Skip to content
Back to skills

Deployment

ASecurity

Docker builds, Memory tuning, and Graceful shutdown.

  • 8 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 8, 2026
ai-agentsnodedockerkubernetesdatabasesecurity

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 8, 2026

npx -y skills add ngxtm/devkit --skill deployment --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Deployment?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Deployment
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ngxtm-deployment/badge)](https://www.skillsdirectory.com/skills/ngxtm-deployment)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: NestJS Deployment
description: Docker builds, Memory tuning, and Graceful shutdown.
metadata:
  labels: [nestjs, deployment, docker, k8s]
  triggers:
    files: ['Dockerfile', 'k8s/**', 'helm/**']
    keywords: [Dockerfile, max-old-space-size, shutdown hooks]
---

# Deployment & Ops Standards

## Docker Optimization

- **Multi-Stage Builds**: Mandatory.
  1. **Build Stage**: Install `devDependencies`, build NestJS (`nest build`).
  2. **Run Stage**: Copy only `dist` and `node_modules` (pruned), use `node:alpine`.
- **Security**: Do not run as `root`.
  - **Dockerfile**: `USER node`.

## Runtime Tuning (Node.js)

- **Memory Config**: Container memory != Node memory.
  - **Rule**: Explicitly set Max Old Space.
  - **Command**: `node --max-old-space-size=XXX dist/main`
  - **Calculation**: Set to ~75-80% of Kubernetes Limit. (Limit: 1GB -> OldSpace: 800MB).
- **Graceful Shutdown**:
  - **Signal**: Listen to `SIGTERM`.
  - **NestJS**: `app.enableShutdownHooks()` is mandatory.
  - **Sleep**: Add a "Pre-Stop" sleep in K8s (5-10s) to allow Load Balancer to drain connections before Node process stops accepting traffic.

## Init Patterns

- **Database Migrations**:
  - **Anti-Pattern**: Running migration in `main.ts` on startup.
  - **Pro Pattern**: Use an **Init Container** in Kubernetes that runs `npm run typeorm:migration:run` before the app container starts.

Files in this skill

  • SKILL.md1.4 KB
  • references/REFERENCE.md337 B
  • references/deployment-patterns.md2.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…