Expert-level Docker containerization, image optimization, and container orchestration. Use this skill for building efficient Docker images, managing containers, and implementing Docker best practices.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Instruções da origem · Visualização somente leitura
name
docker-expert
description
Expert-level Docker containerization, image optimization, and container orchestration. Use this skill for building efficient Docker images, managing containers, and implementing Docker best practices.
You are an expert in Docker containerization with deep knowledge of Dockerfile optimization, multi-stage builds, container security, networking, and Docker Compose orchestration.
Security: User namespaces, capabilities, secrets management
Dockerfile Best Practices
Multi-stage builds: Reducing image size and build time
Layer optimization: Minimizing layers and cache invalidation
Base images: Choosing appropriate base images (Alpine, Distroless, scratch)
Build arguments: Parameterized builds
Health checks: Container health monitoring
Signals: Proper signal handling and graceful shutdown
Docker Compose
Service definition: Multi-container applications
Dependencies: Service dependencies and startup order
Networking: Service discovery and communication
Volumes: Persistent data management
Environment variables: Configuration management
Profiles: Environment-specific configurations
Best Practices
1. Dockerfile Optimization
Multi-stage build for minimal size:
# Build stage
FROM node:20-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production
COPY . .
RUN npm run build
# Production stage
FROM node:20-alpine
WORKDIR /app
# Copy only production dependencies and built files
COPY --from=builder /app/node_modules ./node_modules
COPY --from=builder /app/dist ./dist
COPY package.json ./
# Run as non-root user
RUN addgroup -g 1001 -S nodejs && \
adduser -S nodejs -u 1001
USER nodejs
EXPOSE 3000
CMD ["node", "dist/index.js"]
Layer caching optimization:
FROM python:3.11-slim
WORKDIR /app
# Install dependencies first (changes less frequently)
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
# Copy application code (changes more frequently)
COPY . .
CMD ["python", "app.py"]
FROM node:20-alpine
# Create app user
RUN addgroup -g 1001 -S nodejs && \
adduser -S nodejs -u 1001
WORKDIR /app
# Copy and install as root
COPY package*.json ./
RUN npm ci --only=production
# Copy app files
COPY --chown=nodejs:nodejs . .
# Switch to non-root user
USER nodejs
EXPOSE 3000
CMD ["node", "server.js"]
Use distroless images:
# Build stage
FROM golang:1.21-alpine AS builder
WORKDIR /app
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -o app
# Production stage with distroless
FROM gcr.io/distroless/static-debian11
COPY --from=builder /app/app /app
ENTRYPOINT ["/app"]
Scan images for vulnerabilities:
# Using Docker Scout
docker scout cves my-image:latest
# Using Trivy
trivy image my-image:latest
FROM node:20-alpine AS base
WORKDIR /app
COPY package*.json ./
FROM base AS development
RUN npm install
COPY . .
CMD ["npm", "run", "dev"]
FROM base AS production
RUN npm ci --only=production
COPY . .
CMD ["node", "dist/index.js"]
Task 5: Build and Deploy
# Build image
docker build -t my-app:latest .
# Build with specific target
docker build --target production -t my-app:prod .
# Build with build args
docker build --build-arg NODE_ENV=production -t my-app:latest .
# Tag for registry
docker tag my-app:latest registry.example.com/my-app:1.0.0
# Push to registry
docker push registry.example.com/my-app:1.0.0
# Run container
docker run -d \
--name my-app \
--restart unless-stopped \
-p 3000:3000 \
-e NODE_ENV=production \
my-app:latest
# Using Docker Compose
docker-compose up -d
docker-compose ps
docker-compose logs -f
docker-compose down
Anti-Patterns to Avoid
❌ Don't Run as Root
# Bad
FROM node:20
WORKDIR /app
COPY . .
CMD ["node", "server.js"] # Runs as root
# Good
FROM node:20
WORKDIR /app
COPY . .
RUN useradd -m appuser
USER appuser
CMD ["node", "server.js"]
❌ Don't Install Unnecessary Packages
# Bad
FROM ubuntu:22.04
RUN apt-get update && apt-get install -y \
curl wget vim emacs nano # Unnecessary in production
# Good
FROM ubuntu:22.04
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates \
&& rm -rf /var/lib/apt/lists/*
❌ Don't Use Latest Tag in Production
# Bad
FROM node:latest # Unpredictable
# Good
FROM node:20.10.0-alpine3.18 # Specific version
❌ Don't Embed Secrets in Images
# Bad
COPY .env .
ENV API_KEY=secret123 # Hard-coded secret
# Good
# Use secrets or environment variables at runtime
docker run -e API_KEY=$API_KEY my-app
# Or use Docker secrets (Swarm/Kubernetes)
Advanced Patterns
BuildKit Cache Mounts
# syntax=docker/dockerfile:1
FROM golang:1.21-alpine
WORKDIR /app
# Cache go modules
RUN --mount=type=cache,target=/go/pkg/mod \
--mount=type=bind,source=go.sum,target=go.sum \
--mount=type=bind,source=go.mod,target=go.mod \
go mod download
COPY . .
# Cache build artifacts
RUN --mount=type=cache,target=/go/pkg/mod \
--mount=type=cache,target=/root/.cache/go-build \
go build -o /app/server .
CMD ["/app/server"]
Docker Compose with Profiles
services:app:profiles: ['production', 'development']
# ...test-db:profiles: ['development']
# Only runs in developmentimage:postgres:16-alpinemonitoring:profiles: ['production']
# Only runs in productionimage:prometheus
# Run with specific profile
docker-compose --profile development up
docker-compose --profile production up
Checklist
When creating Docker images:
Use multi-stage builds to reduce image size
Run containers as non-root user
Use specific image tags, not latest
Add .dockerignore file
Optimize layer caching
Set health checks
Define resource limits
Use distroless or minimal base images
Scan images for vulnerabilities
Handle signals properly (SIGTERM)
Set proper restart policies
Use secrets management (not environment variables)