Skip to content
Back to skills

Docker

ASecurity

Containerize applications with Docker: Dockerfiles, images, networking, volumes, compose, and production hardening. Use for any deployable service.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentsgoshellbashsqlnodedockergitdatabasedevopsci/cd

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 29, 2026

npx -y skills add ssrjkk/claude-skills --skill docker --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Docker?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Docker
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ssrjkk-docker/badge)](https://www.skillsdirectory.com/skills/ssrjkk-docker)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: docker
description: "Containerize applications with Docker: Dockerfiles, images, networking, volumes, compose, and production hardening. Use for any deployable service."
category: devops
tags: [docker, containers, images, dockerfile, compose, deployment, devops]
models: [sonnet, opus, gpt-5, gemini-2.5, glm-4.6]
version: 1.0.0
created: 2026-09-20
updated: 2026-09-28
author: ssrjkk
---
# Docker

> Containerizing applications with Docker for consistent deployment.

## Quick Start
```bash
docker build -t myapp .
docker run -p 8080:8080 myapp
docker compose up -d
```

## When to Use
- Consistent environments across dev, test, and prod
- Microservices and isolated dependencies
- CI/CD artifacts that are identical everywhere
- Local development with databases and services

## Best Practices

### Dockerfiles
- Use multi-stage builds to slim images
- Prefer official and pinned base images (`alpine:3.20`)
- Run as non-root; copy only what is needed
- Layer ordering: dependencies first, code last (better caching)

### Images
- Keep images small: distroless or alpine when possible
- Tag with commit SHA and semver; avoid `latest` for prod
- Scan images with `docker scout` or Trivy
- Use `--platform` for multi-arch builds

### Runtime
- Set resource limits (`--memory`, `--cpus`)
- Use volumes for persistent data; anonymous volumes are ephemeral
- Prefer `init: true` or `tini` to reap zombies
- Add healthchecks so orchestrators can manage lifecycle

## Dependencies
```bash
# Docker Desktop or docker engine + compose plugin
docker --version
docker compose version
```

## Examples
```dockerfile
# Multi-stage Node build
FROM node:22-alpine AS build
WORKDIR /app
COPY package*.json ./
RUN npm ci
COPY . .
RUN npm run build

FROM node:22-alpine AS runtime
ENV NODE_ENV=production
WORKDIR /app
COPY --from=build /app/dist ./dist
COPY --from=build /app/node_modules ./node_modules
USER node
EXPOSE 3000
CMD ["node", "dist/server.js"]
```
```yaml
# docker-compose.yml
services:
  web:
    build: .
    ports:
      - "8080:8080"
    depends_on:
      db:
        condition: service_healthy
    healthcheck:
      test: ["CMD", "wget", "-qO-", "http://localhost:8080/health"]
      interval: 10s
      retries: 3
  db:
    image: postgres:17-alpine
    environment:
      POSTGRES_PASSWORD: secret
    volumes:
      - pgdata:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U postgres"]
volumes:
  pgdata:
```
```bash
# Build and push with metadata
docker build -t ghcr.io/org/myapp:${GITHUB_SHA} .
docker push ghcr.io/org/myapp:${GITHUB_SHA}
```
```bash
# Inspect and debug
docker exec -it myapp sh
docker logs --follow myapp
docker image prune -f
```

## Step-by-Step
1. Write a multi-stage Dockerfile with pinned base images.
2. Order layers for cache efficiency (deps before code).
3. Run as non-root; add a healthcheck.
4. Build and test locally with `docker build` and `docker run`.
5. Compose services for local integration (app + db + cache).
6. Tag images with the commit SHA; push to a registry.
7. Scan for vulnerabilities before deploy.
8. Pin resource limits and set up log rotation.

## Validation
1. `docker build` succeeds with no warnings
2. `docker run` starts and responds to healthcheck
3. Image scan reports no critical vulnerabilities
4. Compose stack starts cleanly with `docker compose up`
5. Non-root container cannot write to protected paths

## Troubleshooting
- "Cannot connect to the Docker daemon": start Docker Desktop/engine.
- Image too large: switch to multi-stage and slimmer base.
- "Address already in use": change host port mapping or stop the conflicting container.

Files in this skill

  • SKILL.md3.6 KB
  • SKILL.ru.md5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…