Back to skills
SKILL.md
Containerization Pro
CSecurityUse when configuring, automating, deploying, and debugging containerization pro pipelines, containers, servers, and cloud infrastructure.
- 5 stars
- 0 votes
- 0 copies
- 0 views
- Added September 27, 2026
Works with
Security analysis
68/100- Accesses sensitive system or user directories
- Performs destructive filesystem operations
- Installs packages at runtime which could introduce malicious dependencies
- Installs packages at runtime which could introduce malicious dependencies
npx -y skills add Harmitx7/tribunal-kit --skill containerization-pro --agent claude-codeAre you the author of Containerization Pro?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/harmitx7-containerization-pro)---
name: containerization-pro
description: "Use when configuring, automating, deploying, and debugging containerization pro pipelines, containers, servers, and cloud infrastructure."
version: 6.0.0
last-updated: 2026-09-29
skills:
- devops-engineer
- cicd-pro
- cloud-architect
tools: Read, Grep, Glob, Bash, Edit, Write
scripts-binding:
- .agent/scripts/lint_runner.js
- .agent/scripts/verify_all.js
---
# Containerization Pro β Production-Grade Docker Mastery
## Mandatory Pre-Flight Context Inspection
Before reading, generating, or refactoring code in the `containerization-pro` domain, inspect these 5 critical parameters:
1. **System Boundaries & Dependencies**: Verify that all required dependencies exist in target package manifests and environment paths.
2. **Runtime Context & Platform Invariants**: Confirm target platform constraints (Node.js, Browser, Mobile OS, Edge runtime) before applying APIs.
3. **Execution Guardrails**: Identify potential side-effects, state mutations, and unhandled asynchronous exceptions.
4. **Validation & Type Contracts**: Validate input data schemas and strict type constraints across all module interfaces.
5. **Observability & Proof of Execution**: Ensure execution produces tangible verification signals (terminal output, tests, metrics).
## Activation Boundaries
- **Activate when:** Use when configuring, automating, deploying, and debugging containerization pro pipelines, containers, servers, and cloud infrastructure.
- **DO NOT activate when:** The task falls outside the `containerization-pro` domain or is managed by a different dedicated specialist agent.
## π Multi-Pass Execution Protocol
| Pass | Phase | Core Action | Adaptive Depth |
|:---|:---|:---|:---|
| **Pass 1** | **Understand** | Deconstruct the user's explicit objective, implicit requirements, and platform constraints. | Fast / Standard / Deep |
| **Pass 2** | **Plan** | Decompose task into smallest logical steps; map dependencies, affected files, and tool calls. | Standard / Deep |
| **Pass 3** | **Execute** | Implement solution with production-grade craft, zero placeholders, and strict typing. | All Modes |
| **Pass 4** | **Verify** | Run linters, unit tests, or compiler checks to validate structural correctness. | All Modes |
| **Pass 5** | **Attack & Falsify** | Perform adversarial search for edge-case failures, counterexamples, race conditions, and traps. | Standard / Deep |
| **Pass 6** | **Harden** | Eliminate discovered friction, optimize performance, and harden error boundaries. | Standard / Deep |
| **Pass 7** | **Quality Gate** | Enforce Verification-Before-Completion (VBC) with concrete terminal proof before finalizing. | All Modes |
---
## π οΈ Technical Architecture & Reference Recipes
## Hallucination Traps (Read First)
- β `FROM node:22` β β
`FROM node:22-alpine` (1GB+ vs ~150MB). Always use slim/alpine variants.
- β `RUN npm install` β β
`RUN npm ci --omit=dev` (deterministic, no devDeps, respects lockfile)
- β `COPY . .` without `.dockerignore` β β
Always create `.dockerignore` first. Copies `node_modules`, `.env`, `.git` otherwise.
- β Running container as root β β
Always create and switch to a non-root user. Root in container = root on host if container escapes.
- β Single-stage Dockerfile β β
Multi-stage builds for any compiled/built application. Final image should contain ONLY runtime artifacts.
- β `docker build` without `--platform` for CI β β
CI often runs on `amd64`; target hosts may be `arm64`. Always specify platform or use multi-platform builds.
---
## 1. The .dockerignore (Write This First)
```
# .dockerignore β always create before writing Dockerfile
node_modules
npm-debug.log*
.npm
.git
.gitignore
.env
.env.*
*.md
README*
.github
.vscode
coverage
.nyc_output
dist # will be rebuilt in container
build # will be rebuilt in container
__pycache__
*.pyc
*.pyo
.pytest_cache
target # Rust build artifacts
```
---
## 2. Multi-Stage Dockerfiles
### Node.js (Production-Ready)
```dockerfile
# β
Multi-stage β builder produces artifacts, runner is minimal
FROM node:22-alpine AS base
WORKDIR /app
# Install deps in isolation for better caching
FROM base AS deps
COPY package.json package-lock.json ./
RUN npm ci
# Build stage
FROM base AS builder
COPY --from=deps /app/node_modules ./node_modules
COPY . .
RUN npm run build
# ββββ Runtime (final) stage ββββ
FROM node:22-alpine AS runner
WORKDIR /app
# Security: create non-root user
RUN addgroup --system --gid 1001 appgroup && \
adduser --system --uid 1001 --ingroup appgroup appuser
# Copy only production artifacts
COPY --from=builder --chown=appuser:appgroup /app/dist ./dist
COPY --from=builder --chown=appuser:appgroup /app/node_modules ./node_modules
COPY --from=builder --chown=appuser:appgroup /app/package.json ./
USER appuser
ENV NODE_ENV=production
ENV PORT=3000
EXPOSE 3000
# Health check β required for orchestration (ECS, Kubernetes)
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
CMD wget --quiet --tries=1 --spider http://localhost:3000/health || exit 1
CMD ["node", "src/index.js"]
```
### Python (FastAPI)
```dockerfile
FROM python:3.12-slim AS builder
WORKDIR /app
# Install build tools (needed for some packages, discarded in final image)
RUN apt-get update && apt-get install -y --no-install-recommends gcc && \
rm -rf /var/lib/apt/lists/*
COPY requirements.txt .
RUN pip install --user --no-cache-dir -r requirements.txt
# ββββ Runtime stage ββββ
FROM python:3.12-slim AS runner
WORKDIR /app
# Security: non-root user
RUN addgroup --system --gid 1001 appgroup && \
adduser --system --uid 1001 --gid 1001 appuser
# Copy installed packages from builder
COPY --from=builder --chown=appuser:appgroup /root/.local /home/appuser/.local
COPY --chown=appuser:appgroup . .
USER appuser
ENV PATH=/home/appuser/.local/bin:$PATH
ENV PYTHONUNBUFFERED=1
EXPOSE 8000
HEALTHCHECK --interval=30s --timeout=5s --retries=3 \
CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8000/health')"
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]
```
### Rust (Distroless Final Image)
```dockerfile
FROM rust:1.78-slim AS builder
WORKDIR /app
# Cache dependencies separately for fast rebuilds
COPY Cargo.toml Cargo.lock ./
RUN mkdir src && echo "fn main() {}" > src/main.rs
RUN cargo build --release
RUN rm src/main.rs
# Build actual application
COPY src ./src
RUN touch src/main.rs && cargo build --release
# ββββ Distroless runtime (no shell, no package manager, minimal attack surface) ββββ
FROM gcr.io/distroless/cc-debian12 AS runner
WORKDIR /app
COPY --from=builder /app/target/release/myapp ./myapp
USER nonroot:nonroot
EXPOSE 8080
CMD ["/app/myapp"]
```
### Go
```dockerfile
FROM golang:1.22-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-w -s" -o server ./cmd/server
# ββββ Scratch (smallest possible image) ββββ
FROM scratch AS runner
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
COPY --from=builder /app/server /server
EXPOSE 8080
ENTRYPOINT ["/server"]
```
---
## 3. BuildKit Layer Caching (CI Speed)
```dockerfile
# syntax=docker/dockerfile:1.6
FROM node:22-alpine AS builder
WORKDIR /app
# Mount npm cache β persists between builds (dramatic speed improvement in CI)
COPY package.json package-lock.json ./
RUN --mount=type=cache,target=/root/.npm \
npm ci
# Mount build cache (Next.js / webpack)
COPY . .
RUN --mount=type=cache,target=/app/.next/cache \
npm run build
```
```yaml
# GitHub Actions β enable BuildKit with caching
- name: Build and push Docker image
uses: docker/build-push-action@v5
with:
context: .
push: true
tags: ${{ env.ECR_REGISTRY }}/${{ env.ECR_REPOSITORY }}:${{ github.sha }}
cache-from: type=gha # GitHub Actions cache
cache-to: type=gha,mode=max # Cache all layers
build-args: |
BUILDKIT_INLINE_CACHE=1
```
---
## 4. Multi-Platform Builds
```bash
# Build for both amd64 (x86) and arm64 (Apple Silicon, AWS Graviton)
docker buildx create --name mybuilder --use
docker buildx build \
--platform linux/amd64,linux/arm64 \
--tag myapp:latest \
--push \
.
```
```yaml
# GitHub Actions β multi-platform
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build multi-platform image
uses: docker/build-push-action@v5
with:
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
```
---
## 5. Docker Compose (Local Development)
```yaml
# docker-compose.yml
services:
api:
build:
context: .
target: builder # use builder stage locally (includes devtools)
dockerfile: Dockerfile
ports:
- '3000:3000'
environment:
NODE_ENV: development
DATABASE_URL: postgres://postgres:postgres@db:5432/myapp_dev
REDIS_URL: redis://redis:6379
volumes:
- .:/app # mount source for hot-reload
- /app/node_modules # anonymous volume prevents host node_modules overwrite
depends_on:
db:
condition: service_healthy
redis:
condition: service_started
restart: unless-stopped
db:
image: postgres:16-alpine
environment:
POSTGRES_DB: myapp_dev
POSTGRES_USER: postgres
POSTGRES_PASSWORD: postgres
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ['CMD-SHELL', 'pg_isready -U postgres']
interval: 5s
timeout: 3s
retries: 5
ports:
- '5432:5432' # expose for local DB clients
redis:
image: redis:7-alpine
volumes:
- redisdata:/data
ports:
- '6379:6379'
volumes:
pgdata:
redisdata:
```
---
## 6. Container Security Scanning
```yaml
# GitHub Actions β Trivy vulnerability scan
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@master
with:
image-ref: ${{ env.ECR_REGISTRY }}/${{ env.ECR_REPOSITORY }}:${{ github.sha }}
format: sarif
output: trivy-results.sarif
severity: CRITICAL,HIGH
exit-code: '1' # fail pipeline on CRITICAL/HIGH vulnerabilities
- name: Upload Trivy scan results to GitHub Security tab
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: trivy-results.sarif
```
```bash
# Local scanning
trivy image myapp:latest
# Scan Dockerfile for misconfigurations before building
trivy config Dockerfile
```
---
## 7. AWS ECR Workflow
```yaml
# Complete ECR push workflow
jobs:
build-and-push:
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
outputs:
image: ${{ steps.build.outputs.image }}
steps:
- uses: actions/checkout@v4
- name: Configure AWS credentials (OIDC β no static keys)
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ROLE_ARN }}
aws-region: us-east-1
- name: Login to Amazon ECR
id: login-ecr
uses: aws-actions/amazon-ecr-login@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build, tag, and push image
id: build
uses: docker/build-push-action@v5
with:
context: .
push: true
tags: |
${{ steps.login-ecr.outputs.registry }}/myapp:${{ github.sha }}
${{ steps.login-ecr.outputs.registry }}/myapp:latest
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Output image URI
run: echo "image=${{ steps.login-ecr.outputs.registry }}/myapp:${{ github.sha }}" >> $GITHUB_OUTPUT
```
### ECR Lifecycle Policy (Cost Control)
```json
{
"rules": [
{
"rulePriority": 1,
"description": "Keep last 10 production images",
"selection": {
"tagStatus": "tagged",
"tagPrefixList": ["v"],
"countType": "imageCountMoreThan",
"countNumber": 10
},
"action": { "type": "expire" }
},
{
"rulePriority": 2,
"description": "Expire untagged images after 1 day",
"selection": {
"tagStatus": "untagged",
"countType": "sinceImagePushed",
"countUnit": "days",
"countNumber": 1
},
"action": { "type": "expire" }
}
]
}
```
## π¨ Edge-Case & Failure Mode Matrix
| Scenario | Risk | Production Mitigation |
|:---|:---|:---|
| **Empty or Null Inputs** | Unhandled exception or unexpected rendering collapse | Enforce fallback guards, optional chaining, and explicit empty state handlers |
| **Network Timeout / Latency** | Hanging operations or duplicate side-effects | Implement bounded abort controllers, exponential backoff, and idempotency keys |
| **Concurrency / Race Conditions** | Stale state overwrite or inconsistent data mutations | Use atomic transactions, mutex locking, or cancel-on-resubmit controls |
| **Invalid Schema / Malformed Payload** | Downstream runtime errors or security injection | Validate boundary payloads with Zod/Pydantic schemas prior to execution |
| **Resource / Memory Saturation** | OOM errors, frame drops, or memory leaks | Clean up listeners, cancel active timers, and enforce pagination/virtualization |
## ποΈ Tribunal Verification & Guardrails
**Active Reviewers:** `pipeline-reviewer` Β· `devops-engineer` Β· `resilience-reviewer`
**Slash Command:** `/review` or `/tribunal-full`
### π¬ Evidence Standard (Tri-State Verification)
Every finding, audit statement, or completion claim must classify its factual certainty:
- **`[OBSERVED]`**: Directly confirmed in the codebase or verified via executed terminal command.
- **`[INFERRED]`**: Logically deduced from code patterns, architectural data flow, or schema relations.
- **`[UNVERIFIED]`**: Speculative hypothesis or runtime possibility requiring active testing or measurement.
### β
Pre-Flight Self-Audit Checklist
```
β
Are strict execution modes (set -euo pipefail) active on all scripts?
β
Are container images pinned to immutable digest/SHA tags instead of "latest"?
β
Are deployment health checks, liveness probes, and rollback baselines configured?
β
Are CI secrets masked and unexposed to untrusted pull requests?
β
Did I verify environment compatibility across target runtimes?
```
### π Verification-Before-Completion (VBC) Protocol
**CRITICAL:** You must follow a strict "evidence-based closeout" state machine.
- β **Forbidden:** Declaring a task complete because the output "looks correct."
- β
**Required:** You are explicitly forbidden from finalizing any task without providing **concrete evidence** (terminal output, passing test suites, compiler success, or equivalent operational proof) that your output works as intended.
Attribution
Comments
Loading commentsβ¦