Skip to content
Back to skills

Container Security

ASecurity

Docker image hardening, rootless containers, K8s security contexts, network policies, pod security standards, and OPA/Gatekeeper policies

  • 6 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 8, 2026
ai-agentspythonbashdockerkubernetesapisecurity

Works with

  • api

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned September 8, 2026

npx -y skills add kmshihab7878/claude-code-setup --skill container-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Container Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Container Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/kmshihab7878-container-security/badge)](https://www.skillsdirectory.com/skills/kmshihab7878-container-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: container-security
description: Docker image hardening, rootless containers, K8s security contexts, network policies, pod security standards, and OPA/Gatekeeper policies
triggers:
  - container security
  - docker hardening
  - rootless container
  - k8s security
  - pod security
  - network policy
  - security context
  - OPA
  - gatekeeper
---

# Container Security

Harden Docker images, enforce Kubernetes security policies, and implement defense-in-depth for containerized services.

## Docker Image Hardening

```dockerfile
# Multi-stage, minimal, rootless
FROM python:3.10-slim AS builder
WORKDIR /build
COPY requirements.txt .
RUN pip install --no-cache-dir --prefix=/install -r requirements.txt

FROM python:3.10-slim
RUN groupadd -r appuser && useradd --no-log-init -r -g appuser appuser
COPY --from=builder /install /usr/local
COPY --chown=appuser:appuser src/ /app/src/
WORKDIR /app
USER appuser
EXPOSE 8000
HEALTHCHECK CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8000/health')"
ENTRYPOINT ["python", "-m", "uvicorn", "coremind.api.main:app", "--host", "0.0.0.0"]
```

### Hardening Checklist
- Use specific image tags, never `latest`
- Multi-stage builds (separate build/runtime)
- Run as non-root user (USER directive)
- No secrets in image layers
- Minimal base image (slim/alpine/distroless)
- HEALTHCHECK defined
- Read-only filesystem where possible
- No unnecessary packages or tools

## Kubernetes Security Context

```yaml
apiVersion: apps/v1
kind: Deployment
spec:
  template:
    spec:
      securityContext:
        runAsNonRoot: true
        runAsUser: 1000
        fsGroup: 1000
        seccompProfile:
          type: RuntimeDefault
      containers:
        - name: coremind-api
          securityContext:
            allowPrivilegeEscalation: false
            readOnlyRootFilesystem: true
            capabilities:
              drop: ["ALL"]
          volumeMounts:
            - name: tmp
              mountPath: /tmp
      volumes:
        - name: tmp
          emptyDir: {}
```

## Network Policies

```yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: coremind-api-netpol
spec:
  podSelector:
    matchLabels:
      app: coremind-api
  policyTypes: [Ingress, Egress]
  ingress:
    - from:
        - podSelector:
            matchLabels:
              app: ingress-nginx
      ports:
        - port: 8000
  egress:
    - to:
        - podSelector:
            matchLabels:
              app: postgres
      ports:
        - port: 5432
    - to:  # DNS
        - namespaceSelector: {}
      ports:
        - port: 53
          protocol: UDP
```

## Scanning Commands

```bash
# Scan Docker image
trivy image coremind-fresh:latest --severity HIGH,CRITICAL

# Scan K8s manifests
trivy config k8s/ --severity HIGH,CRITICAL

# Scan running cluster
trivy k8s --report summary cluster
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…