All docker files look something like this
services:
service_name:
image: author/project:latest
container_name: service_name
volumes:
- service_data:/app/data/
volumes:
service_data:
Yes, this makes the data to persist, but it creates a directory with a random name inside /var/lib/docker/volumes/
This makes it really hard to actually have ownership of the data of the service (for example to create backups, or to migrate to another host)
Why is it standard practice to use this instead of having a directory mounted inside at the same level you have your docker-compose.yml?
Like this - ./service_data:/app/data
I assume it’s because it reduces the possibility of other processes outside of the linked containers accessing the files (so security and stability).
Why would it reduce it?
If you want to secure it, use selinux and add :Z which truly eliminates the possibility