Docker Compose conventions — short service names, no root, no host ports in base compose, override files for local customisations.

MITAuto-check: notesDevOps & Cloud

Install Docker

skills CLI
$ npx skills add spinspire/pocketbase-sveltekit-starter --skill docker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install spinspire/pocketbase-sveltekit-starter docker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/spinspire/pocketbase-sveltekit-starter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/docker .claude/skills/docker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker
GitHub stars
511
Token cost
~1.1k tokens
SKILL.md length
374 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Docker Compose conventions — short service names, no root, no host ports in base compose, override files for local customisations.

  • Works in 12 steps: .env (git-ignored) + .env.example… → No root. → No port forwarding in the base compose… → …
  • Tasks that involve Containers
  • SKILL.md covers Principles, Patterns and Production checklist
  • Calls docker; needs POSTGRES_PASSWORD

What it does

Docker is an agent skill from spinspire/pocketbase-sveltekit-starter. Docker Compose conventions — short service names, no root, no host ports in base compose, override files for local customisations.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers. It works with Docker and SvelteKit. The repository describes itself as: a starter project to build a SvelteKit frontend with PocketBase backend. The licence is MIT.

When your agent uses it

  • Tasks that involve Containers

Example prompts

  • “/docker”

Requirements

  • Docker

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. .env (git-ignored) + .env.example (checked in, with doc comments).
  2. No root.
  3. No port forwarding in the base compose file.
  4. Override file (example only).
  5. Lightweight images.
  6. Named project.
  7. Mandatory env vars.
  8. Short service names.
  9. Restart policy.
  10. Read-only root.
  11. Log rotation.
  12. Pin images.

What it can do on your machine

Read from SKILL.md and the folder at commit 66f6dee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Docker loads about 1.1k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 374 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:12
    1. **`.env` (git-ignored) + `.env.example` (checked in, with doc comments).**
  • NoteMentions a .env fileSKILL.md:13
    and environment-specific values live in `.env`. The example file documents each variable.
  • NoteMentions a .env fileSKILL.md:127
    - [ ] `.env` in `.gitignore`, `.env.example` checked in

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from spinspire/pocketbase-sveltekit-starter at commit 66f6dee, republished under its MIT licence (© spinspire). 374 words, ~1,084 tokens.

Download SKILL.mdSave it as .claude/skills/docker/SKILL.md (or your agent's skills folder).
name
docker
description
Docker Compose conventions — short service names, no root, no host ports in base compose, override files for local customisations.

Docker Compose conventions

Apply these conventions when creating or modifying docker-compose.yml.

Principles

  1. .env (git-ignored) + .env.example (checked in, with doc comments).
    All secrets and environment-specific values live in .env. The example file documents each variable.

  2. No root.
    Every service that doesn't need root gets user: "${UID:-1000}:${GID:-1000}".

    • Dockerfiles must make the working directory group-writable (RUN chmod g+w .).
    • Postgres is exempt — its official image handles user switching.
  3. No port forwarding in the base compose file.
    ports: only appear in override files. The base file exposes nothing to the host.

  4. Override file (example only).
    Write docker-compose.override-example.yml with documented, commented-out options.
    Users copy it to docker-compose.override.yml (git-ignored) for their local customisations.
    Never write docker-compose.override.yml into the project — only the example.

  5. Lightweight images.
    Prefer -alpine or -slim variants.

  6. Named project.
    Set name: at the top so volumes and containers are predictable. Or use COMPOSE_PROJECT_NAME env var.

  7. Mandatory env vars.
    Use ${VAR:?required} so compose errors immediately when a required variable is missing.

  8. Short service names.
    pg, bun, ml, py, sk (SvelteKit), pb (PocketBase), etc. If there's a "primary" app, their service should be named app.

  9. Restart policy.
    restart: unless-stopped for long-lived services, on-failure:N for batch jobs. Never use always (it reanimates after intentional docker compose stop).

  10. Read-only root.
    read_only: true on every service that doesn't need to write to its own filesystem. Mount tmpfs for paths that must be writable (/tmp, /run). Combine with tmpfs for the writable paths the app actually needs.

  11. Log rotation.
    Every service gets logging.driver: json-file with max-size: 10m and max-file: 3. Prevents disk fills.

  12. Pin images.
    Never :latest — use explicit version tags or digests. Reproducible builds.

Show full SKILL.md (98 more words)Show less

Patterns

Base compose
yaml
name: prj

services:
  app:
    build: .
    image: prj-app
    user: "${UID:-1000}:${GID:-1000}"
    environment:
      DB_URL: postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD}@pg:5432/${POSTGRES_DB}
    depends_on:
      pg:
        condition: service_healthy

  pg:
    image: postgres:17-alpine
    environment:
      POSTGRES_USER: ${POSTGRES_USER:?required}
      POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?required}
      POSTGRES_DB: ${POSTGRES_DB:?required}
    volumes:
      - pgdata:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER} -d ${POSTGRES_DB}"]
      interval: 5s
      timeout: 5s
      retries: 5

volumes:
  pgdata:
Override example
yaml
# docker-compose.override.yml
services:
  pg:
    ports:
      - "127.0.0.1:5432:5432"

  app:
    ports:
      - "127.0.0.1:8000:8000"
    volumes:
      - ./src:/app/src:ro
Dockerfile — writable working dir
dockerfile
WORKDIR /app
RUN chmod g+w .
.env.example
sh
# ── Section ────────────────────────────────────────────────────────
# Description of what this is for.
VAR_NAME=default-value

Production checklist

Before deploying, verify:

  • restart: unless-stopped on every long-lived service
  • deploy.resources.limits.memory + cpus set per service
  • Health checks on all services with start_period
  • depends_on uses condition: service_healthy where needed
  • read_only: true + tmpfs for writable paths
  • user: set to non-root on every non-Postgres service
  • No :latest — all images pinned to versions or digests
  • Log rotation configured (max-size / max-file)
  • .env in .gitignore, .env.example checked in
  • name: set at top of compose file
  • No ports: in base compose (use override files)
  • cap_drop: ALL + specific cap_add + no-new-privileges:true
  • Backend/internal networks use internal: true

© spinspire, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/docker of spinspire/pocketbase-sveltekit-starter.

Open the folder on GitHubat commit 66f6dee

Compare with similar skills

Docker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker this skillspinspire/pocketbase-sveltekit-starter511—~1.1kAutomated safety check: NotesMIT
Weft FrontendWeaveMindAI/weft2k—~8kAutomated safety check: NotesCustom licence
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell15k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Weft Frontend

    WeaveMindAI/weft

    Read when the user wants a page, app or site for the program, and before dispatching the frontend-builder: the verified scaffold commands, the default stack (pnpm, SvelteKit, PostgreSQL, BetterAuth…

    2k GitHub stars~8k tokensUpdated yesterday
    Frontend & DesignAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Ssh Skill

    badseal/ssh-skill

    A skill your agent uses when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download…

    535 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from spinspire/pocketbase-sveltekit-starter

All 8 skills in this repo
  • Bun Runtime

    spinspire/pocketbase-sveltekit-starter

    Bun as runtime, package manager, bundler, and test runner. An agent skill from spinspire/pocketbase-sveltekit-starter.

    511 GitHub starsUsed in 5 repos~653 tokens
    Auto-check: notes
  • Pb API

    spinspire/pocketbase-sveltekit-starter

    Operate PocketBase via its REST API. An agent skill from spinspire/pocketbase-sveltekit-starter.

    511 GitHub stars~562 tokensUpdated 1 mo ago
    Auto-check: notes
  • Pb Extend

    spinspire/pocketbase-sveltekit-starter

    Extend PocketBase with custom hooks and routes in JS or Go. An agent skill from spinspire/pocketbase-sveltekit-starter.

    511 GitHub stars~689 tokensUpdated 1 mo ago
    Auto-check: notes
  • Pwa

    spinspire/pocketbase-sveltekit-starter

    A skill your agent uses when the user asks to make a site installable, turn it into a PWA, add a service worker, add a web app manifest, enable "add to home screen", or support offline.

    511 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Frontend Design

    spinspire/pocketbase-sveltekit-starter

    Create distinctive, production-grade frontend interfaces with high design quality and accessible markup.

    511 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Code Reuse

    spinspire/pocketbase-sveltekit-starter

    A skill your agent uses when building a UI component, PocketBase hook, page, or app feature and there is proven code to copy from the reference repos.

    511 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Categories

Questions about Docker

What does Docker do?

Docker Compose conventions — short service names, no root, no host ports in base compose, override files for local customisations. Docker is an agent skill from spinspire/pocketbase-sveltekit-starter. Docker Compose conventions — short service names, no root, no host ports in base compose, override files for local customisations.

When should I use Docker?

Docker fits situations like: tasks that involve Containers.

How do I install Docker in Claude Code?

Run `npx skills add spinspire/pocketbase-sveltekit-starter --skill docker -a claude-code`. Or copy the skill folder (.agents/skills/docker in spinspire/pocketbase-sveltekit-starter) into .claude/skills/docker in your project. Claude Code loads it when a task matches its description.

How do I install Docker in Codex?

Run `npx skills add spinspire/pocketbase-sveltekit-starter --skill docker -a codex`. Or copy the skill folder (.agents/skills/docker in spinspire/pocketbase-sveltekit-starter) into .agents/skills/docker in your project. Codex loads it when a task matches its description.

Can I use Docker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add spinspire/pocketbase-sveltekit-starter --skill docker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker, .gemini/skills/docker, .github/skills/docker and .opencode/skills/docker in your project.

What does Docker need to run?

Going by SKILL.md and its folder, Docker needs the command-line tools its instructions call (docker) and credentials named POSTGRES_PASSWORD. Our summary lists: Docker.

Does Docker access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Docker use?

Docker is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Docker?

Skills that share tags, products or a category with Docker: Weft Frontend (WeaveMindAI/weft, 2k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker?

spinspire (a GitHub organization) maintains it in spinspire/pocketbase-sveltekit-starter, which has 511 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on August 22, 2026.

Source: spinspire/pocketbase-sveltekit-starter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.