Containerize applications with Docker: Dockerfiles, images, networking, volumes, compose, and production hardening. Use for any deployable service.
Pro scans all 2 files and shows the line behind each finding
Scanned 9/29/2026
npx -y skills add ssrjkk/claude-skills --skill docker --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Docker?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/ssrjkk-docker)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: docker
description: "Containerize applications with Docker: Dockerfiles, images, networking, volumes, compose, and production hardening. Use for any deployable service."
category: devops
tags: [docker, containers, images, dockerfile, compose, deployment, devops]
models: [sonnet, opus, gpt-5, gemini-2.5, glm-4.6]
version: 1.0.0
created: 2026-09-20
updated: 2026-09-28
author: ssrjkk
---
# Docker
> Containerizing applications with Docker for consistent deployment.
## Quick Start
```bash
docker build -t myapp .
docker run -p 8080:8080 myapp
docker compose up -d
```
## When to Use
- Consistent environments across dev, test, and prod
- Microservices and isolated dependencies
- CI/CD artifacts that are identical everywhere
- Local development with databases and services
## Best Practices
### Dockerfiles
- Use multi-stage builds to slim images
- Prefer official and pinned base images (`alpine:3.20`)
- Run as non-root; copy only what is needed
- Layer ordering: dependencies first, code last (better caching)
### Images
- Keep images small: distroless or alpine when possible
- Tag with commit SHA and semver; avoid `latest` for prod
- Scan images with `docker scout` or Trivy
- Use `--platform` for multi-arch builds
### Runtime
- Set resource limits (`--memory`, `--cpus`)
- Use volumes for persistent data; anonymous volumes are ephemeral
- Prefer `init: true` or `tini` to reap zombies
- Add healthchecks so orchestrators can manage lifecycle
## Dependencies
```bash
# Docker Desktop or docker engine + compose plugin
docker --version
docker compose version
```
## Examples
```dockerfile
# Multi-stage Node build
FROM node:22-alpine AS build
WORKDIR /app
COPY package*.json ./
RUN npm ci
COPY . .
RUN npm run build
FROM node:22-alpine AS runtime
ENV NODE_ENV=production
WORKDIR /app
COPY --from=build /app/dist ./dist
COPY --from=build /app/node_modules ./node_modules
USER node
EXPOSE 3000
CMD ["node", "dist/server.js"]
```
```yaml
# docker-compose.yml
services:
web:
build: .
ports:
- "8080:8080"
depends_on:
db:
condition: service_healthy
healthcheck:
test: ["CMD", "wget", "-qO-", "http://localhost:8080/health"]
interval: 10s
retries: 3
db:
image: postgres:17-alpine
environment:
POSTGRES_PASSWORD: secret
volumes:
- pgdata:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U postgres"]
volumes:
pgdata:
```
```bash
# Build and push with metadata
docker build -t ghcr.io/org/myapp:${GITHUB_SHA} .
docker push ghcr.io/org/myapp:${GITHUB_SHA}
```
```bash
# Inspect and debug
docker exec -it myapp sh
docker logs --follow myapp
docker image prune -f
```
## Step-by-Step
1. Write a multi-stage Dockerfile with pinned base images.
2. Order layers for cache efficiency (deps before code).
3. Run as non-root; add a healthcheck.
4. Build and test locally with `docker build` and `docker run`.
5. Compose services for local integration (app + db + cache).
6. Tag images with the commit SHA; push to a registry.
7. Scan for vulnerabilities before deploy.
8. Pin resource limits and set up log rotation.
## Validation
1. `docker build` succeeds with no warnings
2. `docker run` starts and responds to healthcheck
3. Image scan reports no critical vulnerabilities
4. Compose stack starts cleanly with `docker compose up`
5. Non-root container cannot write to protected paths
## Troubleshooting
- "Cannot connect to the Docker daemon": start Docker Desktop/engine.
- Image too large: switch to multi-stage and slimmer base.
- "Address already in use": change host port mapping or stop the conflicting container.Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!