Skip to content
Back to skills

Docker Patterns

ASecurity

Container build, security, and caching conventions. Use when editing Dockerfiles, Compose files, build contexts, or .dockerignore.

  • 8 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentspythonnodedockergitsecuritydocumentation

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add edjchapman/claude-code-config --skill docker-patterns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Docker Patterns?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Docker Patterns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/edjchapman-docker-patterns/badge)](https://www.skillsdirectory.com/skills/edjchapman-docker-patterns)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: docker-patterns
description: Container build, security, and caching conventions. Use when editing Dockerfiles, Compose files, build contexts, or .dockerignore.
---

# Docker Patterns

## Multi-Stage Builds

- Use multi-stage builds to separate build dependencies from runtime
- Name stages for clarity: `FROM node:20 AS builder`
- Copy only build artifacts into the final stage
- Keep the final image as small as possible (use `slim` or `alpine` base images)

## Layer Caching

- Order instructions from least to most frequently changing
- Copy dependency files (`package.json`, `requirements.txt`) before source code
- Group related `RUN` commands with `&&` to reduce layers
- Use `.dockerignore` to exclude unnecessary files from build context

## .dockerignore

- Always include: `.git`, `node_modules`, `__pycache__`, `.env`, `*.log`
- Mirror `.gitignore` patterns plus build artifacts
- Exclude test files and documentation from production images

## Security

- Never run as root -- use `USER nonroot` or create a dedicated user
- Don't store secrets in images -- use environment variables or secrets managers
- Pin base image versions: `python:3.12-slim` not `python:latest`
- Scan images for vulnerabilities with `docker scout` or `trivy`
- Use `COPY` instead of `ADD` unless you need tar extraction

## Health Checks

- Always define `HEALTHCHECK` in production Dockerfiles
- Use lightweight endpoints (`/healthz`) that check actual dependencies
- Set appropriate intervals, timeouts, and retries
- Health checks should complete quickly (< 5s)

## Compose Best Practices

- Use named volumes for persistent data
- Define explicit networks for service isolation
- Use `depends_on` with health check conditions
- Use `.env` files for environment configuration
- Define resource limits (`mem_limit`, `cpus`) for production
- Use `profiles` to group services by environment (dev, test, prod)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…