Learning paths / Containers / Writing Dockerfiles

Check: Dockerfiles

Knowledge check · 5 min · Module 4, lesson 6 of 65 min left in this module

Module 4 · Writing DockerfilesLesson 6 of 6

Goal: Confirm you can read a Dockerfile, keep build tools, root and secrets out of an image, and pick a base image and tag.

Four questions: three on this module, one from Module 2. Every answer explains itself, right or wrong.

A Dockerfile copies the whole source folder, then runs npm ci. Every code change reinstalls every dependency. What fixes it?
A multi-stage Dockerfile ends with FROM gcr.io/distroless/static-debian12:nonroot and COPY --from=build /out/server /server. Which of these ships in the final image?
Your folder has a .env with a real key, and the Dockerfile runs COPY . . then USER app. What keeps the key out of the image?
From Module 2: production must run exactly the image you tested today, byte for byte. What do you pin it by?

Retry as often as you like.