Odoo Docker Deployment
sickn33/agentic-awesome-skills
Production-ready Docker and docker-compose setup for Odoo with PostgreSQL, persistent volumes, environment-based configuration, and Nginx reverse proxy.
Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nginx --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/nginx .claude/skills/nginx && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nginx" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/nginx into .claude/skills/nginx/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nginx", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/nginxType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nginx --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/nginx .agents/skills/nginx && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nginx" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/nginx into .agents/skills/nginx/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nginx", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nginx --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/nginx .cursor/skills/nginx && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nginx" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/nginx into .cursor/skills/nginx/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nginx", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git --path .claude/skills/nginx--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nginx --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/nginx .gemini/skills/nginx && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nginx" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/nginx into .gemini/skills/nginx/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nginx", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nginxInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/nginx .github/skills/nginx && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nginx" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/nginx into .github/skills/nginx/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nginx", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nginx --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/nginx .opencode/skills/nginx && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nginx" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/nginx into .opencode/skills/nginx/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nginx", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nginxProduction NGINX configuration best practices, especially as a reverse proxy in front of containerized backends.
Nginx is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends. Use when writing or editing nginx.conf, server blocks, upstreams, SSL, proxy caching, security headers, structured logging, or stream (TCP/UDP) proxying. Covers the Docker-DNS resolver that keeps upstreams from going stale, separate access-controlled health ports, the stream-block placement gotcha, and headers that must be sent on errors too. Kept separate from the docker and docker-swarm skills.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Cloud networking. It works with NGINX and Docker. The repository describes itself as: The definitive starting point for Claude Code projects. Based on Claude Code Mastery Guides V1-V5. The licence is MIT.
Read from SKILL.md and the folder at commit 61fbb99. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are nginx).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nginx loads about 1.9k tokens when it runs. Until then it costs about 130 tokens; SKILL.md has 666 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from TheDecipherist/claude-code-mastery-project-starter-kit at commit 61fbb99, republished under its MIT licence (© TheDecipherist). 666 words, ~1,872 tokens.
.claude/skills/nginx/SKILL.md (or your agent's skills folder).Aimed at NGINX in front of containerized backends. The defaults are fine for a static site, these are the things that bite in production.
By default NGINX resolves an upstream host once, at startup, and caches the IP forever. In Docker that IP belongs to a container that will be replaced, so the proxy keeps sending traffic to a dead address. Point NGINX at Docker's internal DNS and force re-resolution:
http {
resolver 127.0.0.11 ipv6=off valid=10s; # Docker DNS, re-resolve every 10s
}valid=10s is what makes NGINX pick up the new container after a restart or scale. This is the NGINX side of "never hardcode IPs", see the docker-swarm skill for the principle.
Reference backends by service name, never IP. Reuse connections with keepalive, which needs HTTP/1.1 and a cleared Connection header:
upstream backend {
server backend-service:8080;
keepalive 32;
}
server {
location / {
proxy_pass http://backend;
proxy_http_version 1.1;
proxy_set_header Connection "";
}
}Log JSON so an aggregator can parse it, and write to stdout/stderr so Docker's logging driver captures it. Never log to a file inside the container.
log_format json_log escape=json '{'
'"time":$msec,"method":"$request_method","status":$status,'
'"uri":"$request_uri","rt":$request_time,'
'"upstream":"$upstream_addr","cache":"$upstream_cache_status",'
'"client":"$remote_addr","xff":"$http_x_forwarded_for"'
'}';
access_log /dev/stdout json_log;
error_log /dev/stderr warn;Keep health checks and metrics off the production port: different access control, no log noise, no interference with real traffic. Restrict to internal networks and turn off access logging.
server { # load balancer health check
listen 82;
allow 10.0.0.0/8; allow 172.16.0.0/12; allow 127.0.0.1; deny all;
location /health { access_log off; return 200 "OK"; }
}
server { # stub_status for Prometheus/Datadog
listen 81;
allow 10.0.0.0/8; allow 127.0.0.1; deny all;
location /nginx_status { stub_status on; }
}A deep health check that proxies an upstream's own /health is worth a third port when a service's liveness depends on its backend being reachable.
Proxying a non-HTTP protocol like MongoDB or a database uses the stream module, which is a top-level block, not inside http. Putting it inside http is a silent misconfiguration. HTTP services (an Elasticsearch REST proxy, say) stay inside http.
load_module modules/ngx_stream_module.so;
include /etc/nginx/mongo.conf; # stream { ... } OUTSIDE http
http {
include /etc/nginx/elasticsearch.conf; # HTTP proxy, INSIDE http
}Modern protocols and ciphers, session cache, OCSP stapling. When certs come from Docker secrets they are mounted at /run/secrets/<name>:
ssl_certificate /run/secrets/server_pem;
ssl_certificate_key /run/secrets/server_key;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_session_cache shared:SSL:60m;
ssl_stapling on; ssl_stapling_verify on;Send security headers with always so they are present on error responses too, not just 2xx/3xx:
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;CSP is the highest-value security header and the one almost always left out. The others harden edges; CSP is the primary defense against XSS and content injection, it tells the browser which sources are allowed to load scripts, styles, images, and frames, so an injected <script> from an attacker simply doesn't execute. A site without a CSP has no second line of defense once markup injection gets through. Add it by default, do not wait to be asked.
default-src 'self' alone is technically a CSP but it breaks most real apps (CDNs, inline styles, analytics) and lulls you into thinking you're covered, so set the directives explicitly:
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'" always;Rules that matter:
'unsafe-inline' and 'unsafe-eval' in script-src. They re-open the XSS hole CSP exists to close. If you have inline scripts, use a per-request nonce or a hash, not a blanket unsafe allow.object-src 'none' and base-uri 'self' are free wins that block plugin and base-tag injection. Set them every time.frame-ancestors controls who can iframe you and supersedes X-Frame-Options, so put your clickjacking policy here.Content-Security-Policy-Report-Only to collect violations without enforcing, watch what trips, tighten, then promote to the enforcing header. The real policy is app-specific and is built by tuning, not guessed in one line.Cache GET/HEAD, and serve stale on upstream error or timeout so a backend hiccup doesn't reach users:
proxy_cache es_cache;
proxy_cache_methods GET HEAD;
proxy_cache_valid 200 1m;
proxy_cache_key $host$uri$args;
proxy_cache_use_stale updating error timeout http_500 http_502 http_503 http_504;
proxy_hide_header X-Powered-By;
add_header X-Proxy-Cache $upstream_cache_status;NGINX config copied in with Windows CRLF line endings can fail to parse or behave oddly in a Linux container, which is why production NGINX images often run dos2unix on the configs at build time. If nginx -t reports something that makes no sense, check the line endings first, see the dev-pitfalls skill.
This skill is built to grow. Add a directive when a real production NGINX problem has a stable, defensible fix. ModSecurity/WAF setup (build as a dynamic module, load_module) is deep enough to deserve its own section when needed.
© TheDecipherist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/nginx of TheDecipherist/claude-code-mastery-project-starter-kit.
Open the folder on GitHubat commit 61fbb99
Nginx next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nginx this skillTheDecipherist/claude-code-mastery-project-starter-kit | 338 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Odoo Docker Deploymentsickn33/agentic-awesome-skills | 47k | 2 repos | ~1.2k | Automated safety check: Notes | MIT | |
| Memstack Deployment Hetzner Setupcwinvestments/memstack | 423 | — | ~4.1k | Automated safety check: Notes | Proprietary | |
| Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package | 187 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Deploy Detect Skilljiushiwon/wg-skills | 110 | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | |
| Super Deploy Skillsjiushiwon/wg-skills | 110 | — | ~716 | Automated safety check: Pass | Apache-2.0 |
sickn33/agentic-awesome-skills
Production-ready Docker and docker-compose setup for Odoo with PostgreSQL, persistent volumes, environment-based configuration, and Nginx reverse proxy.
cwinvestments/memstack
A skill your agent uses when the user says 'Hetzner', 'VPS setup', 'server provisioning', 'deploy to VPS', 'hetzner-setup', 'cloud server', or needs to provision, harden, and deploy applications to…
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.
jiushiwon/wg-skills
用于自动检测项目根目录的技术栈(语言、Web 框架、前端框架、数据库、缓存/消息),并生成标准化的「项目部署画像 deploy-profile.md」,作为 server-setup-skill、static-nginx-skill、deploy-native-skill、deploy-docker-skill 共享的事实来源。当用户说「部署检测」「detect…
jiushiwon/wg-skills
一键部署技能套件(父入口)。覆盖项目技术栈检测、服务器环境检测与依赖安装、前端 Nginx 托管、原生部署脚本、Docker 部署。当用户说「部署项目」「一键部署」「deploy」「帮我上线」「发布到服务器」时触发,并按意图路由到子技能 deploy-detect-skill / server-setup-skill / static-nginx-skill /…
LeoYeAI/openclaw-master-skills
Your on-call DevOps assistant — one-click deploy, monitoring setup, scheduled backups, and fault diagnosis.
TheDecipherist/claude-code-mastery-project-starter-kit
Scaffold a new microservice that follows the project's server/handlers/adapters architecture.
TheDecipherist/claude-code-mastery-project-starter-kit
Where CSS should live. An agent skill from TheDecipherist/claude-code-mastery-project-starter-kit.
TheDecipherist/claude-code-mastery-project-starter-kit
Production Docker best practices for writing Dockerfiles, Compose files, and Swarm stacks.
TheDecipherist/claude-code-mastery-project-starter-kit
Production Docker Swarm deployment rules: what changes when a compose file goes from a single node to a multi-node Swarm.
TheDecipherist/claude-code-mastery-project-starter-kit
Production MongoDB backup and restore practices that the documentation gets wrong.
TheDecipherist/claude-code-mastery-project-starter-kit
Production MongoDB replica-set operation: topology, durability, host tuning, and the container-specific gotchas Claude gets wrong.
Categories
Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends. Nginx is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Production NGINX configuration best practices, especially as a reverse proxy in front of containerized backends.
Nginx fits situations like: editing nginx.conf; security headers; structured logging; stream (TCP/UDP) proxying.
Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a claude-code`. Or copy the skill folder (.claude/skills/nginx in TheDecipherist/claude-code-mastery-project-starter-kit) into .claude/skills/nginx in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a codex`. Or copy the skill folder (.claude/skills/nginx in TheDecipherist/claude-code-mastery-project-starter-kit) into .agents/skills/nginx in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nginx -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nginx, .gemini/skills/nginx, .github/skills/nginx and .opencode/skills/nginx in your project.
SKILL.md names no scripts, command-line tools or credentials: Nginx is instructions for the agent only. Our summary lists: Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nginx is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nginx: Odoo Docker Deployment (sickn33/agentic-awesome-skills, 47k stars), Memstack Deployment Hetzner Setup (cwinvestments/memstack, 423 stars), Frappe Ops Deployment (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars) and Deploy Detect Skill (jiushiwon/wg-skills, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TheDecipherist (a GitHub user) maintains it in TheDecipherist/claude-code-mastery-project-starter-kit, which has 338 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on June 29, 2026.
Source: TheDecipherist/claude-code-mastery-project-starter-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.