Skip to content
Back to skills

Container Standards

ASecurity

Container build and runtime standards: multi-stage builds into a minimal runtime (Alpine/Distroless/Scratch), manifest-before-source layer ordering for cache hits, non-root user, vulnerability scan failing on HIGH/CRITICAL, no secrets in the image, tini/dumb-init as PID 1, HEALTHCHECK, and semver+SHA tags that are never reused. Load when writing or reviewing a Dockerfile, docker-compose file, container build pipeline, or image tagging scheme.

  • 146 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentsdockersecurity

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add Goldziher/ai-rulez --skill container-standards --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Container Standards?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Container Standards
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/goldziher-container-standards/badge)](https://www.skillsdirectory.com/skills/goldziher-container-standards)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: container-standards
description: "Container build and runtime standards: multi-stage builds into a minimal runtime (Alpine/Distroless/Scratch), manifest-before-source layer ordering for cache hits, non-root user, vulnerability scan failing on HIGH/CRITICAL, no secrets in the image, tini/dumb-init as PID 1, HEALTHCHECK, and semver+SHA tags that are never reused. Load when writing or reviewing a Dockerfile, docker-compose file, container build pipeline, or image tagging scheme."
---

- **Multi-stage builds**: full toolchain builder → minimal runtime (Alpine/Distroless/Scratch).
- **Layer caching**: copy dependency manifests first, then source — maximize cache hits.
- **Security**: non-root user, vulnerability scanning (fail on HIGH/CRITICAL), no secrets in the image.
- **Signal handling**: use an init process (tini/dumb-init) as PID 1, and define a `HEALTHCHECK`.
- **Tagging**: semantic version + commit SHA, never reuse a tag.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…