本文へ移動
cccskills
無料GitHub で公開

docker-expert

Advanced Docker containerization expert for multi-stage builds, image optimization, security hardening, and Compose orchestration. Use when the task involves `working with Dockerfile`, `docker-compose.yml`, `containerization`, `multi-stage builds`, or `optimizing Docker images`.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md3.9 KB
  • assets/.dockerignore483 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

When to Use

  • Creating or optimizing a Dockerfile for any project.
  • Setting up or reviewing docker-compose.yml for local development or production.
  • Troubleshooting container security, large image sizes, or slow build times.
  • Implementing multi-stage builds to separate dependencies from runtime.

Critical Patterns

  • Security First (Non-Root): NEVER run containers as root. Always create and switch to a non-root user via the USER instruction.
  • Secrets over Env Vars: Use Docker Secrets (secrets:) for sensitive data in docker-compose.yml rather than plain environment variables.
  • Multi-Stage Builds: Always separate the builder (compilation, dependency fetching) from the final runtime image. Do not ship build tools to production.
  • Minimal Attack Surface: Prefer alpine, slim, or distroless base images.
  • Supply Chain Integrity: Pin base image versions down to the digest (e.g., alpine:3.21@sha256:xyz...).
  • Layer Caching: Order instructions by frequency of change. Copy and install dependencies before copying the rest of the source code.
  • One Layer Operations: Chain apt-get update with apt-get install using && and clear the cache (rm -rf /var/lib/apt/lists/*) in the exact same RUN command.

Code Examples

Optimized Multi-Stage Dockerfile

# Stage 1: Build & Dependencies
FROM node:18-alpine AS deps
WORKDIR /app
COPY package*.json ./
RUN --mount=type=cache,target=/root/.npm \
    npm ci --only=production

# Stage 2: Build source
FROM node:18-alpine AS build
WORKDIR /app
COPY package*.json ./
RUN npm ci
COPY . .
RUN npm run build && npm prune --production

# Stage 3: Runtime
FROM node:18-alpine AS runtime
# Create non-root user explicitly
RUN addgroup -g 1001 -S nodejs && adduser -S appuser -u 1001 -G nodejs
WORKDIR /app

# Copy only what is strictly necessary
COPY --from=deps --chown=appuser:nodejs /app/node_modules ./node_modules
COPY --from=build --chown=appuser:nodejs /app/dist ./dist

# Drop privileges
USER appuser

EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
  CMD wget --no-verbose --tries=1 --spider http://localhost:3000/health || exit 1

CMD ["node", "dist/index.js"]

Production-Ready Compose Pattern

version: '3.8'
services:
  app:
    build:
      context: .
      target: runtime
    depends_on:
      db:
        condition: service_healthy
    networks:
      - frontend
      - backend
    deploy:
      resources:
        limits:
          cpus: '0.5'
          memory: 512M

  db:
    image: postgres:15-alpine
    environment:
      POSTGRES_DB_FILE: /run/secrets/db_name
      POSTGRES_USER_FILE: /run/secrets/db_user
      POSTGRES_PASSWORD_FILE: /run/secrets/db_password
    secrets:
      - db_name
      - db_user
      - db_password
    networks:
      - backend
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER}"]
      interval: 10s
      timeout: 5s
      retries: 5

networks:
  frontend:
  backend:
    internal: true

secrets:
  db_name:
    external: true
  db_user:
    external: true
  db_password:
    external: true

Commands

# Clean builds with no cache
docker build --pull --no-cache -t my-app:latest .

# Validate Compose configuration
docker-compose config

# Check local image sizes and tags
docker images --format "table {{.Repository}}\t{{.Tag}}\t{{.Size}}"

Resources

  • Templates: See assets/.dockerignore for a production-ready .dockerignore template to optimize build context.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Audit and improve web accessibility following WCAG 2.1 guidelines. Use when the task involves `improve accessibility`, `a11y audit`, `WCAG compliance`, `screen reader support`, `keyboard navigation`, or `make accessible`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

astro

無料

Skill for building with the Astro web framework. Helps create Astro components and pages, configure SSR adapters, set up content collections, deploy static sites, and manage project structure and CLI commands. Use when the user needs to work with Astro, mentions .astro files, asks about static site generation (SSG), islands architecture, content collections, or deploying an Astro project.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Apply modern web development best practices for security, compatibility, and code quality. Use when the task involves `apply best practices`, `security audit`, `modernize code`, `code quality review`, or `check for vulnerabilities`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Optimize Core Web Vitals (LCP, INP, CLS) for better page experience and search ranking. Use when the task involves `improve Core Web Vitals`, `fix LCP`, `reduce CLS`, `optimize INP`, `page experience optimization`, or `fix layout shifts`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Create distinctive, production-grade frontend interfaces with high design quality that avoids generic AI aesthetics. Use when the task involves `build web components`, `create frontend interface`, `build web page`, `build web application`, `frontend design`, `create UI component`, or `design web interface`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Comprehensive guide for building robust, secure, and efficient CI/CD pipelines using GitHub Actions. Use when the task involves `creating or editing GitHub Actions workflows`, `.github/workflows/*.yml`, `CI/CD pipelines`, `GitHub Actions best practices`, or `workflow optimization`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

dallay のスキルをすべて見る

このスキルの問題を報告する