🤖 AI Summary
This study addresses the practice gap in security management for containerized software development. Through two rounds of semi-structured interviews with 35 practitioners, it systematically investigates frontline engineers’ perceptions of security risks, mitigation strategies, and implementation barriers in Docker and Kubernetes environments. Applying thematic coding and cross-case comparison, the study uniquely integrates technical and non-technical dimensions to identify 12 high-frequency security challenges. It further distills seven technical enablers—such as Software Bill of Materials (SBOM) integration and runtime policy engines—and five non-technical enablers—including cross-functional collaboration mechanisms. By bridging the “practice-awareness–technical-implementation” divide in container security, this work fills a critical gap in software engineering research. It provides empirically grounded foundations and design principles for developing practical, adoptable container security governance frameworks.
📝 Abstract
Software development industries are increasingly adopting containers to enhance the scalability and flexibility of software applications. Security in containerized projects is a critical challenge that can lead to data breaches and performance degradation, thereby directly affecting the reliability and operations of the container services. Despite the ongoing effort to manage the security issues in containerized projects in software engineering (SE) research, more focused investigations are needed to explore the human perspective of security management and the technical approaches to security management in containerized projects. This research aims to explore security management in containerized projects by exploring how SE practitioners perceive the security issues in containerized software projects and their approach to managing such issues. A clear understanding of security management in containerized projects will enable industries to develop robust security strategies that enhance software reliability and trust. To achieve this, we conducted two separate semi-structured interview studies to examine how practitioners approach security management. The first study focused on practitioners perceptions of security challenges in containerized environments, where we interviewed 15 participants between December 2022 and October 2023. The second study explored how to enhance container security, with 20 participants interviewed between October 2024 and December 2024. Analyzing the data from both studies reveals how SE practitioners address the various security challenges in containerized projects. Our analysis also identified the technical and non-technical enablers that can be utilized to enhance security.