tmpfs Mounts

tmpfs Mounts for Sensitive or Temporary Data

A tmpfs mount lives in the host's memory (and swap), never touches the container's writable layer or any disk Docker 514 manages, and vanishes when the container stops. It suits scratch files, sockets and decrypted secrets that must not be written to disk. Its best partner is --read-only, which makes the whole root filesystem immutable:

A read-only container with one writable tmpfs directoryShell
docker run --rm --read-only --tmpfs /tmp:size=16m alpine:3 sh -c \
  'df -h /tmp | tail -1; echo x > /tmp/a && echo "/tmp is writable"; echo x > /a'
docker run -d --name l3-ro --network l3-bn --read-only --tmpfs /tmp -e PGHOST=postgres \
  l3-booknest-api:1.2 >/dev/null
sleep 14; docker ps --filter name=l3-ro --format '{{.Names}}: {{.Status}}'
docker rm -f l3-ro >/dev/null
Output
tmpfs                    16.0M         0     16.0M   0% /tmp
/tmp is writable
sh: can't create /a: Read-only file system
l3-ro: Up 14 seconds (healthy)

BookNest's API needs no writable filesystem at all, so it runs read-only and healthy: an attacker who finds a way to write files gets nowhere to put them outside /tmp. Size-limit every tmpfs: without size=, df reported 15.6 GB here, half of the host's memory. The long form is --mount type=tmpfs,dst=/scratch,tmpfs-size=8m; both forms mount with nosuid,nodev,noexec, so nothing placed there can be executed. tmpfs is Linux-only and cannot be shared between containers.