Agent skill

Containerization

by kid-sid in kid-sid/claude-spellbook

A skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…

MITAuto-check: notesDevOps & Cloud

Install Containerization

skills CLI
$ npx skills add kid-sid/claude-spellbook --skill containerization -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kid-sid/claude-spellbook containerization --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/containerization .claude/skills/containerization && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
containerization
GitHub stars
189
Token cost
~4.2k tokens
SKILL.md length
1,087 words
Files
1
Skills in repo
54
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…

  • Configuring Kubernetes resources (Deployment
  • SKILL.md covers When to Activate, Dockerfile Best Practices, docker-compose for Local… and Kubernetes Core Resources, plus 7 more sections
  • Calls helm, docker and uv; needs POSTGRES_PASSWORD
  • Sizing pod resource requests and limits

What it does

Containerization is an agent skill from kid-sid/claude-spellbook. Use when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a service with Helm charts. Not for writing Dockerfiles or docker-compose files — use docker.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Container orchestration. It works with Docker, Kubernetes, Helm and Python. The repository describes itself as: A curated collection of skills, prompts, and workflows that extend Claude's capabilities — your personal grimoire for AI-powered development. The licence is MIT.

When your agent uses it

  • Configuring Kubernetes resources (Deployment
  • Sizing pod resource requests and limits
  • Setting securityContext
  • Packaging a service with Helm charts

Example prompts

  • “/containerization”

Requirements

  • Python 3
  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit a7c2ac9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • helm
    • docker
    • uv
    • npm
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • external-secrets.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Containerization loads about 4.2k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 1,087 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:115
    .env
  • NoteMentions a .env fileSKILL.md:148
    cking services locally. Keep secrets in `.env` (gitignored) and load them via `env_file`.
  • NoteMentions a .env fileSKILL.md:160
    - .env
  • NoteMentions a .env fileSKILL.md:544
    text (including `.git`, `node_modules`, `.env`) is sent to the Docker daemon on every build, leaking secrets and adding
  • NoteMentions a .env fileSKILL.md:552
    - [ ] `.dockerignore` excludes `.git`, `.env`, `node_modules`, `__pycache__`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kid-sid/claude-spellbook at commit a7c2ac9, republished under its MIT licence (© kid-sid). 1,087 words, ~4,204 tokens.

Download SKILL.mdSave it as .claude/skills/containerization/SKILL.md (or your agent's skills folder).
name
containerization
description
Use when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a service with Helm charts. Not for writing Dockerfiles or docker-compose files — use docker.

Containerization

Package and orchestrate services with Docker and Kubernetes using production-ready patterns for image builds, local development, cluster deployments, and autoscaling.

When to Activate

  • Writing or reviewing a Dockerfile for a service
  • Setting up docker-compose for local development
  • Writing Kubernetes manifests for a new service
  • Deploying to a Kubernetes cluster
  • Sizing CPU/memory requests and limits for a pod
  • Setting up a Helm chart
  • Optimizing Docker image build time or image size

Dockerfile Best Practices

Multi-Stage Builds

Multi-stage builds keep build-time tools out of the final image, reducing attack surface and image size.

Python

dockerfile
# Stage 1: build dependencies
FROM python:3.12-slim AS builder
WORKDIR /app
COPY pyproject.toml uv.lock ./
RUN pip install uv && uv sync --frozen --no-dev

# Stage 2: runtime image
FROM python:3.12-slim AS runtime
WORKDIR /app
COPY --from=builder /app/.venv /app/.venv
COPY src/ ./src/
ENV PATH="/app/.venv/bin:$PATH"
USER 1000:1000
EXPOSE 8000
HEALTHCHECK --interval=30s --timeout=5s CMD curl -f http://localhost:8000/health || exit 1
ENTRYPOINT ["python", "-m", "uvicorn", "src.main:app", "--host", "0.0.0.0", "--port", "8000"]

Node.js / TypeScript

dockerfile
FROM node:20-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --include=dev
COPY . .
RUN npm run build

FROM node:20-alpine AS runtime
WORKDIR /app
COPY package*.json ./
RUN npm ci --omit=dev
COPY --from=builder /app/dist ./dist
USER node
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=5s CMD wget -qO- http://localhost:3000/health || exit 1
CMD ["node", "dist/index.js"]

Go (smallest possible image)

dockerfile
FROM golang:1.22-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-w -s" -o /app/server ./cmd/server

FROM gcr.io/distroless/static-debian12 AS runtime
COPY --from=builder /app/server /server
EXPOSE 8080
USER nonroot:nonroot
ENTRYPOINT ["/server"]
Layer Caching Order

Docker caches each layer. If a layer's input changes, all subsequent layers are invalidated. Copy dependency manifests before source code so that the expensive dependency-install step is only re-run when dependencies actually change, not on every source edit.

dockerfile
# BAD — source copy before dependency install; every code change busts the npm ci cache
COPY . .
RUN npm ci

# GOOD — copy only the manifest first; npm ci cache survives source-only changes
COPY package*.json ./
RUN npm ci
COPY . .

The same principle applies to all runtimes:

RuntimeCopy firstThen install
Python (uv)pyproject.toml uv.lockuv sync --frozen
Nodepackage*.jsonnpm ci
Gogo.mod go.sumgo mod download
.dockerignore

Always create a .dockerignore at the repo root. Files excluded here are never sent to the Docker build context, speeding up builds and preventing accidental secret leaks.

dockerignore
.git
.gitignore
.env
*.env
__pycache__
*.pyc
node_modules
dist
build
.pytest_cache
.coverage
*.log
README.md
Base Image Selection
ImageSizeVulnerability surfaceBest for
ubuntu:22.04~80 MBHighDev/debug only
debian:bookworm-slim~75 MBMediumGeneral purpose
python:3.12-slim~150 MBMediumPython apps
node:20-alpine~170 MBLowNode apps
alpine:3.19~7 MBVery lowCustom builds
gcr.io/distroless/static-debian12~2 MBMinimalGo static binaries
gcr.io/distroless/python3-debian12~80 MBMinimalPython (no shell!)

Pin to digest for reproducibility in production:

dockerfile
FROM python:3.12-slim@sha256:abc123...

docker-compose for Local Development

Use docker-compose for wiring together the application and its backing services locally. Keep secrets in .env (gitignored) and load them via env_file.

yaml
version: '3.9'
services:
  app:
    build:
      context: .
      target: runtime  # use multi-stage target
    ports:
      - "8000:8000"
    env_file:
      - .env
    environment:
      DATABASE_URL: postgresql://user:pass@db:5432/appdb
    depends_on:
      db:
        condition: service_healthy
      redis:
        condition: service_healthy
    volumes:
      - ./src:/app/src  # hot-reload in dev
    profiles:
      - dev

  db:
    image: postgres:16-alpine
    environment:
      POSTGRES_USER: user
      POSTGRES_PASSWORD: pass
      POSTGRES_DB: appdb
    volumes:
      - postgres_data:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U user -d appdb"]
      interval: 5s
      timeout: 3s
      retries: 5

  redis:
    image: redis:7-alpine
    healthcheck:
      test: ["CMD", "redis-cli", "ping"]
      interval: 5s
      timeout: 3s
      retries: 5

volumes:
  postgres_data:

Profiles. Use profiles to mark optional services. Start only what you need:

bash
docker compose --profile dev up

Override file. Create docker-compose.override.yml for local-only tweaks (e.g., mounting a local SDK, exposing extra ports). Add it to .gitignore so it never ships.

yaml
# docker-compose.override.yml (gitignored)
services:
  app:
    environment:
      DEBUG: "true"
    volumes:
      - ../my-local-sdk:/app/vendor/sdk

Kubernetes Core Resources

Deployment
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: payment-service
  namespace: production
spec:
  replicas: 3
  selector:
    matchLabels:
      app: payment-service
  strategy:
    type: RollingUpdate
    rollingUpdate:
      maxSurge: 1
      maxUnavailable: 0  # zero-downtime: always have full capacity during rollout
  template:
    metadata:
      labels:
        app: payment-service
    spec:
      containers:
        - name: payment-service
          image: ghcr.io/org/payment-service:abc123
          ports:
            - containerPort: 8000
          resources:
            requests:
              cpu: 100m
              memory: 128Mi
            limits:
              cpu: 500m
              memory: 256Mi
          envFrom:
            - configMapRef:
                name: payment-service-config
          env:
            - name: DATABASE_URL
              valueFrom:
                secretKeyRef:
                  name: payment-service-secrets
                  key: database-url
          readinessProbe:
            httpGet:
              path: /health/ready
              port: 8000
            initialDelaySeconds: 5
            periodSeconds: 10
          livenessProbe:
            httpGet:
              path: /health/live
              port: 8000
            initialDelaySeconds: 30
            periodSeconds: 30
            failureThreshold: 3
Service
yaml
apiVersion: v1
kind: Service
metadata:
  name: payment-service
  namespace: production
spec:
  selector:
    app: payment-service
  ports:
    - port: 80
      targetPort: 8000
  type: ClusterIP  # internal only; use LoadBalancer for external

Service type reference:

TypeAccessibilityUse case
ClusterIPCluster-internal onlyInternal services
NodePortExternal via node IP:portDev/testing
LoadBalancerExternal via cloud LBProd external services
ExternalNameDNS aliasOff-cluster services
Ingress
yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: payment-service
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
  tls:
    - hosts:
        - api.example.com
      secretName: api-tls-cert
  rules:
    - host: api.example.com
      http:
        paths:
          - path: /payments
            pathType: Prefix
            backend:
              service:
                name: payment-service
                port:
                  number: 80
ConfigMap and Secret
yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: payment-service-config
data:
  LOG_LEVEL: "INFO"
  APP_ENV: "production"
---
apiVersion: v1
kind: Secret
metadata:
  name: payment-service-secrets
type: Opaque
data:
  database-url: <base64-encoded-value>  # echo -n "postgresql://..." | base64

Never commit Secrets to git. Use one of:

  • sealed-secrets — encrypts Secret with a cluster key; safe to commit
  • external-secrets-operator — syncs from AWS Secrets Manager / GCP Secret Manager / Vault
  • Vault agent injection — sidecar writes secrets to an in-memory volume

Resource Management

Requests vs Limits
FieldPurposeWhat happens when exceeded
requests.cpuGuaranteed CPU; used for schedulingN/A — node selection only
limits.cpuMaximum CPU the container may useThrottled (not killed)
requests.memoryGuaranteed memory; used for schedulingN/A — node selection only
limits.memoryMaximum memory the container may useOOMKilled (pod restarted)
  • Requests are what the scheduler uses to decide which node a pod lands on.
  • Limits are enforced at runtime by the kernel cgroup.
  • Setting limits.memory without headroom above requests.memory invites spurious OOMKills under GC pressure.
QoS Classes

Kubernetes assigns a QoS class based on how requests and limits are configured. Higher QoS = last to be evicted under node memory pressure.

ClassConditionEviction priority
Guaranteedrequests == limits for every resourceLast to be evicted
Burstablerequests < limits for at least one resourceMiddle
BestEffortNo requests or limits set at allFirst to be evicted

For critical services, set requests == limits to achieve Guaranteed QoS. For batch jobs or low-priority workers, Burstable is acceptable.

Health Probes

ProbeWhat it checksFailure action
readinessProbeIs pod ready to receive traffic?Remove from Service endpoints
livenessProbeIs pod alive?Restart pod
startupProbeHas pod finished starting? (slow-starting apps)Replaces liveness until started

Common mistake: setting livenessProbe.failureThreshold too low (e.g., 2 with periodSeconds: 10) causes restart loops during slow GC pauses or transient DB query spikes. For most services, failureThreshold: 3 with periodSeconds: 30 is a safer baseline.

yaml
# BAD — aggressive liveness; 20 seconds of GC pause triggers restart
livenessProbe:
  httpGet:
    path: /health/live
    port: 8000
  periodSeconds: 10
  failureThreshold: 2

# GOOD — tolerates 90 seconds of unresponsiveness before restarting
livenessProbe:
  httpGet:
    path: /health/live
    port: 8000
  initialDelaySeconds: 30
  periodSeconds: 30
  failureThreshold: 3
Show full SKILL.md (454 more words)Show less

HorizontalPodAutoscaler

HPA scales the replica count based on observed metrics. Requires the metrics-server addon (or custom metrics adapter for non-CPU metrics).

yaml
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
  name: payment-service
spec:
  scaleTargetRef:
    apiVersion: apps/v1
    kind: Deployment
    name: payment-service
  minReplicas: 2
  maxReplicas: 20
  metrics:
    - type: Resource
      resource:
        name: cpu
        target:
          type: Utilization
          averageUtilization: 70

HPA only works correctly when requests.cpu is set — it calculates utilization as actual / request. Without a CPU request, HPA cannot compute a meaningful ratio and will not scale.

Helm Basics

Helm packages Kubernetes manifests into versioned, parameterised charts.

Chart structure:

mychart/
├── Chart.yaml          # metadata (name, version, appVersion)
├── values.yaml         # default values
├── templates/
│   ├── deployment.yaml
│   ├── service.yaml
│   └── _helpers.tpl    # reusable template snippets

Key commands:

bash
helm install my-release ./mychart --values prod-values.yaml
helm upgrade my-release ./mychart --values prod-values.yaml
helm rollback my-release 1
helm diff upgrade my-release ./mychart  # requires helm-diff plugin

values.yaml pattern — expose only what varies per environment:

yaml
# values.yaml
image:
  repository: ghcr.io/org/payment-service
  tag: latest  # override per environment with --set image.tag=abc123

replicaCount: 3

resources:
  requests:
    cpu: 100m
    memory: 128Mi
  limits:
    cpu: 500m
    memory: 256Mi

Override at release time without editing the chart:

bash
helm upgrade my-release ./mychart \
  --values prod-values.yaml \
  --set image.tag=abc123

Security Context

Apply securityContext at both the pod level and the container level. The settings below satisfy most CIS Kubernetes Benchmark requirements.

yaml
# pod-level: applies to all containers in the pod
spec:
  securityContext:
    runAsNonRoot: true
    runAsUser: 1000
    runAsGroup: 1000
    seccompProfile:
      type: RuntimeDefault

  containers:
    - name: app
      # container-level: overrides/extends pod-level settings
      securityContext:
        readOnlyRootFilesystem: true
        allowPrivilegeEscalation: false
        capabilities:
          drop: ["ALL"]

If readOnlyRootFilesystem: true causes write errors, mount an explicit emptyDir volume for the specific writable path rather than disabling the restriction:

yaml
# BAD — disabling readOnly to allow one directory to be writable
securityContext:
  readOnlyRootFilesystem: false

# GOOD — keep readOnly, mount emptyDir for the specific path
securityContext:
  readOnlyRootFilesystem: true
volumeMounts:
  - name: tmp
    mountPath: /tmp
volumes:
  - name: tmp
    emptyDir: {}

See also: ci-cd, deployment-strategies, security

Red Flags

  • Running the container process as root — a process breakout inside the container inherits root on the host; always set USER 1000:1000 (or USER node) in the final Dockerfile stage
  • Copying the entire build context before installing dependencies — COPY . . before RUN npm ci busts the layer cache on every source change, making every build a full cold install
  • Using latest tag in Kubernetes manifests — imagePullPolicy: Always with latest means different nodes may pull different images across a rolling deploy; pin to a commit SHA or versioned tag
  • Setting limits.memory equal to requests.memory with no headroom — a JVM or Python GC spike briefly exceeds the request value; without headroom the pod is OOMKilled and restarted during normal operation
  • Liveness probe with low failureThreshold (1–2) and short periodSeconds (5–10) — a slow GC pause or cold DB query triggers an unnecessary pod restart loop; use failureThreshold: 3 and periodSeconds: 30 as a baseline
  • Storing Kubernetes Secrets as plain base64 in git — base64 is not encryption; use Sealed Secrets or external-secrets-operator so plaintext values never enter version control
  • No .dockerignore — the full build context (including .git, node_modules, .env) is sent to the Docker daemon on every build, leaking secrets and adding seconds of unnecessary transfer
  • HPA configured without CPU requests set — HPA calculates utilization as actual / request; a missing request means the denominator is undefined and the autoscaler cannot make scaling decisions

Checklist

  • Multi-stage Dockerfile used — build tools not in final image
  • Source files copied after dependency files (layer cache optimization)
  • Non-root user set in Dockerfile (USER 1000:1000 or USER node)
  • .dockerignore excludes .git, .env, node_modules, __pycache__
  • HEALTHCHECK instruction defined in Dockerfile
  • All pods have readinessProbe and livenessProbe configured
  • CPU and memory requests and limits set on every container
  • Secrets stored in Kubernetes Secrets (or external secrets manager), not ConfigMaps
  • securityContext sets runAsNonRoot: true and allowPrivilegeEscalation: false
  • HPA configured for services with variable load
  • maxUnavailable: 0 in rolling update strategy for zero-downtime deployments
  • Image tagged with commit SHA, not latest

© kid-sid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/containerization of kid-sid/claude-spellbook.

Open the folder on GitHubat commit a7c2ac9

Compare with similar skills

Containerization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Containerization compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Containerization this skillkid-sid/claude-spellbook189—~4.2kAutomated safety check: NotesMIT
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider173—~2.6kAutomated safety check: PassCustom licence
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Security Review Skill For Dockerxwtro0tk1t-cloud/harness265—~2.8kAutomated safety check: WarnNone
Deploying Go SDK Bundlesastronomer/agents450—~1.8kAutomated safety check: NotesApache-2.0
Docker Devopssoftspark/ai-toolkit179—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    173 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Security Review Skill For Docker

    xwtro0tk1t-cloud/harness

    审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持…

    265 GitHub stars~2.8k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check: warnings
  • Deploying Go SDK Bundles

    astronomer/agents

    Builds, packs, and deploys compiled Airflow Go SDK bundles so the ExecutableCoordinator can run them.

    450 GitHub stars~1.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Docker Devops

    softspark/ai-toolkit

    Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm.

    179 GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Containerizing Applications

    aiskillstore/marketplace

    Containerizes applications with Docker, docker-compose, and Helm charts.

    430 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from kid-sid/claude-spellbook

All 54 skills in this repo
  • Accessibility

    kid-sid/claude-spellbook

    A skill your agent uses when building or reviewing UI components for keyboard and screen reader compatibility, adding ARIA to custom widgets, auditing a page for WCAG AA conformance, or preparing…

    189 GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Agentex

    kid-sid/claude-spellbook

    A skill your agent uses when building, wiring, or debugging an Agentex agent — choosing agent type, configuring acp.py and manifest.yaml, using adk.messages or adk.state, or resolving…

    189 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • AI Engineer

    kid-sid/claude-spellbook

    A skill your agent uses when building production LLM applications — designing RAG pipelines, choosing vector databases, implementing agent orchestration, optimizing cost, or adding AI safety…

    189 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Angular

    kid-sid/claude-spellbook

    A skill your agent uses when building or refactoring Angular applications — choosing between signals, RxJS, and NgRx for state, configuring routing with guards and lazy loading, optimizing change…

    189 GitHub stars~5k tokensUpdated 2 mo ago
    Auto-check passed
  • API Design

    kid-sid/claude-spellbook

    A skill your agent uses when designing new REST endpoints, reviewing an existing API contract, adding pagination or filtering, planning a versioning strategy, or building a public or partner-facing…

    189 GitHub stars~3.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Auth

    kid-sid/claude-spellbook

    A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…

    189 GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Containerization

What does Containerization do?

A skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…. Containerization is an agent skill from kid-sid/claude-spellbook. Use when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a service with Helm charts.

When should I use Containerization?

Containerization fits situations like: configuring Kubernetes resources (Deployment; sizing pod resource requests and limits; setting securityContext; packaging a service with Helm charts.

How do I install Containerization in Claude Code?

Run `npx skills add kid-sid/claude-spellbook --skill containerization -a claude-code`. Or copy the skill folder (skills/containerization in kid-sid/claude-spellbook) into .claude/skills/containerization in your project. Claude Code loads it when a task matches its description.

How do I install Containerization in Codex?

Run `npx skills add kid-sid/claude-spellbook --skill containerization -a codex`. Or copy the skill folder (skills/containerization in kid-sid/claude-spellbook) into .agents/skills/containerization in your project. Codex loads it when a task matches its description.

Can I use Containerization in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kid-sid/claude-spellbook --skill containerization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/containerization, .gemini/skills/containerization, .github/skills/containerization and .opencode/skills/containerization in your project.

What does Containerization need to run?

Going by SKILL.md and its folder, Containerization needs the command-line tools its instructions call (helm, docker, uv, npm and go) and credentials named POSTGRES_PASSWORD. Our summary lists: Python 3; Node.js; Docker.

Does Containerization access the network?

SKILL.md names 2 domains. As links in the text: github.com and external-secrets.io. This is read from the text; nothing was executed.

Is Containerization safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Containerization use?

Containerization is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Containerization use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Containerization?

Skills that share tags, products or a category with Containerization: Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 173 stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Security Review Skill For Docker (xwtro0tk1t-cloud/harness, 265 stars) and Deploying Go SDK Bundles (astronomer/agents, 450 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Containerization?

kid-sid (a GitHub user) maintains it in kid-sid/claude-spellbook, which has 189 GitHub stars. The repository holds 54 skills in this directory. The repository was last updated on August 5, 2026.

Source: kid-sid/claude-spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.