Ama Logs Update Charts Release Notes
microsoft/Docker-Provider
Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.
A skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…
$ npx skills add kid-sid/claude-spellbook --skill containerization -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kid-sid/claude-spellbook containerization --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/containerization .claude/skills/containerization && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "containerization" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/containerization into .claude/skills/containerization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "containerization", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kid-sid/claude-spellbook/tree/main/skills/containerizationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kid-sid/claude-spellbook --skill containerization -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kid-sid/claude-spellbook containerization --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/containerization .agents/skills/containerization && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "containerization" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/containerization into .agents/skills/containerization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "containerization", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kid-sid/claude-spellbook --skill containerization -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kid-sid/claude-spellbook containerization --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/containerization .cursor/skills/containerization && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "containerization" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/containerization into .cursor/skills/containerization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "containerization", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kid-sid/claude-spellbook.git --path skills/containerization--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kid-sid/claude-spellbook --skill containerization -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kid-sid/claude-spellbook containerization --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/containerization .gemini/skills/containerization && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "containerization" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/containerization into .gemini/skills/containerization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "containerization", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kid-sid/claude-spellbook containerizationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kid-sid/claude-spellbook --skill containerization -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/containerization .github/skills/containerization && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "containerization" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/containerization into .github/skills/containerization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "containerization", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kid-sid/claude-spellbook --skill containerization -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kid-sid/claude-spellbook containerization --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/containerization .opencode/skills/containerization && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "containerization" agent skill from https://github.com/kid-sid/claude-spellbook/tree/main/skills/containerization into .opencode/skills/containerization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "containerization", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
containerizationA skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…
Containerization is an agent skill from kid-sid/claude-spellbook. Use when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a service with Helm charts. Not for writing Dockerfiles or docker-compose files — use docker.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Containers and Container orchestration. It works with Docker, Kubernetes, Helm and Python. The repository describes itself as: A curated collection of skills, prompts, and workflows that extend Claude's capabilities — your personal grimoire for AI-powered development. The licence is MIT.
Read from SKILL.md and the folder at commit a7c2ac9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
helmdockeruvnpmgoFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comexternal-secrets.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
POSTGRES_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Containerization loads about 4.2k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 1,087 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
.envcking services locally. Keep secrets in `.env` (gitignored) and load them via `env_file`.- .envtext (including `.git`, `node_modules`, `.env`) is sent to the Docker daemon on every build, leaking secrets and adding- [ ] `.dockerignore` excludes `.git`, `.env`, `node_modules`, `__pycache__`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kid-sid/claude-spellbook at commit a7c2ac9, republished under its MIT licence (© kid-sid). 1,087 words, ~4,204 tokens.
.claude/skills/containerization/SKILL.md (or your agent's skills folder).Package and orchestrate services with Docker and Kubernetes using production-ready patterns for image builds, local development, cluster deployments, and autoscaling.
Multi-stage builds keep build-time tools out of the final image, reducing attack surface and image size.
Python
# Stage 1: build dependencies
FROM python:3.12-slim AS builder
WORKDIR /app
COPY pyproject.toml uv.lock ./
RUN pip install uv && uv sync --frozen --no-dev
# Stage 2: runtime image
FROM python:3.12-slim AS runtime
WORKDIR /app
COPY --from=builder /app/.venv /app/.venv
COPY src/ ./src/
ENV PATH="/app/.venv/bin:$PATH"
USER 1000:1000
EXPOSE 8000
HEALTHCHECK --interval=30s --timeout=5s CMD curl -f http://localhost:8000/health || exit 1
ENTRYPOINT ["python", "-m", "uvicorn", "src.main:app", "--host", "0.0.0.0", "--port", "8000"]Node.js / TypeScript
FROM node:20-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --include=dev
COPY . .
RUN npm run build
FROM node:20-alpine AS runtime
WORKDIR /app
COPY package*.json ./
RUN npm ci --omit=dev
COPY --from=builder /app/dist ./dist
USER node
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=5s CMD wget -qO- http://localhost:3000/health || exit 1
CMD ["node", "dist/index.js"]Go (smallest possible image)
FROM golang:1.22-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-w -s" -o /app/server ./cmd/server
FROM gcr.io/distroless/static-debian12 AS runtime
COPY --from=builder /app/server /server
EXPOSE 8080
USER nonroot:nonroot
ENTRYPOINT ["/server"]Docker caches each layer. If a layer's input changes, all subsequent layers are invalidated. Copy dependency manifests before source code so that the expensive dependency-install step is only re-run when dependencies actually change, not on every source edit.
# BAD — source copy before dependency install; every code change busts the npm ci cache
COPY . .
RUN npm ci
# GOOD — copy only the manifest first; npm ci cache survives source-only changes
COPY package*.json ./
RUN npm ci
COPY . .The same principle applies to all runtimes:
| Runtime | Copy first | Then install |
|---|---|---|
| Python (uv) | pyproject.toml uv.lock | uv sync --frozen |
| Node | package*.json | npm ci |
| Go | go.mod go.sum | go mod download |
Always create a .dockerignore at the repo root. Files excluded here are never sent to the Docker build context, speeding up builds and preventing accidental secret leaks.
.git
.gitignore
.env
*.env
__pycache__
*.pyc
node_modules
dist
build
.pytest_cache
.coverage
*.log
README.md| Image | Size | Vulnerability surface | Best for |
|---|---|---|---|
ubuntu:22.04 | ~80 MB | High | Dev/debug only |
debian:bookworm-slim | ~75 MB | Medium | General purpose |
python:3.12-slim | ~150 MB | Medium | Python apps |
node:20-alpine | ~170 MB | Low | Node apps |
alpine:3.19 | ~7 MB | Very low | Custom builds |
gcr.io/distroless/static-debian12 | ~2 MB | Minimal | Go static binaries |
gcr.io/distroless/python3-debian12 | ~80 MB | Minimal | Python (no shell!) |
Pin to digest for reproducibility in production:
FROM python:3.12-slim@sha256:abc123...Use docker-compose for wiring together the application and its backing services locally. Keep secrets in .env (gitignored) and load them via env_file.
version: '3.9'
services:
app:
build:
context: .
target: runtime # use multi-stage target
ports:
- "8000:8000"
env_file:
- .env
environment:
DATABASE_URL: postgresql://user:pass@db:5432/appdb
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
volumes:
- ./src:/app/src # hot-reload in dev
profiles:
- dev
db:
image: postgres:16-alpine
environment:
POSTGRES_USER: user
POSTGRES_PASSWORD: pass
POSTGRES_DB: appdb
volumes:
- postgres_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U user -d appdb"]
interval: 5s
timeout: 3s
retries: 5
redis:
image: redis:7-alpine
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 5s
timeout: 3s
retries: 5
volumes:
postgres_data:Profiles. Use profiles to mark optional services. Start only what you need:
docker compose --profile dev upOverride file. Create docker-compose.override.yml for local-only tweaks (e.g., mounting a local SDK, exposing extra ports). Add it to .gitignore so it never ships.
# docker-compose.override.yml (gitignored)
services:
app:
environment:
DEBUG: "true"
volumes:
- ../my-local-sdk:/app/vendor/sdkapiVersion: apps/v1
kind: Deployment
metadata:
name: payment-service
namespace: production
spec:
replicas: 3
selector:
matchLabels:
app: payment-service
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 1
maxUnavailable: 0 # zero-downtime: always have full capacity during rollout
template:
metadata:
labels:
app: payment-service
spec:
containers:
- name: payment-service
image: ghcr.io/org/payment-service:abc123
ports:
- containerPort: 8000
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 256Mi
envFrom:
- configMapRef:
name: payment-service-config
env:
- name: DATABASE_URL
valueFrom:
secretKeyRef:
name: payment-service-secrets
key: database-url
readinessProbe:
httpGet:
path: /health/ready
port: 8000
initialDelaySeconds: 5
periodSeconds: 10
livenessProbe:
httpGet:
path: /health/live
port: 8000
initialDelaySeconds: 30
periodSeconds: 30
failureThreshold: 3apiVersion: v1
kind: Service
metadata:
name: payment-service
namespace: production
spec:
selector:
app: payment-service
ports:
- port: 80
targetPort: 8000
type: ClusterIP # internal only; use LoadBalancer for externalService type reference:
| Type | Accessibility | Use case |
|---|---|---|
ClusterIP | Cluster-internal only | Internal services |
NodePort | External via node IP:port | Dev/testing |
LoadBalancer | External via cloud LB | Prod external services |
ExternalName | DNS alias | Off-cluster services |
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: payment-service
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
tls:
- hosts:
- api.example.com
secretName: api-tls-cert
rules:
- host: api.example.com
http:
paths:
- path: /payments
pathType: Prefix
backend:
service:
name: payment-service
port:
number: 80apiVersion: v1
kind: ConfigMap
metadata:
name: payment-service-config
data:
LOG_LEVEL: "INFO"
APP_ENV: "production"
---
apiVersion: v1
kind: Secret
metadata:
name: payment-service-secrets
type: Opaque
data:
database-url: <base64-encoded-value> # echo -n "postgresql://..." | base64Never commit Secrets to git. Use one of:
| Field | Purpose | What happens when exceeded |
|---|---|---|
requests.cpu | Guaranteed CPU; used for scheduling | N/A — node selection only |
limits.cpu | Maximum CPU the container may use | Throttled (not killed) |
requests.memory | Guaranteed memory; used for scheduling | N/A — node selection only |
limits.memory | Maximum memory the container may use | OOMKilled (pod restarted) |
limits.memory without headroom above requests.memory invites spurious OOMKills under GC pressure.Kubernetes assigns a QoS class based on how requests and limits are configured. Higher QoS = last to be evicted under node memory pressure.
| Class | Condition | Eviction priority |
|---|---|---|
Guaranteed | requests == limits for every resource | Last to be evicted |
Burstable | requests < limits for at least one resource | Middle |
BestEffort | No requests or limits set at all | First to be evicted |
For critical services, set requests == limits to achieve Guaranteed QoS. For batch jobs or low-priority workers, Burstable is acceptable.
| Probe | What it checks | Failure action |
|---|---|---|
readinessProbe | Is pod ready to receive traffic? | Remove from Service endpoints |
livenessProbe | Is pod alive? | Restart pod |
startupProbe | Has pod finished starting? (slow-starting apps) | Replaces liveness until started |
Common mistake: setting livenessProbe.failureThreshold too low (e.g., 2 with periodSeconds: 10) causes restart loops during slow GC pauses or transient DB query spikes. For most services, failureThreshold: 3 with periodSeconds: 30 is a safer baseline.
# BAD — aggressive liveness; 20 seconds of GC pause triggers restart
livenessProbe:
httpGet:
path: /health/live
port: 8000
periodSeconds: 10
failureThreshold: 2
# GOOD — tolerates 90 seconds of unresponsiveness before restarting
livenessProbe:
httpGet:
path: /health/live
port: 8000
initialDelaySeconds: 30
periodSeconds: 30
failureThreshold: 3HPA scales the replica count based on observed metrics. Requires the metrics-server addon (or custom metrics adapter for non-CPU metrics).
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
name: payment-service
spec:
scaleTargetRef:
apiVersion: apps/v1
kind: Deployment
name: payment-service
minReplicas: 2
maxReplicas: 20
metrics:
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: 70HPA only works correctly when requests.cpu is set — it calculates utilization as actual / request. Without a CPU request, HPA cannot compute a meaningful ratio and will not scale.
Helm packages Kubernetes manifests into versioned, parameterised charts.
Chart structure:
mychart/
├── Chart.yaml # metadata (name, version, appVersion)
├── values.yaml # default values
├── templates/
│ ├── deployment.yaml
│ ├── service.yaml
│ └── _helpers.tpl # reusable template snippetsKey commands:
helm install my-release ./mychart --values prod-values.yaml
helm upgrade my-release ./mychart --values prod-values.yaml
helm rollback my-release 1
helm diff upgrade my-release ./mychart # requires helm-diff pluginvalues.yaml pattern — expose only what varies per environment:
# values.yaml
image:
repository: ghcr.io/org/payment-service
tag: latest # override per environment with --set image.tag=abc123
replicaCount: 3
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 256MiOverride at release time without editing the chart:
helm upgrade my-release ./mychart \
--values prod-values.yaml \
--set image.tag=abc123Apply securityContext at both the pod level and the container level. The settings below satisfy most CIS Kubernetes Benchmark requirements.
# pod-level: applies to all containers in the pod
spec:
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
seccompProfile:
type: RuntimeDefault
containers:
- name: app
# container-level: overrides/extends pod-level settings
securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]If readOnlyRootFilesystem: true causes write errors, mount an explicit emptyDir volume for the specific writable path rather than disabling the restriction:
# BAD — disabling readOnly to allow one directory to be writable
securityContext:
readOnlyRootFilesystem: false
# GOOD — keep readOnly, mount emptyDir for the specific path
securityContext:
readOnlyRootFilesystem: true
volumeMounts:
- name: tmp
mountPath: /tmp
volumes:
- name: tmp
emptyDir: {}See also:
ci-cd,deployment-strategies,security
USER 1000:1000 (or USER node) in the final Dockerfile stageCOPY . . before RUN npm ci busts the layer cache on every source change, making every build a full cold installlatest tag in Kubernetes manifests — imagePullPolicy: Always with latest means different nodes may pull different images across a rolling deploy; pin to a commit SHA or versioned taglimits.memory equal to requests.memory with no headroom — a JVM or Python GC spike briefly exceeds the request value; without headroom the pod is OOMKilled and restarted during normal operationfailureThreshold (1–2) and short periodSeconds (5–10) — a slow GC pause or cold DB query triggers an unnecessary pod restart loop; use failureThreshold: 3 and periodSeconds: 30 as a baseline.dockerignore — the full build context (including .git, node_modules, .env) is sent to the Docker daemon on every build, leaking secrets and adding seconds of unnecessary transferrequests set — HPA calculates utilization as actual / request; a missing request means the denominator is undefined and the autoscaler cannot make scaling decisionsUSER 1000:1000 or USER node).dockerignore excludes .git, .env, node_modules, __pycache__HEALTHCHECK instruction defined in DockerfilereadinessProbe and livenessProbe configuredrequests and limits set on every containersecurityContext sets runAsNonRoot: true and allowPrivilegeEscalation: falsemaxUnavailable: 0 in rolling update strategy for zero-downtime deploymentslatest© kid-sid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/containerization of kid-sid/claude-spellbook.
Open the folder on GitHubat commit a7c2ac9
Containerization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Containerization this skillkid-sid/claude-spellbook | 189 | — | ~4.2k | Automated safety check: Notes | MIT | |
| Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider | 173 | — | ~2.6k | Automated safety check: Pass | Custom licence | |
| Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Security Review Skill For Dockerxwtro0tk1t-cloud/harness | 265 | — | ~2.8k | Automated safety check: Warn | None | |
| Deploying Go SDK Bundlesastronomer/agents | 450 | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Docker Devopssoftspark/ai-toolkit | 179 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 |
microsoft/Docker-Provider
Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
xwtro0tk1t-cloud/harness
审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持…
astronomer/agents
Builds, packs, and deploys compiled Airflow Go SDK bundles so the ExecutableCoordinator can run them.
softspark/ai-toolkit
Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm.
aiskillstore/marketplace
Containerizes applications with Docker, docker-compose, and Helm charts.
kid-sid/claude-spellbook
A skill your agent uses when building or reviewing UI components for keyboard and screen reader compatibility, adding ARIA to custom widgets, auditing a page for WCAG AA conformance, or preparing…
kid-sid/claude-spellbook
A skill your agent uses when building, wiring, or debugging an Agentex agent — choosing agent type, configuring acp.py and manifest.yaml, using adk.messages or adk.state, or resolving…
kid-sid/claude-spellbook
A skill your agent uses when building production LLM applications — designing RAG pipelines, choosing vector databases, implementing agent orchestration, optimizing cost, or adding AI safety…
kid-sid/claude-spellbook
A skill your agent uses when building or refactoring Angular applications — choosing between signals, RxJS, and NgRx for state, configuring routing with guards and lazy loading, optimizing change…
kid-sid/claude-spellbook
A skill your agent uses when designing new REST endpoints, reviewing an existing API contract, adding pagination or filtering, planning a versioning strategy, or building a public or partner-facing…
kid-sid/claude-spellbook
A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…
Works with
Categories
A skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…. Containerization is an agent skill from kid-sid/claude-spellbook. Use when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a service with Helm charts.
Containerization fits situations like: configuring Kubernetes resources (Deployment; sizing pod resource requests and limits; setting securityContext; packaging a service with Helm charts.
Run `npx skills add kid-sid/claude-spellbook --skill containerization -a claude-code`. Or copy the skill folder (skills/containerization in kid-sid/claude-spellbook) into .claude/skills/containerization in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kid-sid/claude-spellbook --skill containerization -a codex`. Or copy the skill folder (skills/containerization in kid-sid/claude-spellbook) into .agents/skills/containerization in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kid-sid/claude-spellbook --skill containerization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/containerization, .gemini/skills/containerization, .github/skills/containerization and .opencode/skills/containerization in your project.
Going by SKILL.md and its folder, Containerization needs the command-line tools its instructions call (helm, docker, uv, npm and go) and credentials named POSTGRES_PASSWORD. Our summary lists: Python 3; Node.js; Docker.
SKILL.md names 2 domains. As links in the text: github.com and external-secrets.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Containerization is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Containerization: Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 173 stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Security Review Skill For Docker (xwtro0tk1t-cloud/harness, 265 stars) and Deploying Go SDK Bundles (astronomer/agents, 450 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kid-sid (a GitHub user) maintains it in kid-sid/claude-spellbook, which has 189 GitHub stars. The repository holds 54 skills in this directory. The repository was last updated on August 5, 2026.
Source: kid-sid/claude-spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.