Agent skill

Docker Best Practices

by rohitg00 in rohitg00/awesome-claude-code-toolkit

Docker best practices including multi-stage builds, compose patterns, image optimization, and security

Apache-2.0Auto-check: notesDevOps & Cloud

Install Docker Best Practices

skills CLI
$ npx skills add rohitg00/awesome-claude-code-toolkit --skill docker-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rohitg00/awesome-claude-code-toolkit docker-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rohitg00/awesome-claude-code-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-best-practices .claude/skills/docker-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker-best-practices
GitHub stars
2.7k
Token cost
~938 tokens
SKILL.md length
156 words
Files
1
Skills in repo
37
Repo updated
First seen
Licence
Apache-2.0

At a glance

Docker best practices including multi-stage builds, compose patterns, image optimization, and security

  • Tasks that involve Containers
  • SKILL.md covers Multi-Stage Build, Python Multi-Stage, Docker Compose and .dockerignore, plus 3 more sections
  • Calls docker; needs POSTGRES_PASSWORD
  • Tasks that involve Web performance

What it does

Docker Best Practices is an agent skill from rohitg00/awesome-claude-code-toolkit. Docker best practices including multi-stage builds, compose patterns, image optimization, and security

Its SKILL.md is about 940 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Web performance. It works with Docker. The repository describes itself as: The most comprehensive toolkit for Claude Code -- 135 agents, 35 curated skills, 42 commands, 176+ plugins, 20 hooks, 15 rules, 7 templates, 14 MCP configs, 26 companion apps, 52… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve Web performance

Example prompts

  • “/docker-best-practices”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit ebdf1d5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Docker Best Practices loads about 938 tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 156 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~938

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:109
    .env*
  • NoteMentions a .env fileSKILL.md:148
    gnore` excludes `.git`, `node_modules`, `.env`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rohitg00/awesome-claude-code-toolkit at commit ebdf1d5, republished under its Apache-2.0 licence (© rohitg00). 156 words, ~938 tokens.

Download SKILL.mdSave it as .claude/skills/docker-best-practices/SKILL.md (or your agent's skills folder).
name
docker-best-practices
description
Docker best practices including multi-stage builds, compose patterns, image optimization, and security

Docker Best Practices

Multi-Stage Build

dockerfile
FROM node:22-alpine AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci --only=production

FROM node:22-alpine AS build
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci
COPY . .
RUN npm run build

FROM node:22-alpine AS runtime
WORKDIR /app
RUN addgroup -g 1001 -S appgroup && adduser -S appuser -u 1001 -G appgroup
COPY --from=deps /app/node_modules ./node_modules
COPY --from=build /app/dist ./dist
COPY --from=build /app/package.json ./
USER appuser
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=3s CMD wget -qO- http://localhost:3000/healthz || exit 1
CMD ["node", "dist/server.js"]

Separate dependency installation from build steps. Final stage contains only runtime artifacts.

Python Multi-Stage

dockerfile
FROM python:3.12-slim AS builder
WORKDIR /app
RUN python -m venv /opt/venv
ENV PATH="/opt/venv/bin:$PATH"
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

FROM python:3.12-slim
WORKDIR /app
RUN useradd --create-home appuser
COPY --from=builder /opt/venv /opt/venv
ENV PATH="/opt/venv/bin:$PATH"
COPY . .
USER appuser
CMD ["gunicorn", "app:create_app()", "-b", "0.0.0.0:8000", "-w", "4"]

Docker Compose

yaml
services:
  api:
    build:
      context: .
      dockerfile: Dockerfile
      target: runtime
    ports:
      - "3000:3000"
    environment:
      - DATABASE_URL=postgres://user:pass@db:5432/app
      - REDIS_URL=redis://cache:6379
    depends_on:
      db:
        condition: service_healthy
      cache:
        condition: service_started
    restart: unless-stopped
    deploy:
      resources:
        limits:
          memory: 512M

  db:
    image: postgres:16-alpine
    volumes:
      - pgdata:/var/lib/postgresql/data
    environment:
      POSTGRES_DB: app
      POSTGRES_USER: user
      POSTGRES_PASSWORD: pass
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U user -d app"]
      interval: 5s
      timeout: 3s
      retries: 5

  cache:
    image: redis:7-alpine
    command: redis-server --maxmemory 128mb --maxmemory-policy allkeys-lru

volumes:
  pgdata:

.dockerignore

node_modules
.git
.env*
*.md
docker-compose*.yml
.github
coverage
dist

Always include a .dockerignore to reduce build context size and prevent leaking secrets.

Image Optimization Tips

bash
# Check image size breakdown
docker history --human --no-trunc <image>

# Use dive for layer analysis
dive <image>

# Multi-arch build
docker buildx build --platform linux/amd64,linux/arm64 -t registry/app:1.0 --push .

Combine RUN commands to reduce layers. Order instructions from least to most frequently changing for cache efficiency.

Anti-Patterns

  • Running as root inside containers
  • Using ADD when COPY suffices (ADD auto-extracts tarballs, pulls URLs)
  • Storing secrets in environment variables in Dockerfiles
  • Not pinning base image versions (FROM node:latest)
  • Missing .dockerignore causing large build contexts
  • Installing dev dependencies in production images

Checklist

  • Multi-stage build separates build and runtime stages
  • Non-root user created and used with USER directive
  • Base images pinned to specific versions (e.g., node:22-alpine)
  • .dockerignore excludes .git, node_modules, .env
  • HEALTHCHECK instruction defined
  • Production image contains no build tools or dev dependencies
  • docker-compose uses depends_on with health conditions
  • Secrets passed via build secrets or runtime mounts, not ENV in Dockerfile

© rohitg00, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/docker-best-practices of rohitg00/awesome-claude-code-toolkit.

Open the folder on GitHubat commit ebdf1d5

Compare with similar skills

Docker Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker Best Practices this skillrohitg00/awesome-claude-code-toolkit2.7k—~938Automated safety check: NotesApache-2.0
Cold Startserithemage/serverless-openclaw196—~1.1kAutomated safety check: PassNone
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Cold Start

    serithemage/serverless-openclaw

    References cold start optimization history and techniques. An agent skill from serithemage/serverless-openclaw.

    196 GitHub stars~1.1k tokensUpdated 6 mo ago
    DevOps & CloudAuto-check passed
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from rohitg00/awesome-claude-code-toolkit

All 37 skills in this repo
  • Accessibility Wcag

    rohitg00/awesome-claude-code-toolkit

    Web accessibility patterns for WCAG 2.2 compliance including ARIA, keyboard navigation, screen readers, and testing

    2.7k GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • API Design Patterns

    rohitg00/awesome-claude-code-toolkit

    REST API design with resource naming, pagination, versioning, and OpenAPI spec generation

    2.7k GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Authentication Patterns

    rohitg00/awesome-claude-code-toolkit

    Authentication and authorization patterns including OAuth2, JWT, RBAC, session management, and PKCE flows

    2.7k GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • AWS Cloud Patterns

    rohitg00/awesome-claude-code-toolkit

    AWS cloud patterns for Lambda, ECS, S3, DynamoDB, and Infrastructure as Code with CDK/Terraform

    2.7k GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • CI CD Pipelines

    rohitg00/awesome-claude-code-toolkit

    CI/CD pipeline patterns for GitHub Actions, GitLab CI, testing strategies, and deployment automation

    2.7k GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Continuous Learning

    rohitg00/awesome-claude-code-toolkit

    Auto-extract patterns from coding sessions, track corrections, and build reusable knowledge with confidence scoring

    2.7k GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Docker Best Practices

What does Docker Best Practices do?

Docker best practices including multi-stage builds, compose patterns, image optimization, and security. Docker Best Practices is an agent skill from rohitg00/awesome-claude-code-toolkit.

When should I use Docker Best Practices?

Docker Best Practices fits situations like: tasks that involve Containers; tasks that involve Web performance.

How do I install Docker Best Practices in Claude Code?

Run `npx skills add rohitg00/awesome-claude-code-toolkit --skill docker-best-practices -a claude-code`. Or copy the skill folder (skills/docker-best-practices in rohitg00/awesome-claude-code-toolkit) into .claude/skills/docker-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Docker Best Practices in Codex?

Run `npx skills add rohitg00/awesome-claude-code-toolkit --skill docker-best-practices -a codex`. Or copy the skill folder (skills/docker-best-practices in rohitg00/awesome-claude-code-toolkit) into .agents/skills/docker-best-practices in your project. Codex loads it when a task matches its description.

Can I use Docker Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rohitg00/awesome-claude-code-toolkit --skill docker-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-best-practices, .gemini/skills/docker-best-practices, .github/skills/docker-best-practices and .opencode/skills/docker-best-practices in your project.

What does Docker Best Practices need to run?

Going by SKILL.md and its folder, Docker Best Practices needs the command-line tools its instructions call (docker) and credentials named POSTGRES_PASSWORD. Our summary lists: Python 3; Docker.

Does Docker Best Practices access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker Best Practices safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Docker Best Practices use?

Docker Best Practices is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker Best Practices use?

About 938 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Docker Best Practices?

Skills that share tags, products or a category with Docker Best Practices: Cold Start (serithemage/serverless-openclaw, 196 stars), Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker Best Practices?

rohitg00 (a GitHub user) maintains it in rohitg00/awesome-claude-code-toolkit, which has 2,685 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on May 12, 2026.

Source: rohitg00/awesome-claude-code-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.