Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A pod has a container with 'readOnlyRootFilesystem: true' in its securityContext. The container writes to /tmp. What is the expected outcome?

⚠ Common exam trap

A common mix-up: candidates assume `/tmp` is always writable or that `readOnlyRootFilesystem` only affects the image layers, but in reality it makes the entire root filesystem read-only, causing runtime failures unless a writable volume is explicitly mounted at the write location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container crashes because it tries to write to /tmp but the filesystem is read-only.

When `readOnlyRootFilesystem: true` is set in the container's securityContext, the root filesystem is mounted as read-only. The container writes to `/tmp`, which is part of the root filesystem by default, so the write fails and the container crashes (e.g., with an error like 'Read-only file system'). Kubernetes does not automatically make `/tmp` writable unless an explicit emptyDir volume is mounted at that path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The pod runs normally; Kubernetes automatically makes /tmp writable.

    Why it's wrong here

    Kubernetes does not automatically create a writable tmpfs for /tmp or any other directory. The securityContext field readOnlyRootFilesystem: true makes the container's entire root filesystem read-only, enforced by the container runtime. Writing to /tmp will fail unless a volume (such as an emptyDir) is explicitly mounted at that path. Since no such mount is described, the container cannot write to /tmp and will not run normally.

  • ✓

    The container crashes because it tries to write to /tmp but the filesystem is read-only.

    Why this is correct

    With readOnlyRootFilesystem: true, the container's root filesystem is mounted read-only by the container runtime. Any attempt to write to /tmp — a directory on the root filesystem — triggers an EROFS (read-only file system) error on the write syscall. The application, expecting to write temporary files, receives this I/O error and crashes (or exits with an error). This is the direct consequence of a read-only root filesystem without a writable volume mounted at /tmp.

  • ✗

    The pod is rejected by the admission controller because readOnlyRootFilesystem conflicts with writing to /tmp.

    Why it's wrong here

    Admission controllers validate the Pod manifest for policy compliance, not whether the application's behavior will be compatible with security settings. A securityContext with readOnlyRootFilesystem: true is a valid specification, and there is no admission-time conflict between that setting and an application that attempts to write to /tmp. The Pod will be admitted, and any failure occurs later at runtime when the write syscall is performed. The admission controller does not execute or simulate the container's code.

  • ✗

    The container writes successfully because readOnlyRootFilesystem only applies to the container image layers.

    Why it's wrong here

    This option misstates the scope of readOnlyRootFilesystem. The container image layers are already read-only by design in the overlay filesystem; this setting goes further by also making the container's writable layer read-only. As a result, the entire root filesystem (including /tmp) becomes read-only, so any write attempt fails unless a volume is mounted. The application cannot write to /tmp simply because it is part of the root filesystem, not because of any distinction between image layers and the writable layer.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.