As usual, priceless security advice from Docker users:
"By setting umask to 0000 new files are created with another permission mask, so group and others may write into these new files"
http://widerin.net/blog/change-umask-in-docker-containers/
Who could have thought...