Agent skill

Docker

by kid-sid in kid-sid/claude-spellbook

A skill your agent uses when writing or optimizing a Dockerfile or docker-compose.yml for local dev, debugging containers that behave differently from local, or reducing image size for Python and…

MITAuto-check: notesDevOps & Cloud

Install Docker

skills CLI
$ npx skills add kid-sid/claude-spellbook --skill docker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kid-sid/claude-spellbook docker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kid-sid/claude-spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker .claude/skills/docker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker
GitHub stars
189
Token cost
~2.5k tokens
SKILL.md length
442 words
Files
1
Skills in repo
54
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when writing or optimizing a Dockerfile or docker-compose.yml for local dev, debugging containers that behave differently from local, or reducing image size for Python and…

  • Optimizing a Dockerfile
  • SKILL.md covers When to Activate, Dockerfile — Python (FastAPI /…, Dockerfile — Node.js (Next.js) and .dockerignore, plus 10 more sections
  • Calls docker; needs SECRET_KEY and POSTGRES_PASSWORD
  • Docker-compose.yml for local dev

What it does

Docker is an agent skill from kid-sid/claude-spellbook. Use when writing or optimizing a Dockerfile or docker-compose.yml for local dev, debugging containers that behave differently from local, or reducing image size for Python and Node.js apps. Not for Kubernetes resources or Helm — use containerization.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Container orchestration. It works with Docker, Python, Node.js and Kubernetes. The repository describes itself as: A curated collection of skills, prompts, and workflows that extend Claude's capabilities — your personal grimoire for AI-powered development. The licence is MIT.

When your agent uses it

  • Optimizing a Dockerfile
  • Docker-compose.yml for local dev
  • Debugging containers that behave differently from local
  • Reducing image size for Python and Node.js apps

Example prompts

  • “/docker”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in SECRET_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit a7c2ac9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY
    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Docker loads about 2.5k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 442 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:101
    **/.env
  • NoteMentions a .env fileSKILL.md:102
    **/.env.*
  • NoteMentions a .env fileSKILL.md:239
    # Option 3: .env file (dev only — don't commit secrets)
  • NoteMentions a .env fileSKILL.md:241
    - .env
  • NoteMentions a .env fileSKILL.md:357
    (`.git`, `node_modules`, `__pycache__`, `.env`) into the build context, bloating image size and potentially leaking secr
  • NoteMentions a .env fileSKILL.md:364
    gnore` excludes `.git`, `node_modules`, `.env`, `__pycache__`
  • NoteMentions a .env fileSKILL.md:369
    ot hardcoded in Dockerfile or committed `.env`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kid-sid/claude-spellbook at commit a7c2ac9, republished under its MIT licence (© kid-sid). 442 words, ~2,483 tokens.

Download SKILL.mdSave it as .claude/skills/docker/SKILL.md (or your agent's skills folder).
name
docker
description
Use when writing or optimizing a Dockerfile or docker-compose.yml for local dev, debugging containers that behave differently from local, or reducing image size for Python and Node.js apps. Not for Kubernetes resources or Helm — use containerization.

Docker Patterns

Production-ready Docker patterns for Python and Node.js services.

When to Activate

  • Writing or optimizing a Dockerfile (multi-stage, layer caching)
  • Configuring Docker Compose services, networking, or volumes
  • Adding health checks or startup dependencies
  • Passing secrets and environment variables safely
  • Debugging a container that won't start or behaves differently in Docker vs local
  • Reducing image size

Dockerfile — Python (FastAPI / uv)

dockerfile
# syntax=docker/dockerfile:1

# --- Build stage ---
FROM python:3.12-slim AS builder

WORKDIR /app

# Install uv
RUN pip install uv --no-cache-dir

# Copy dependency files first — cached unless they change
COPY pyproject.toml uv.lock ./

# Install deps into a prefix (not system), no dev deps
RUN uv sync --frozen --no-dev --prefix /install

# --- Runtime stage ---
FROM python:3.12-slim AS runtime

WORKDIR /app

# Copy installed packages from builder
COPY --from=builder /install /usr/local

# Copy application code last (changes most often)
COPY src/ ./src/

# Non-root user — security best practice
RUN adduser --disabled-password --gecos "" appuser
USER appuser

EXPOSE 8000
CMD ["uvicorn", "src.main:app", "--host", "0.0.0.0", "--port", "8000"]

Dockerfile — Node.js (Next.js)

dockerfile
FROM node:20-alpine AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci --frozen-lockfile

FROM node:20-alpine AS builder
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .
RUN npm run build

FROM node:20-alpine AS runtime
WORKDIR /app
ENV NODE_ENV=production

# Only copy what's needed to run
COPY --from=builder /app/.next/standalone ./
COPY --from=builder /app/.next/static ./.next/static
COPY --from=builder /app/public ./public

EXPOSE 3000
CMD ["node", "server.js"]

Enable standalone output in next.config.js:

js
output: "standalone"

.dockerignore

# Always include these
.git
.gitignore
**/.env
**/.env.*
**/node_modules
**/__pycache__
**/*.pyc
**/*.pyo
.venv
dist
build
.next
coverage
*.log
.DS_Store

Layer Caching Rules

Order files from least-changed to most-changed:

dockerfile
# ✅ GOOD — deps cached unless pyproject.toml changes
COPY pyproject.toml uv.lock ./
RUN uv sync --frozen
COPY src/ ./src/           # code changes don't bust dep layer

# ❌ BAD — any code change busts the dep install layer
COPY . .
RUN uv sync --frozen

Cache mounts (BuildKit) — don't write pip/uv cache to image:

dockerfile
RUN --mount=type=cache,target=/root/.cache/uv \
    uv sync --frozen --no-dev

Docker Compose

yaml
# docker-compose.yml
services:
  api:
    build:
      context: .
      target: runtime          # use a specific stage
    ports:
      - "5003:8000"
    environment:
      DATABASE_URL: postgresql+asyncpg://user:pass@db:5432/app
      REDIS_URL: redis://redis:6379
    depends_on:
      db:
        condition: service_healthy   # wait for health check, not just start
      redis:
        condition: service_started
    restart: unless-stopped
    networks:
      - backend

  db:
    image: postgres:16-alpine
    environment:
      POSTGRES_USER: user
      POSTGRES_PASSWORD: pass
      POSTGRES_DB: app
    volumes:
      - pg_data:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U user -d app"]
      interval: 5s
      timeout: 3s
      retries: 5
      start_period: 10s
    networks:
      - backend

  redis:
    image: redis:7-alpine
    command: redis-server --appendonly yes   # persist to disk
    volumes:
      - redis_data:/data
    healthcheck:
      test: ["CMD", "redis-cli", "ping"]
      interval: 5s
      timeout: 3s
      retries: 3
    networks:
      - backend

volumes:
  pg_data:
  redis_data:

networks:
  backend:
    driver: bridge

Health Checks

yaml
# Standard health check pattern
healthcheck:
  test: ["CMD", "curl", "-f", "http://localhost:8000/health"]
  interval: 30s       # how often to check
  timeout: 10s        # max time per check
  retries: 3          # failures before unhealthy
  start_period: 30s   # grace period before first check counts

FastAPI health endpoint:

python
@app.get("/health")
async def health():
    return {"status": "ok"}

Environment Variables and Secrets

yaml
services:
  api:
    # Option 1: inline (dev only — visible in docker inspect)
    environment:
      SECRET_KEY: dev-secret

    # Option 2: reference host env var (no value = pass-through)
    environment:
      SECRET_KEY: ${SECRET_KEY}

    # Option 3: .env file (dev only — don't commit secrets)
    env_file:
      - .env

    # Option 4: Docker secrets (production / Swarm)
    secrets:
      - db_password

secrets:
  db_password:
    file: ./secrets/db_password.txt

Access secret in container at /run/secrets/db_password.


Networking

yaml
networks:
  frontend:   # API + nginx
  backend:    # API + DB + Redis (not exposed to frontend network)

services:
  nginx:
    networks: [frontend]
  api:
    networks: [frontend, backend]   # bridge between networks
  db:
    networks: [backend]             # only reachable from backend

Service DNS: containers on the same network reach each other by service name.

# From api container, reach db:
postgresql://db:5432/mydb       # "db" resolves to the db container IP
redis://redis:6379

Common Commands

bash
# Build
docker build -t myapp .
docker build --target builder -t myapp:builder .   # build specific stage
docker build --no-cache -t myapp .                  # force rebuild

# Compose
docker compose up -d                   # start in background
docker compose up --build              # rebuild before starting
docker compose down -v                 # stop + remove volumes
docker compose logs -f api             # follow logs for one service
docker compose exec api bash           # shell into running container
docker compose ps                      # status of all services

# Inspect
docker inspect <container>             # full config, env vars, mounts
docker stats                           # live resource usage
docker system df                       # disk usage by layer/image/volume

# Cleanup
docker system prune -f                 # remove stopped containers + dangling images
docker volume prune -f                 # remove unused volumes
docker image prune -a -f               # remove all unused images

Debugging

bash
# Container exits immediately — run it interactively
docker run -it --entrypoint bash myapp

# Check environment inside container
docker exec <container> env

# Copy files out of container
docker cp <container>:/app/logs ./local-logs

# Run with host network (skip Docker networking)
docker run --network host myapp

# Override CMD for one-off
docker compose run --rm api python manage.py migrate

Image Size Reduction

TechniqueSavings
Use slim/alpine base (python:3.12-slim)60–80% vs full image
Multi-stage build — don't ship build toolsvaries
--no-install-recommends on apt-get20–40%
Remove apt cache: rm -rf /var/lib/apt/lists/*small
--no-cache-dir on pipsmall
.dockerignore to skip test/docssmall
dockerfile
# Minimal apt install pattern
RUN apt-get update && apt-get install -y --no-install-recommends \
    curl \
    && rm -rf /var/lib/apt/lists/*

Red Flags

  • COPY . . before installing dependencies — copying all source code first busts the dependency layer on every code change; always COPY pyproject.toml uv.lock ./ → install → COPY src/ ./ so deps are cached unless manifests change
  • Running the container as root — the default user is root inside a container; a process escape gives the attacker full host access; always add RUN adduser --disabled-password appuser && USER appuser in the runtime stage
  • No health check on services others depends_on — depends_on without condition: service_healthy starts the dependent service immediately, before the dependency is actually ready; always define a healthcheck and use service_healthy
  • Secrets in environment: as plaintext — environment variables are visible in docker inspect, CI logs, and image layers if baked in; use Docker secrets, a secrets manager, or pass via host env refs (SECRET_KEY: ${SECRET_KEY})
  • No .dockerignore — without it, COPY . . sends the entire repo (.git, node_modules, __pycache__, .env) into the build context, bloating image size and potentially leaking secrets
  • Single-stage build shipping build tools to production — compilers, dev headers, and test dependencies included in the runtime image increase attack surface and image size; use multi-stage builds so the runtime stage starts fresh from a slim base
  • Anonymous volumes for data that must persist — volumes: ["/var/lib/postgresql/data"] (without a named volume) is recreated on docker compose down; use named volumes (pg_data:/var/lib/postgresql/data) to persist data across restarts
Show full SKILL.md (62 more words)Show less

Checklist

  • Multi-stage build used — builder installs, runtime only has what's needed
  • .dockerignore excludes .git, node_modules, .env, __pycache__
  • Dependencies copied before source code (layer cache)
  • Non-root user for runtime stage
  • Health check defined for services that others depends_on
  • depends_on uses condition: service_healthy not just service_started
  • Secrets not hardcoded in Dockerfile or committed .env
  • Volumes named (not anonymous) for data you want to persist

© kid-sid, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/docker of kid-sid/claude-spellbook.

Open the folder on GitHubat commit a7c2ac9

Compare with similar skills

Docker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker this skillkid-sid/claude-spellbook189—~2.5kAutomated safety check: NotesMIT
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Deploying Go SDK Bundlesastronomer/agents450—~1.8kAutomated safety check: NotesApache-2.0
Docker Devopssoftspark/ai-toolkit179—~2.1kAutomated safety check: PassApache-2.0
Nestjs DeploymentHoangNguyen0403/agent-skills-standard570—~692Automated safety check: PassMIT
Containerization AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: NotesApache-2.0

Similar skills

  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Deploying Go SDK Bundles

    astronomer/agents

    Builds, packs, and deploys compiled Airflow Go SDK bundles so the ExecutableCoordinator can run them.

    450 GitHub stars~1.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Docker Devops

    softspark/ai-toolkit

    Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm.

    179 GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Nestjs Deployment

    HoangNguyen0403/agent-skills-standard

    Containerize NestJS apps with multi-stage Docker builds, tune Node.js memory, and implement graceful shutdown hooks.

    570 GitHub stars~692 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Containerization Assistant

    ArabelaTso/Skills-4-SE

    Generate Dockerfiles, Docker Compose configurations, and Kubernetes manifests for containerizing applications.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes

More from kid-sid/claude-spellbook

All 54 skills in this repo
  • Accessibility

    kid-sid/claude-spellbook

    A skill your agent uses when building or reviewing UI components for keyboard and screen reader compatibility, adding ARIA to custom widgets, auditing a page for WCAG AA conformance, or preparing…

    189 GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Agentex

    kid-sid/claude-spellbook

    A skill your agent uses when building, wiring, or debugging an Agentex agent — choosing agent type, configuring acp.py and manifest.yaml, using adk.messages or adk.state, or resolving…

    189 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • AI Engineer

    kid-sid/claude-spellbook

    A skill your agent uses when building production LLM applications — designing RAG pipelines, choosing vector databases, implementing agent orchestration, optimizing cost, or adding AI safety…

    189 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Angular

    kid-sid/claude-spellbook

    A skill your agent uses when building or refactoring Angular applications — choosing between signals, RxJS, and NgRx for state, configuring routing with guards and lazy loading, optimizing change…

    189 GitHub stars~5k tokensUpdated 2 mo ago
    Auto-check passed
  • API Design

    kid-sid/claude-spellbook

    A skill your agent uses when designing new REST endpoints, reviewing an existing API contract, adding pagination or filtering, planning a versioning strategy, or building a public or partner-facing…

    189 GitHub stars~3.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Auth

    kid-sid/claude-spellbook

    A skill your agent uses when implementing login flows, issuing or validating JWTs, setting up OAuth2/OIDC with a provider, designing role-based or attribute-based access control, securing API…

    189 GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Docker

What does Docker do?

A skill your agent uses when writing or optimizing a Dockerfile or docker-compose.yml for local dev, debugging containers that behave differently from local, or reducing image size for Python and…. Docker is an agent skill from kid-sid/claude-spellbook.js apps.

When should I use Docker?

Docker fits situations like: optimizing a Dockerfile; Docker-compose.yml for local dev; debugging containers that behave differently from local; reducing image size for Python and Node.js apps.

How do I install Docker in Claude Code?

Run `npx skills add kid-sid/claude-spellbook --skill docker -a claude-code`. Or copy the skill folder (skills/docker in kid-sid/claude-spellbook) into .claude/skills/docker in your project. Claude Code loads it when a task matches its description.

How do I install Docker in Codex?

Run `npx skills add kid-sid/claude-spellbook --skill docker -a codex`. Or copy the skill folder (skills/docker in kid-sid/claude-spellbook) into .agents/skills/docker in your project. Codex loads it when a task matches its description.

Can I use Docker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kid-sid/claude-spellbook --skill docker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker, .gemini/skills/docker, .github/skills/docker and .opencode/skills/docker in your project.

What does Docker need to run?

Going by SKILL.md and its folder, Docker needs the command-line tools its instructions call (docker) and credentials named SECRET_KEY and POSTGRES_PASSWORD. Our summary lists: Python 3; Node.js; Docker; A credential in SECRET_KEY.

Does Docker access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Docker use?

Docker is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Docker?

Skills that share tags, products or a category with Docker: Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Deploying Go SDK Bundles (astronomer/agents, 450 stars), Docker Devops (softspark/ai-toolkit, 179 stars) and Nestjs Deployment (HoangNguyen0403/agent-skills-standard, 570 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker?

kid-sid (a GitHub user) maintains it in kid-sid/claude-spellbook, which has 189 GitHub stars. The repository holds 54 skills in this directory. The repository was last updated on August 5, 2026.

Source: kid-sid/claude-spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.