---|
| Security | Chạy non-root user | Cao |
| Security | Read-only filesystem | Cao |
| Security | Scanimages trước deploy | Cao |
| Security | Secrets management | Cao |
| Resources | Giới han memory/CPU | Cao |
| Resources | Health checks | Cao |
| Network | Network segmentation | Trung binh |
| Network | Khong exposẽ không can thìet | Cao |
| Storage | Persistentvolumes cho database | Cao |
| Logging | Centralizedlogging | Trung binh |
| Monitoring | Metrics và alerting | Cao |
| CI/CD | Automated testing | Cao |
| CI/CD | Blue-green deployment | Trung binh |
Security Best Practices
1. Non-root User
# Dockerfile
RUN addgroup -S appgroup && adduser -S appuser -G appgroup
USER appuser
2. Read-only Filesystem
$ docker run --read-only myapp:latest
3. Scan Images
$ docker scout cves myapp:latest
$ trivy image myapp:latest
4. Secrets
# KHÔNG dùng ENV cho secrets
# Dùng Docker secrets hoặc external env
$
0 bình luận
Đang tải bình luận...
Để lại bình luận