Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Docker

DSecurity

Expert coverage of Docker Engine across all supported versions: dockerd/containerd/runc architecture, BuildKit builds, Dockerfile optimization, Compose v2, networking, storage drivers, security hardening, and Docker Scout. Use for \"Docker\", \"Dockerfile\", \"docker-compose\", \"Docker Compose\", \"BuildKit\", \"docker build\", \"docker run\", \"dockerd\", \"Docker Desktop\", \"Docker Scout\".

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
devopspythongobashnodedockerkubernetesgitapibackendsecurity

Works with

cliapi

Security Analysis

D56/100
criticalAccesses sensitive system or user directories
highPerforms destructive filesystem operations
criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study
mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 7 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill docker --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Docker?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Docker
[![Security: D — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-docker/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-docker)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: docker
description: "Expert coverage of Docker Engine across all supported versions: dockerd/containerd/runc architecture, BuildKit builds, Dockerfile optimization, Compose v2, networking, storage drivers, security hardening, and Docker Scout. Use for \"Docker\", \"Dockerfile\", \"docker-compose\", \"Docker Compose\", \"BuildKit\", \"docker build\", \"docker run\", \"dockerd\", \"Docker Desktop\", \"Docker Scout\"."
license: MIT
---

# Docker Engine

This skill covers Docker Engine across all supported versions (25.0 through 29.x), including:

- Docker daemon (`dockerd`) and its delegation to containerd and runc
- BuildKit build engine, multi-stage builds, cache optimization, multi-platform builds
- Dockerfile best practices, layer optimization, security hardening
- Docker Compose v2 (Go rewrite, CLI plugin)
- Networking (bridge, host, overlay, macvlan, ipvlan, nftables)
- Storage drivers and volume management
- Security (rootless mode, user namespaces, seccomp, AppArmor, capabilities)
- Docker Scout vulnerability scanning and SBOM generation
- Registry interaction (Docker Hub, private registries, Harbor)

When a question is version-specific, read the matching file in the Version-specific guidance section below. When the version is unknown, provide guidance based on the latest stable release (29.x).

## How to Approach Tasks

1. **Classify** the request:
   - **Build optimization** -- Load `references/best-practices.md` for Dockerfile patterns, multi-stage builds, cache strategies
   - **Troubleshooting** -- Load `references/diagnostics.md` for docker logs, inspect, stats, events, system df
   - **Architecture** -- Load `references/architecture.md` for daemon/containerd/runc flow, networking, storage
   - **Compose** -- Apply Compose v2 patterns, profiles, watch mode, depends_on conditions
   - **Security** -- Apply rootless, seccomp, capabilities, image scanning guidance

2. **Identify version** -- Determine Docker Engine version. Key boundaries: v25 (BuildKit default), v28 (nftables experimental), v29 (containerd image store default). If unclear, ask.

3. **Load context** -- Read the relevant reference file below.

4. **Analyze** -- Apply Docker-specific reasoning, not generic container advice.

5. **Recommend** -- Provide actionable guidance with CLI examples, Dockerfile snippets, or compose.yaml patterns.

6. **Verify** -- Suggest validation steps (`docker inspect`, `docker stats`, `docker scout cves`).

## Core Architecture

```
Docker CLI --> Docker Daemon (dockerd) --> containerd --> containerd-shim-runc-v2 --> runc --> Linux Kernel
```

### dockerd (Docker Daemon)

The daemon listens on a Unix socket (`/var/run/docker.sock`), TCP socket, or named pipe (Windows). It manages:
- Image builds (delegated to BuildKit)
- Container lifecycle (create, start, stop, remove)
- Volume and network management
- Plugin system (storage, network, authorization plugins)

The daemon delegates all container execution to containerd. As of Docker Engine v29, the daemon no longer manages its own image store -- that responsibility moved to containerd's content store.

### containerd Integration

Docker Engine bundles containerd as its execution backend:
- Image pull, push, and storage (content-addressable store)
- Container execution and supervision via shims
- containerd namespaces isolate Docker ("moby" namespace) from other clients
- Docker Engine v29 ships containerd 2.2.2 with config version 3

### runc and Shims

runc is the OCI reference runtime that creates containers:
- Reads OCI runtime spec (`config.json`) generated by containerd
- Sets up Linux namespaces, cgroups, seccomp, capabilities
- `containerd-shim-runc-v2` manages runc processes, keeping containers alive if containerd restarts

## Dockerfile Best Practices

### Multi-Stage Builds

The primary mechanism for minimal production images:

```dockerfile
# Build stage
FROM golang:1.23-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /app/server .

# Production stage -- scratch or distroless
FROM gcr.io/distroless/static-debian12:nonroot
WORKDIR /app
COPY --from=builder /app/server .
EXPOSE 8080
ENTRYPOINT ["/app/server"]
```

### Layer Caching Strategy

1. Put rarely-changing instructions first (OS packages, dependency install)
2. Copy dependency manifests before source code (`package.json` before `src/`)
3. Use BuildKit cache mounts for package managers:

```dockerfile
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \
    --mount=type=cache,target=/var/lib/apt,sharing=locked \
    apt-get update && apt-get install -y --no-install-recommends build-essential

RUN --mount=type=cache,target=/root/.cache/go-build \
    --mount=type=cache,target=/go/pkg/mod \
    go build -o /app/server .
```

### Security Hardening

```dockerfile
# Non-root user
RUN adduser -u 10001 -D appuser
USER 10001

# Health check
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
  CMD wget -qO- http://localhost:8080/health || exit 1
```

- Use specific image tags, never `:latest` in production
- Prefer `COPY` over `ADD` (predictable, no auto-extraction)
- Use `ENTRYPOINT` for the command, `CMD` for default arguments
- Combine `RUN` with `&&` to minimize layers
- Always include `.dockerignore` to exclude `.git`, `node_modules`, `.env`, secrets

## BuildKit

BuildKit is the default build engine since Docker 23.0. It provides concurrent DAG-based builds with content-addressable caching.

### Multi-Platform Builds

```bash
docker buildx create --name mybuilder --use --bootstrap
docker buildx build \
  --platform linux/amd64,linux/arm64 \
  --tag registry.example.com/myapp:v1.0 \
  --push .
```

### Cache Export/Import

```bash
# Registry cache
docker buildx build \
  --cache-to type=registry,ref=registry.example.com/myapp:cache,mode=max \
  --cache-from type=registry,ref=registry.example.com/myapp:cache \
  --push -t registry.example.com/myapp:latest .

# GitHub Actions cache
docker buildx build \
  --cache-to type=gha,mode=max \
  --cache-from type=gha \
  --push -t myapp:latest .
```

Cache backends: `registry`, `local`, `gha`, `s3`, `azblob`, `inline`. `mode=max` caches all intermediate layers; `mode=min` (default) caches only final layers.

### Build Secrets

```bash
docker buildx build --secret id=npmrc,src=$HOME/.npmrc .
```
```dockerfile
RUN --mount=type=secret,id=npmrc,target=/root/.npmrc npm install
```

Secrets are never baked into image layers.

### Docker Bake (HCL)

Declarative build orchestration for multi-service projects:

```hcl
group "default" {
  targets = ["api", "worker"]
}
target "api" {
  context    = "./api"
  platforms  = ["linux/amd64", "linux/arm64"]
  tags       = ["registry.example.com/api:latest"]
  cache-from = ["type=registry,ref=registry.example.com/api:cache"]
  cache-to   = ["type=registry,ref=registry.example.com/api:cache,mode=max"]
}
```

## Docker Compose v2

Compose v2 is a Go rewrite integrated as a Docker CLI plugin (`docker compose`). Legacy Python `docker-compose` (v1) is EOL. Compose Specification v5.0.0 (Dec 2025) removed the internal builder in favor of Docker Bake.

### Key Features

- **depends_on conditions**: `condition: service_healthy` waits for health check
- **Profiles**: Conditional service activation (`--profile debug`)
- **Watch mode**: File sync, rebuild, or sync+restart on file changes (`docker compose watch`)
- **Secrets**: Mount files as secrets, never in environment variables
- **Deploy resources**: CPU/memory limits via `deploy.resources.limits`

### Watch Mode (Compose v2.22.0+)

```yaml
services:
  app:
    build: .
    develop:
      watch:
        - action: sync
          path: ./src
          target: /app/src
        - action: rebuild
          path: package.json
        - action: sync+restart
          path: ./config
          target: /app/config
```

## Networking

### Network Drivers

| Driver | Scope | Use Case |
|---|---|---|
| bridge | local | Default; containers on same host communicate via DNS |
| host | local | No network isolation, use host stack directly |
| overlay | swarm | Multi-host (VXLAN encapsulation, UDP 4789) |
| macvlan | local | Container gets own MAC/IP on physical LAN |
| ipvlan | local | Like macvlan but shares MAC; L2 or L3 modes |
| none | local | No networking |

### Custom Bridge (recommended over default docker0)

```bash
docker network create \
  --driver bridge \
  --subnet 172.20.0.0/16 \
  --gateway 172.20.0.1 \
  myapp-net
```

Custom bridges provide automatic DNS resolution between containers by name.

### nftables (Docker Engine v29)

Experimental support for generating nftables rules directly instead of routing through iptables-nft translation. Requires `"experimental": true` in daemon.json.

## Storage

### Volume Types

- **Named volumes**: Managed by Docker, persist across container restarts (`docker volume create mydata`)
- **Bind mounts**: Map host path into container (`-v /host/path:/container/path`)
- **tmpfs**: In-memory, not persisted (`--tmpfs /tmp:rw,size=100m`)

### Storage Drivers (Docker Engine v29)

| Driver | Status | Notes |
|---|---|---|
| overlay2 | Default | Requires ftype=1 on XFS |
| fuse-overlayfs | Supported | Required for rootless on older kernels |
| btrfs | Supported | Native snapshotting |
| zfs | Supported | Enterprise features |
| devicemapper | Removed (v29) | Migrate to overlay2 |
| aufs | Removed (v29) | Migrate to overlay2 |

With the containerd image store (default in v29), storage is managed by containerd's overlayfs snapshotter.

## Security

### Rootless Mode

Run Docker daemon as non-root, eliminating container-escape-to-root risk:

```bash
dockerd-rootless-setuptool.sh install
export DOCKER_HOST=unix://$XDG_RUNTIME_DIR/docker.sock
```

Limitations: no macvlan/ipvlan, no AppArmor by default, ports < 1024 require `net.ipv4.ip_unprivileged_port_start=0`.

### Runtime Security Controls

```bash
# Drop all capabilities, add only needed
docker run --cap-drop ALL --cap-add NET_BIND_SERVICE myimage

# Read-only filesystem
docker run --read-only --tmpfs /tmp --tmpfs /var/run myimage

# Custom seccomp profile
docker run --security-opt seccomp=/path/to/profile.json myimage

# User namespace remapping (daemon.json: "userns-remap": "default")
```

### Docker Scout

```bash
docker scout cves myimage:latest          # Scan for CVEs
docker scout compare myimage:v1 myimage:v2  # Compare versions
docker scout sbom myimage:latest          # Generate SBOM
docker scout recommendations myimage      # Upgrade suggestions
```

## Docker Desktop vs Docker Engine

| Feature | Docker Desktop | Docker Engine (Linux) |
|---|---|---|
| Platform | macOS, Windows, Linux | Linux only |
| License | Paid for large orgs (>250 employees / >$10M revenue) | Apache 2.0 (free) |
| VM isolation | HyperKit/WSL2/Virtualization.framework | Native (no VM) |
| GUI | Yes (dashboard, extensions) | No |
| Kubernetes | Built-in (optional) | No |

## Common Pitfalls

1. **Using `:latest` in production** -- Not a version, it is a moving target. Pin to specific tags or digests.
2. **COPY . . at the top of Dockerfile** -- Invalidates cache on every source change. Copy dependency manifests first.
3. **Running as root** -- Default for Docker. Always add a `USER` instruction or use `--user` flag.
4. **No .dockerignore** -- Build context includes `.git`, `node_modules`, secrets. Always create a `.dockerignore`.
5. **ADD instead of COPY** -- `ADD` auto-extracts archives and supports URLs, creating unexpected behavior. Use `COPY` unless extraction is intended.
6. **No health checks** -- Without `HEALTHCHECK`, Docker cannot distinguish a healthy container from a hung one.
7. **Storing secrets in images** -- Use BuildKit `--secret` mounts or runtime secrets. Never `ENV SECRET=...` or `COPY .env`.
8. **Not cleaning apt cache** -- `apt-get update && apt-get install` without `rm -rf /var/lib/apt/lists/*` wastes layer space. Use BuildKit cache mounts instead.

## Version-specific guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 29.x | `references/versions/29.md` | containerd image store default, nftables, API minimum 1.44 |

## Reference Files

Read these for implementation depth:

- `references/architecture.md` -- Daemon/containerd/runc internals, BuildKit, networking drivers, storage drivers. Read for "how does X work" questions.
- `references/diagnostics.md` -- docker logs, inspect, stats, events, system df, troubleshooting workflows. Read when troubleshooting.
- `references/best-practices.md` -- Dockerfile patterns, multi-stage builds, security hardening, Compose patterns, image optimization. Read for design questions.

## Diagnostic Scripts

Ready-made docker CLI bundles (read-only, nothing pruned) in `scripts/`.

- `scripts/01-disk-usage.sh` -- Disk breakdown with reclaimable-space preview (dangling images/volumes)
- `scripts/02-container-health.sh` -- Restarting/unhealthy/exited sweep plus one-shot stats

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Terraform Module Library

Build reusable Terraform modules for AWS, Azure, and GCP infrastructure following infrastructure-as-code best practices. Use when creating infrastructure modules, standardizing cloud provisioning, or implementing reusable IaC components.

401991 votes

sematext-otel

Wire a service's OpenTelemetry output to Sematext Cloud. Walks through region, App-type, instrumentation flow (managed OTLP endpoint vs Sematext Agent), and signal selection (traces/metrics/logs), then produces the exact env-var block and points at a runnable reference example in this repo. Invoke when instrumenting a new app for Sematext.

01 votes

Deployment Patterns

Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up deployment infrastructure or planning releases.

2699140 votes

Babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

971540 votes

V7 Roster

Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.

953190 votes
View all in devops →