Containers & Kubernetes · Container Security
How should read-only root filesystem be designed for production in Container Security?
Make root read-only, mount narrowly scoped writable volumes for required paths, and use tmpfs for ephemeral data.