Skip to content
Back to skills

Container Hardening

ASecurity

Secure Docker images and container runtime configurations.

  • 6 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 22, 2026
devopsgobashdockerkubernetesgitapidevopssecurity

Works with

  • api

Security analysis

A93/100
  • highPerforms destructive filesystem operations

Pro shows the line behind each finding and how to fix it

Scanned September 22, 2026

npx -y skills add ranbot-ai/awesome-skills --skill container-hardening --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Container Hardening?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Container Hardening
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ranbot-ai-container-hardening/badge)](https://www.skillsdirectory.com/skills/ranbot-ai-container-hardening)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: container-hardening
description: Secure Docker images and container runtime configurations. 
category: Security & Systems
source: antigravity
tags: [api, ai, agent, template, image, security, vulnerability, docker, kubernetes]
url: https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/container-hardening
---


# Container Hardening

Secure container images and runtime configurations.

## When to Use This Skill

Use this skill when:
- Building secure container images
- Hardening container deployments
- Meeting container security requirements
- Implementing defense in depth

## Dockerfile Security

```dockerfile
# Use minimal base image
FROM alpine:3.18

# Don't run as root
RUN addgroup -g 1001 -S appgroup && \
    adduser -u 1001 -S appuser -G appgroup

# Copy with specific ownership
COPY --chown=appuser:appgroup . /app

# Remove unnecessary packages
RUN apk del --purge build-dependencies && \
    rm -rf /var/cache/apk/*

# Use non-root user
USER appuser

# Read-only filesystem support
WORKDIR /app
```

## Runtime Security

```bash
# Run with security options
docker run -d \
  --read-only \
  --tmpfs /tmp \
  --security-opt=no-new-privileges:true \
  --cap-drop=ALL \
  --cap-add=NET_BIND_SERVICE \
  --user 1001:1001 \
  myapp:latest
```

## Kubernetes Security Context

```yaml
apiVersion: v1
kind: Pod
spec:
  securityContext:
    runAsNonRoot: true
    runAsUser: 1001
    fsGroup: 1001
  containers:
  - name: app
    securityContext:
      allowPrivilegeEscalation: false
      readOnlyRootFilesystem: true
      capabilities:
        drop: ["ALL"]
```

## Image Scanning

```bash
# Scan with Trivy
trivy image --severity HIGH,CRITICAL myapp:latest

# Use distroless images
FROM gcr.io/distroless/static-debian11
```

## Best Practices

- Use minimal base images
- Run as non-root user
- Enable read-only filesystem
- Drop all capabilities
- Scan images regularly
- Sign and verify images
- Use secrets management

## Related Skills

- container-scanning (`container-scanning`) - Vulnerability scanning
- kubernetes-hardening (`kubernetes-hardening`) - K8s security

## Limitations

- Apply guidance only within authorized scope; test destructive steps in non-production first.
- Docs-only import: upstream scripts and templates not bundled.

### Example

```bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20
```

> Adapted from [BagelHole/DevOps-Security-Agent-Skills](https://github.com/BagelHole/DevOps-Security-Agent-Skills) (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…