Agent skill

Docker Devops

by softspark in softspark/ai-toolkit

Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm.

Apache-2.0Auto-check passedDevOps & Cloud

Install Docker Devops

skills CLI
$ npx skills add softspark/ai-toolkit --skill docker-devops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit docker-devops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/docker-devops .claude/skills/docker-devops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker-devops
GitHub stars
179
Token cost
~2.1k tokens
SKILL.md length
433 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm.

  • Tasks that involve Containers
  • SKILL.md covers Dockerfile Best Practices, Docker Compose Patterns, CI/CD Patterns and Infrastructure as Code, plus 5 more sections
  • Calls docker; needs POSTGRES_PASSWORD
  • Tasks that involve Container orchestration

What it does

Docker Devops is an agent skill from softspark/ai-toolkit. Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm. Triggers: Docker, Dockerfile, container, Kubernetes, k8s, compose, Helm, pod.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Container orchestration. It works with Docker, Kubernetes and Python. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve Container orchestration

Example prompts

  • “/docker-devops”

Requirements

  • Python 3
  • Node.js
  • Docker
  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Docker Devops loads about 2.1k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 433 words, ~2,056 tokens.

Download SKILL.mdSave it as .claude/skills/docker-devops/SKILL.md (or your agent's skills folder).
name
docker-devops
description
Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm. Triggers: Docker, Dockerfile, container, Kubernetes, k8s, compose, Helm, pod.
allowed-tools
Read
effort
medium
user-invocable
false

Docker & DevOps Skill

Dockerfile Best Practices

Multi-Stage Build (Node.js)
dockerfile
# Build stage
FROM node:20-alpine AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci
COPY . .
RUN npm run build

# Production stage
FROM node:20-alpine AS runner
WORKDIR /app
ENV NODE_ENV=production

# Non-root user
RUN addgroup -g 1001 -S nodejs
RUN adduser -S nextjs -u 1001

COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
COPY --from=builder --chown=nextjs:nodejs /app/public ./public

USER nextjs
EXPOSE 3000
CMD ["node", "server.js"]
Multi-Stage Build (Python)
dockerfile
# Build stage
FROM python:3.12-slim AS builder
WORKDIR /app
RUN pip install --no-cache-dir poetry
COPY pyproject.toml poetry.lock ./
RUN poetry export -f requirements.txt -o requirements.txt

# Production stage
FROM python:3.12-slim
WORKDIR /app

# Non-root user
RUN useradd -m -u 1000 appuser

COPY --from=builder /app/requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

COPY --chown=appuser:appuser . .
USER appuser

EXPOSE 8000
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]

Docker Compose Patterns

Development Setup
yaml
version: '3.8'

services:
  app:
    build:
      context: .
      dockerfile: Dockerfile.dev
    volumes:
      - .:/app
      - /app/node_modules
    ports:
      - "3000:3000"
    environment:
      - NODE_ENV=development
      - DATABASE_URL=postgresql://postgres:postgres@db:5432/app
    depends_on:
      - db
      - redis

  db:
    image: postgres:16-alpine
    volumes:
      - postgres_data:/var/lib/postgresql/data
    environment:
      POSTGRES_USER: postgres
      POSTGRES_PASSWORD: postgres
      POSTGRES_DB: app
    ports:
      - "5432:5432"

  redis:
    image: redis:7-alpine
    ports:
      - "6379:6379"

volumes:
  postgres_data:
Production Setup
yaml
version: '3.8'

services:
  app:
    image: ${REGISTRY}/app:${TAG}
    restart: unless-stopped
    ports:
      - "3000:3000"
    environment:
      - NODE_ENV=production
      - DATABASE_URL=${DATABASE_URL}
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:3000/health"]
      interval: 30s
      timeout: 10s
      retries: 3
    deploy:
      resources:
        limits:
          cpus: '1'
          memory: 512M

CI/CD Patterns

GitHub Actions (Node.js)
yaml
name: CI/CD

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-node@v6
        with:
          node-version: '20'
          cache: 'npm'
      - run: npm ci
      - run: npm run lint
      - run: npm run test
      - run: npm run build

  deploy:
    needs: test
    if: github.ref == 'refs/heads/main'
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
      - name: Deploy to production
        run: |
          # Deploy commands
GitHub Actions (Python)
yaml
name: CI/CD

on:
  push:
    branches: [main]
  pull_request:

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-python@v5
        with:
          python-version: '3.12'
      - name: Install dependencies
        run: |
          pip install poetry
          poetry install
      - name: Lint
        run: poetry run ruff check .
      - name: Type check
        run: poetry run mypy .
      - name: Test
        run: poetry run pytest --cov

Infrastructure as Code

Terraform Basic Structure
infrastructure/
├── main.tf
├── variables.tf
├── outputs.tf
├── providers.tf
├── modules/
│   ├── networking/
│   ├── compute/
│   └── database/
└── environments/
    ├── dev/
    ├── staging/
    └── prod/
Terraform Best Practices
hcl
# variables.tf
variable "environment" {
  description = "Environment name"
  type        = string
  validation {
    condition     = contains(["dev", "staging", "prod"], var.environment)
    error_message = "Environment must be dev, staging, or prod."
  }
}

# main.tf
resource "aws_instance" "app" {
  ami           = var.ami_id
  instance_type = var.instance_type

  tags = {
    Name        = "${var.project}-${var.environment}-app"
    Environment = var.environment
    ManagedBy   = "terraform"
  }
}

Health Checks

HTTP Health Check
python
# FastAPI
@app.get("/health")
async def health_check():
    return {
        "status": "healthy",
        "timestamp": datetime.utcnow().isoformat(),
        "version": settings.VERSION
    }

@app.get("/ready")
async def readiness_check():
    # Check database
    try:
        await db.execute("SELECT 1")
    except Exception:
        raise HTTPException(503, "Database not ready")

    return {"status": "ready"}
Docker Health Check
dockerfile
HEALTHCHECK --interval=30s --timeout=10s --retries=3 \
  CMD curl -f http://localhost:3000/health || exit 1

Security Checklist

  • No secrets in Dockerfile or compose
  • Non-root user in container
  • Minimal base image (alpine, distroless)
  • Pinned image versions
  • Read-only filesystem where possible
  • Resource limits defined
  • Health checks configured
  • Logs to stdout/stderr

Rules

  • MUST use multi-stage builds for any production image — shipping build tools in the final layer is wasteful and insecure
  • MUST pin base images by digest (@sha256:...), not just by tag — tags are mutable and reproducibility collapses on every latest update
  • NEVER run a container as root in production — USER appuser with a non-zero UID is the default, not an optimization
  • NEVER COPY . . before the dependency manifest — layer cache becomes useless and every source change re-downloads packages
  • CRITICAL: logs go to stdout/stderr. Containers writing to log files require volumes, lose on crash, and break 12-factor assumptions.
  • MANDATORY: every Dockerfile has a HEALTHCHECK, every compose service has restart: unless-stopped (or always in production)

Gotchas

  • alpine uses musl libc, not glibc. Python wheels compiled for glibc fail to install on alpine — use python:3.12-slim (glibc-based, small) instead of python:3.12-alpine unless you know every dependency ships a musl wheel.
  • docker compose build caches layers per service. A change to a shared file (e.g., root COPY . . used by two services) invalidates both caches. Structure Dockerfiles to copy manifests first, source last.
  • HEALTHCHECK in a Dockerfile is only respected by Docker and Compose, not by Kubernetes. K8s uses its own livenessProbe / readinessProbe. Maintaining both costs duplicate logic.
  • docker compose up -d streams build output only to the terminal, not to a build log. CI that captures docker compose up -d silently misses build errors — use docker compose build as a separate step with log redirection.
  • Container time is host time unless you mount /etc/localtime — a container running on a UTC host is UTC regardless of its TZ env var for anything reading /etc/localtime. For Python datetime.now(timezone.utc) is safer than datetime.now() inside containers.
  • volumes: ./data:/app/data on macOS with VirtioFS mounts with inverted ownership (host UID vs container UID). Containers that chmod/chown the volume fail silently in dev, succeed in Linux CI.
Show full SKILL.md (52 more words)Show less

When NOT to Load

  • For CI/CD pipeline design that uses Docker — use /ci-cd-patterns
  • For generating a project-specific Dockerfile — use /app-builder
  • For Kubernetes-specific manifests beyond Docker — this skill covers compose + basics; use /devops-implementer agent for k8s depth
  • For observability of containers (metrics, logs, traces) — use /observability-patterns
  • For secret management at runtime — use /security-patterns

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/docker-devops of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Docker Devops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker Devops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker Devops this skillsoftspark/ai-toolkit179—~2.1kAutomated safety check: PassApache-2.0
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Deploying Go SDK Bundlesastronomer/agents450—~1.8kAutomated safety check: NotesApache-2.0
Containerizationkid-sid/claude-spellbook189—~4.2kAutomated safety check: NotesMIT
Dockerkid-sid/claude-spellbook189—~2.5kAutomated safety check: NotesMIT
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone

Similar skills

  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Deploying Go SDK Bundles

    astronomer/agents

    Builds, packs, and deploys compiled Airflow Go SDK bundles so the ExecutableCoordinator can run them.

    450 GitHub stars~1.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Containerization

    kid-sid/claude-spellbook

    A skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…

    189 GitHub stars~4.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Docker

    kid-sid/claude-spellbook

    A skill your agent uses when writing or optimizing a Dockerfile or docker-compose.yml for local dev, debugging containers that behave differently from local, or reducing image size for Python and…

    189 GitHub stars~2.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes

Categories

Questions about Docker Devops

What does Docker Devops do?

Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm. Docker Devops is an agent skill from softspark/ai-toolkit. Docker/K8s: Dockerfile, multi-stage, compose, manifests, Helm.

When should I use Docker Devops?

Docker Devops fits situations like: tasks that involve Containers; tasks that involve Container orchestration.

How do I install Docker Devops in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill docker-devops -a claude-code`. Or copy the skill folder (app/skills/docker-devops in softspark/ai-toolkit) into .claude/skills/docker-devops in your project. Claude Code loads it when a task matches its description.

How do I install Docker Devops in Codex?

Run `npx skills add softspark/ai-toolkit --skill docker-devops -a codex`. Or copy the skill folder (app/skills/docker-devops in softspark/ai-toolkit) into .agents/skills/docker-devops in your project. Codex loads it when a task matches its description.

Can I use Docker Devops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill docker-devops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-devops, .gemini/skills/docker-devops, .github/skills/docker-devops and .opencode/skills/docker-devops in your project.

What does Docker Devops need to run?

Going by SKILL.md and its folder, Docker Devops needs the command-line tools its instructions call (docker) and credentials named POSTGRES_PASSWORD. Our summary lists: Python 3; Node.js; Docker. Its frontmatter pre-approves these tools: Read.

Does Docker Devops access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker Devops safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Docker Devops use?

Docker Devops is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker Devops use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Docker Devops?

Skills that share tags, products or a category with Docker Devops: Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars), Deploying Go SDK Bundles (astronomer/agents, 450 stars), Containerization (kid-sid/claude-spellbook, 189 stars) and Docker (kid-sid/claude-spellbook, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker Devops?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.