Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when working with Docker — Dockerfile edits, docker-compose services, containers, or the dual-container (fast + Xdebug) setup — even when the user just says 'my container won't start'.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Use this skill when working with Docker configuration, container setup, Dockerfile changes, or docker-compose modifications.
Do NOT use when:
aws-infrastructure skill)devcontainer skill)agents/ or Docs/, check Makefile/Taskfile.yml for targets, read docker-compose.yml/compose.yaml for service layout.docker compose ps to see running containers and their health status.docker compose build <service> (add --no-cache if Dockerfile base layers changed).docker compose up -d, check docker compose ps for healthy status, run a smoke test (e.g., make test-quick or curl localhost)..docker/Dockerfile)Multi-stage build with these targets:
| Stage | Purpose |
|---|---|
base | Alpine + PHP-FPM + system packages + extensions |
dev | Development: Xdebug, dev tools, Composer dev deps |
pro | Production: optimized, no dev deps, New Relic agent |
Key build args:
PHP_VERSION — extracted from Dockerfile, used by CICOMPOSER_AUTH — private registry access (passed as secret)CACHEBUST — weekly cache invalidation (date +%Y-%U)COMPOSER_NO_DEV — 1 for production, 0 for devSome projects run two PHP-FPM containers simultaneously (fast + Xdebug):
| Container | Purpose | PHP-FPM mode |
|---|---|---|
{project}-php | Fast execution, no debugger | pm = dynamic |
{project}-php-xdebug | Xdebug enabled, debugging | pm = ondemand |
NGINX routes requests based on HTTP headers:
X-Xdebug-Enable: 1 or X-Debug-Session: PHPSTORM → Xdebug containerRead docker-compose.yml / compose.yaml to discover the actual service names. Common patterns:
| Service type | Description |
|---|---|
| PHP-FPM | Main application server |
| PHP-FPM + Xdebug | Debugging container |
| NGINX | Reverse proxy |
| Queue worker | Background job processing (e.g., Horizon) |
| Scheduler | Cron/task scheduler |
| Database | MariaDB / MySQL / PostgreSQL |
| Cache | Redis / Memcached |
docker compose exec -T <service> ... for non-interactive (scripts, CI).make console for interactive shell access.make console-xdebug for Xdebug container access.Which test runner and quality commands exist depends on the project shape.
Check for artisan in the project root before picking one:
artisan present) — php artisan test, vendor/bin/phpstan analyse, vendor/bin/rector processartisan) — vendor/bin/phpunit, vendor/bin/phpstan analyse, vendor/bin/rector processEither way the command runs inside the container:
docker compose exec -T <php-service> <command>.
target: pro — no dev dependencies.Extensions are installed via mlocati/php-extension-installer:
base stage so they're available in all targets..env is NOT baked into the Docker image..env is fetched from AWS Secrets Manager at deploy time..env is mounted via docker-compose volumes.Always check the Makefile for available targets before using raw docker commands:
make start # Start all containers
make stop # Stop all containers
make console # Enter PHP container (bash)
make console-xdebug # Enter Xdebug PHP container
make composer-install # Run composer install in container
make migrate # Run migrations
make migrate-and-seed # Run migrations + seed
make test # Run all tests (parallel)
When the development environment is out of sync (missing containers, wrong state):
docker compose ps to see which services are running.make start or docker compose up -d.docker compose build --no-cache <service> after Dockerfile changes.make migrate-and-seed after fresh container start.| Symptom | Cause | Fix |
|---|---|---|
| "Connection refused" | Container not running | make start |
| "Table not found" | Migrations not run | make migrate-and-seed |
| "Class not found" | Composer not installed | make composer-install |
| Old PHP version | Image not rebuilt | docker compose build <php-service> |
| Extension missing | Dockerfile changed | Rebuild with --no-cache |
When running multiple projects simultaneously:
traefik skill) for routing by domain instead of port.docker-compose.shared.yml.When creating or reviewing Dockerfiles:
USER directive before CMD.ENV or COPY secrets. Use --mount=type=secret (BuildKit) or runtime secrets.RUN layer.--read-only flag where possible, mount writable dirs explicitly.latest tag — pin base image versions (node:18.19-alpine, not node:latest).docker scout quickview or Trivy for vulnerability scanning.# Security pattern
RUN addgroup -g 1001 -S appgroup && \
adduser -S appuser -u 1001 -G appgroup
COPY --chown=appuser:appgroup . .
USER 1001
Always add health checks to long-running services:
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
CMD curl -f http://localhost:8080/health || exit 1
In docker-compose, use condition: service_healthy for dependency ordering:
services:
app:
depends_on:
db:
condition: service_healthy
| Technique | Impact | When |
|---|---|---|
| Multi-stage builds | High | Always — separate build from runtime |
| Alpine base images | High | When compatibility allows |
| Distroless images | High | Production, no shell needed |
.dockerignore | Medium | Always — exclude node_modules, .git, tests, docs |
Combine RUN layers | Medium | When installing packages + cleaning cache |
| Copy only artifacts | Medium | COPY --from=build only what's needed |
Use BuildKit cache mounts for package managers:
# Composer (PHP)
RUN --mount=type=cache,target=/root/.composer/cache \
composer install --no-dev --optimize-autoloader
# npm (Node.js)
RUN --mount=type=cache,target=/root/.npm \
npm ci --only=production
Layer ordering for cache efficiency:
composer.json, package.json) — changes sometimesRUN install — cached if dependency files unchangedCOPY . .) — changes often, last layer| Symptom | Root cause | Fix |
|---|---|---|
| Every build reinstalls all dependencies (builds are slow) | COPY . . runs before the dependency install, so any source edit busts the dependency layer's cache | Copy only the manifest + lockfile (composer.json+composer.lock / package.json+lock), install deps, THEN COPY . . |
| Image is much larger / slower to push than expected | No .dockerignore, so .git, vendor/, node_modules/, and local env files enter the build context and image | Add a .dockerignore excluding VCS, installed deps, build output, and secrets |
vendor/ or node_modules/ is empty inside the container even though install ran | A bind-mount of the project directory shadows the image's installed-deps directory | Put a named/anonymous volume over the deps dir, or don't bind-mount over it |
Files the container writes are owned by root on the host | The container process runs as UID 0; bind-mounted writes inherit that owner | Run as a non-root USER whose UID matches the host user, or chown on entry |
| Container exits immediately with code 0 | The CMD process daemonizes/backgrounds, so PID 1 has nothing to keep alive | Run the long-lived process in the foreground as PID 1 (no &, no daemonize flag) |
docker compose down -v destroys volumes including the database — use down without -v unless you mean it.docker compose exec -T (no TTY) when running in scripts or CI.pro stage.platform without verifying AWS runner architecture.traefik — local reverse proxy with real domains and HTTPSdevcontainer — DevContainer and Codespaces setupphp-debugging — Xdebug dual-container architecturedocker-commands.md — all PHP commands run inside Dockerまだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when defining or auditing the activation event — aha-moment selection, retention correlation, falsifiable definition. Triggers on 'what is our aha moment', 'redefine activation'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when capturing an architectural decision — file naming, next ADR number, Status / Context / Decision / Consequences, index regen; fires even without saying 'ADR'.
日本語の概要は準備中です。原文の説明を表示しています。
Adversarial critique — devil's advocate, stress-test, honest teardown ('poke holes', 'be brutal', 'was hältst du davon'); explicit request only. Routine code or design review → code-review.
日本語の概要は準備中です。原文の説明を表示しています。
Use when reading, creating, or updating agent documentation, module docs, roadmaps, or AGENTS.md. Understands the full .augment/, agents/, and copilot-instructions structure.
日本語の概要は準備中です。原文の説明を表示しています。
Use for an adversarial red-team / blue-team / auditor review of an AI agent's CONFIG + behaviour (rules, skills, MCP, hooks, permissions) — attack-chain → defensive-gap list, not a code audit.
日本語の概要は準備中です。原文の説明を表示しています。