Iron Proxy Gateway for NanoClaw
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
Updates Docker container image tags used by Aspire hosting integrations.
$ npx skills add microsoft/aspire --skill update-container-images -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/aspire update-container-images --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/aspire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/update-container-images .claude/skills/update-container-images && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "update-container-images" agent skill from https://github.com/microsoft/aspire/tree/main/.agents/skills/update-container-images into .claude/skills/update-container-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-container-images", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/aspire/tree/main/.agents/skills/update-container-imagesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/aspire --skill update-container-images -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/aspire update-container-images --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/aspire.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/update-container-images .agents/skills/update-container-images && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "update-container-images" agent skill from https://github.com/microsoft/aspire/tree/main/.agents/skills/update-container-images into .agents/skills/update-container-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-container-images", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/aspire --skill update-container-images -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/aspire update-container-images --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/aspire.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/update-container-images .cursor/skills/update-container-images && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "update-container-images" agent skill from https://github.com/microsoft/aspire/tree/main/.agents/skills/update-container-images into .cursor/skills/update-container-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-container-images", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/aspire.git --path .agents/skills/update-container-images--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/aspire --skill update-container-images -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/aspire update-container-images --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/aspire.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/update-container-images .gemini/skills/update-container-images && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "update-container-images" agent skill from https://github.com/microsoft/aspire/tree/main/.agents/skills/update-container-images into .gemini/skills/update-container-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-container-images", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/aspire update-container-imagesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/aspire --skill update-container-images -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/aspire.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/update-container-images .github/skills/update-container-images && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "update-container-images" agent skill from https://github.com/microsoft/aspire/tree/main/.agents/skills/update-container-images into .github/skills/update-container-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-container-images", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/aspire --skill update-container-images -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/aspire update-container-images --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/aspire.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/update-container-images .opencode/skills/update-container-images && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "update-container-images" agent skill from https://github.com/microsoft/aspire/tree/main/.agents/skills/update-container-images into .opencode/skills/update-container-images/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "update-container-images", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
update-container-imagesUpdates Docker container image tags used by Aspire hosting integrations.
Update Container Images is an agent skill from microsoft/aspire, published by the product's own GitHub organization. Updates Docker container image tags used by Aspire hosting integrations. Queries registries for newer tags, uses LLM to determine version-compatible updates, and applies changes. Use this when asked to update container image versions.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files.
It sits in DevOps & Cloud, covering Containers. It works with Docker. The repository describes itself as: Aspire is the tool for code-first, extensible, observable dev and deploy. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a3f44d2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (C#), which the agent can run.
Shell commands in SKILL.md call:
dotnetFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
container-registry.oracle.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Update Container Images loads about 2.4k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 917 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft/aspire at commit a3f44d2, republished under its MIT licence (© microsoft). 917 words, ~2,387 tokens.
.claude/skills/update-container-images/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.You are a specialized container image update agent for the microsoft/aspire repository. Your primary function is to update the Docker container image tags used by Aspire hosting integrations to their latest compatible versions.
Aspire hosting integrations pin specific Docker image tags in *ImageTags.cs files (e.g., SeqContainerImageTags.cs, RedisContainerImageTags.cs). These tags ensure the Aspire orchestrator uses known-compatible container images at runtime. Tags are intentionally pinned (never latest) and require periodic manual updates — roughly monthly.
Each *ImageTags.cs file follows this pattern:
internal static class RedisContainerImageTags
{
/// <remarks>docker.io</remarks>
public const string Registry = "docker.io";
/// <remarks>library/redis</remarks>
public const string Image = "library/redis";
/// <remarks>8.6</remarks>
public const string Tag = "8.6";
}Some files contain multiple image definitions (primary + companion tools) using field name prefixes:
// Primary image: Registry, Image, Tag
// Companion: PgAdminRegistry, PgAdminImage, PgAdminTagThe repository uses 5 container registries:
| Registry | Domain | Auth |
|---|---|---|
| Docker Hub | docker.io | Anonymous (Hub REST API) |
| Microsoft Container Registry | mcr.microsoft.com | Anonymous (OCI v2) |
| GitHub Container Registry | ghcr.io | Anonymous token |
| Oracle Container Registry | container-registry.oracle.com | Anonymous token |
| Quay.io (Red Hat) | quay.io | Anonymous (OCI v2) |
A single-file C# script is bundled at .agents/skills/update-container-images/UpdateImageTags.cs. It discovers all *ImageTags.cs files, parses them, queries each registry for available tags, and outputs a structured JSON report. This script handles the deterministic work; the LLM handles version analysis.
This skill is typically invoked with one of:
Run the companion script from the repository root to generate a JSON report of all images and their available tags:
cd <repo-root>
dotnet run .agents/skills/update-container-images/UpdateImageTags.cs 2>update-tags-stderr.txt 1>update-tags-report.jsonCheck stderr for any failures:
cat update-tags-stderr.txtAll registries should report a tag count. If any show FAILED, investigate the error (usually auth or network issues) before proceeding.
Read the generated update-tags-report.json. The report structure is:
{
"images": [
{
"file": "src\\Aspire.Hosting.Redis\\RedisContainerImageTags.cs",
"entries": [
{
"registry": "docker.io",
"image": "library/redis",
"currentTag": "8.6",
"availableTags": ["8.6", "8.4", "8.2", "9.0", ...]
}
]
}
]
}Entries marked with "skipped": true should be ignored (they are latest tags or derived/computed tags).
The script handles comprehensive tag discovery automatically — for Docker Hub images it queries both recent tags and version-prefix-based queries to ensure newer major/minor versions are included in the results.
For each image, apply these version analysis rules:
The new tag must use the same version format as the current tag:
| Current Tag Format | Example | Match Pattern | Do NOT pick |
|---|---|---|---|
M.m (2-part) | 8.2 | 8.6, 9.0 | 8.6.1, v8.6 |
M.m.p (3-part) | 9.9.0 | 9.12.0, 10.0.0 | 9.12, v9.12.0 |
vM.m.p (v-prefix 3-part) | v1.15.5 | v1.16.3, v2.0.0 | 1.16.3, v1.16 |
vM.m (v-prefix 2-part) | v2.5 | v2.6, v3.0 | v2.5.1, 2.5 |
YYYY.N (year.seq) | 2025.2 | 2025.3, 2026.1 | 2025.2.15571 |
M.m.p.b (4-part) | 23.26.0.0 | 23.26.1.0 | 23.26.1 |
YYYY-suffix | 2022-latest | 2025-latest | 2022-CU23 |
M.m.p-pre.N | 2.3.0-preview.4 | 2.3.0-preview.5 | 2.3.0, 2.3-preview |
Do cross major version boundaries. If Postgres is at 17.8 and 18.2 exists as an M.m tag, update to 18.2. The goal is to pick the newest tag that matches the same format.
Ignore tags with platform suffixes like -alpine, -bookworm, -amd64, -arm64, -fpm, -management-alpine, etc. Only consider "bare" tags matching the version format.
Exception: Tags like 4.2-management in RabbitMQ are derived/computed from the base Tag field and will be flagged as "isDerived": true in the report. Skip these — they auto-update when the base tag is updated.
Check the source file for comments about known issues. For example, Milvus has:
// Note that when trying to update to v2.6.0 we hit https://github.com/microsoft/aspire/issues/11184If such a comment exists, stay within the noted version range (e.g., v2.5.x for Milvus) unless you can verify the issue is resolved.
"latest" — cannot be version-bumped"vnext-latest" — not a version scheme$"{Tag}-management") — updated automaticallyBefore applying changes, present a summary table to the user:
| Image | Current | New | Notes |
|-------|---------|-----|-------|
| library/postgres | 17.8 | 18.2 | Major version bump |
| qdrant/qdrant | v1.15.5 | v1.16.3 | Minor + patch bump |
| library/redis | 8.6 | 8.6 | Already latest |Wait for user confirmation before proceeding. If the user wants to skip specific updates, honor that.
Edit each *ImageTags.cs file to update both the tag value and its <remarks> XML comment:
// Before:
/// <remarks>17.6</remarks>
public const string Tag = "17.6";
// After:
/// <remarks>18.2</remarks>
public const string Tag = "18.2";Always update both the <remarks> and the string literal — they must stay in sync.
Build all affected projects to ensure the changes compile:
# Restore first if needed
./restore.cmd # Windows
./restore.sh # Linux/macOS
# Build each affected project
dotnet build src/Aspire.Hosting.Redis/Aspire.Hosting.Redis.csproj --no-restore -v q /p:SkipNativeBuild=true
dotnet build src/Aspire.Hosting.PostgreSQL/Aspire.Hosting.PostgreSQL.csproj --no-restore -v q /p:SkipNativeBuild=true
# ... repeat for each modified projectAll projects must build successfully. If any fail, investigate whether it's related to the tag change (it shouldn't be — these are just string constants).
Present a final summary:
## Container Image Tag Updates
Updated 15 tags across 12 files:
| File | Field | Old Tag | New Tag |
|------|-------|---------|---------|
| PostgresContainerImageTags.cs | Tag | 17.6 | 18.2 |
| PostgresContainerImageTags.cs | PgAdminTag | 9.9.0 | 9.12.0 |
| ... | ... | ... | ... |
Unchanged (already latest): 14 entries
Skipped (latest/derived): 6 entries
Build: ✅ All affected projects compile<remarks> and string literal in synclatest tags — they are intentionally unpinned8.6 to 8.6.1)v1.16.3 to v1.16)update-tags-report.json, update-tags-stderr.txt) after completing401 Unauthorized: The script needs to acquire a token from https://container-registry.oracle.com/auth. If this fails, Oracle may be experiencing issues — skip and flag for manual review.Some images use non-standard versioning:
YYYY.N format (e.g., 2025.2), but also has build-number tags like 2025.2.15571 — ignore the build-number variants23.26.1.0) — all 4 parts are significantYYYY-latest rolling tags — look for newer year-based rolling tags© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files in .agents/skills/update-container-images of microsoft/aspire.
Open the folder on GitHubat commit a3f44d2
Update Container Images next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Update Container Images this skillmicrosoft/aspire | 6.3k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Iron Proxy Gateway for NanoClawnanocoai/nanoclaw | 31k | — | ~4.6k | Automated safety check: Notes | MIT | |
| GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb | 6.7k | — | ~4k | Automated safety check: Notes | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | |
| Build Openshell Mxc WindowsNVIDIA/OpenShell | 15k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 |
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
GreptimeTeam/greptimedb
Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
NVIDIA/OpenShell
Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.
omnigent-ai/omnigent
Brings up the Omnigent server and Postgres as a Docker compose stack on any Docker host, and covers the Dockerfile's runtime and host build targets for extending it to a new platform.
microsoft/aspire
A skill your agent uses when asked to trigger or inspect Aspire internal Azure DevOps builds, source-index runs, or release validation on dnceng/internal; push to the internal mirror; download build…
microsoft/aspire
Backports a merged PR to a release branch by triggering the /backport bot, waiting for the bot-created PR, and filling in the shiproom template (Customer Impact, Testing, Risk, Regression?).
microsoft/aspire
Bumps the Aspire repository product version in eng/Versions.props using previous version-bump commits as guidance.
microsoft/aspire
Guide for diagnosing GitHub Actions test failures, extracting failed tests from runs, and creating or updating failing-test issues.
microsoft/aspire
Create a pull request using the repository PR template. An agent skill from microsoft/aspire.
microsoft/aspire
Guide for writing tests for the Aspire Dashboard. An agent skill from microsoft/aspire.
Works with
Categories
Updates Docker container image tags used by Aspire hosting integrations. Update Container Images is an agent skill from microsoft/aspire, published by the product's own GitHub organization. Updates Docker container image tags used by Aspire hosting integrations.
Update Container Images fits situations like: tasks that involve Containers.
Run `npx skills add microsoft/aspire --skill update-container-images -a claude-code`. Or copy the skill folder (.agents/skills/update-container-images in microsoft/aspire) into .claude/skills/update-container-images in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/aspire --skill update-container-images -a codex`. Or copy the skill folder (.agents/skills/update-container-images in microsoft/aspire) into .agents/skills/update-container-images in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/aspire --skill update-container-images -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-container-images, .gemini/skills/update-container-images, .github/skills/update-container-images and .opencode/skills/update-container-images in your project.
Going by SKILL.md and its folder, Update Container Images needs C# for the scripts in its folder and the command-line tools its instructions call (dotnet). Our summary lists: Docker.
SKILL.md names 1 domain. In commands or code: container-registry.oracle.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Update Container Images is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Update Container Images: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/aspire, which has 6,348 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.
Source: microsoft/aspire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.