Skip to content
Back to skills

Docker Containerization

ASecurity

创建优化的 Docker 容器,使用多阶段构建、安全最佳实践和最小镜像大小。在容器化应用程序、创建 Dockerfile、优化容器镜像或设置 Docker Compose 服务时使用。

  • 8 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 12, 2026
devopspythongojavanodenodejsdjangoflaskspringdockerci/cd

Security analysis

A100/100

Pro scans all 9 files and shows the line behind each finding

Scanned September 12, 2026

npx -y skills add lza6/Claude-code-cli-config --skill docker-containerization --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Docker Containerization?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Docker Containerization
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lza6-docker-containerization/badge)](https://www.skillsdirectory.com/skills/lza6-docker-containerization)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: docker-containerization
description: "创建优化的 Docker 容器,使用多阶段构建、安全最佳实践和最小镜像大小。在容器化应用程序、创建 Dockerfile、优化容器镜像或设置 Docker Compose 服务时使用。"
---

# Docker 容器化

## 目录

- [概述](#概述)
- [何时使用](#何时使用)
- [快速启动](#快速启动)
- [参考指南](#参考指南)
- [最佳实践](#最佳实践)

## 概述

遵循安全性、性能和可维护性的最佳实践构建生产就绪的 Docker 容器。

## 何时使用

- 将应用程序容器化以进行部署
- 为新服务创建 Dockerfile
- 优化现有容器镜像
- 设置开发环境
- 构建 CI/CD 容器管道
- 实施微服务

## 快速入门

最小工作示例:

```dockerfile
# Node.js 应用程序的多阶段构建
# 阶段 1:构建
FROM node:18-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production
COPY . .
RUN npm run build

# 阶段 2:生产环境
FROM node:18-alpine
WORKDIR /app
# 仅复制生产依赖和构建文件
COPY --from=builder /app/node_modules ./node_modules
COPY --from=builder /app/dist ./dist
COPY package*.json ./

# 安全:以非 root 用户运行
RUN addgroup -g 1001 -S nodejs && adduser -S nodejs -u 1001
USER nodejs

EXPOSE 3000
CMD ["node", "dist/index.js"]
```

## 参考指南

详细实现在 `references/` 目录中:

| 指南 | 内容 |
|---|---|
| [多阶段构建](references/multi-stage-builds.md) | 多阶段构建 |
| [优化技术](references/optimization-techniques.md) | 优化技术 |
| [安全最佳实践](references/security-best-practices.md) | 安全最佳实践、环境配置 |
| [Docker Compose 多容器](references/docker-compose-for-multi-container.md) | Docker Compose 多容器 |
| [.dockerignore 文件](references/dockerignore-file.md) | .dockerignore 文件 |
| [Python](references/python.md) | Python (Django/Flask), Java (Spring Boot), Go |

## 最佳实践

### ✅ 应该做

- 使用官方基础镜像
- 实施多阶段构建
- 以非 root 用户身份运行
- 使用 .dockerignore
- 固定特定版本
- 包含健康检查
- 扫描漏洞
- 最小化层数
- 有效利用构建缓存

### ❌ 不要做

- 在生产中使用 `latest` 标签
- 以 root 用户身份运行
- 在镜像中包含密钥
- 创建不必要的层
- 安装不必要的包
- 忽略安全更新
- 在容器中存储数据

Files in this skill

  • SKILL.md2.3 KB
  • references/docker-compose-for-multi-container.md1.1 KB
  • references/dockerignore-file.md207 B
  • references/multi-stage-builds.md609 B
  • references/optimization-techniques.md598 B
  • references/python.md954 B
  • references/security-best-practices.md745 B
  • scripts/validate-pipeline.sh502 B
  • templates/pipeline.yaml665 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…