Agent skill

Maintaining Docker Hub

by TriliumNext in TriliumNext/Trilium

A skill your agent uses when working on Trilium's published Docker images on Docker Hub or GHCR rather than on the Dockerfiles — "how many pulls does the image get?", "why is the Docker Hub…

AGPL-3.0Auto-check: warningsDevOps & Cloud

Install Maintaining Docker Hub

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add TriliumNext/Trilium --skill maintaining-docker-hub -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TriliumNext/Trilium maintaining-docker-hub --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TriliumNext/Trilium.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/maintaining-docker-hub .claude/skills/maintaining-docker-hub && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
maintaining-docker-hub
GitHub stars
38k
Token cost
~2.3k tokens
SKILL.md length
1,133 words
Files
2
Skills in repo
23
Repo updated
First seen
Licence
AGPL-3.0

At a glance

A skill your agent uses when working on Trilium's published Docker images on Docker Hub or GHCR rather than on the Dockerfiles — "how many pulls does the image get?", "why is the Docker Hub…

  • Works in 4 steps: Deleting a tag frees nothing. The image… → Deleting an image index deletes its… → A digest a tag still uses cannot be… → …
  • Working on Triliums published Docker images on Docker Hub
  • SKILL.md covers The repositories, What is published where, How Docker Hub stores images and Recipes, plus 3 more sections
  • Runs JavaScript scripts from its folder; calls node and docker; needs DOCKERHUB_TOKEN and GITHUB_TOKEN

What it does

Maintaining Docker Hub is an agent skill from TriliumNext/Trilium. Use when working on Trilium's published Docker images on Docker Hub or GHCR rather than on the Dockerfiles — "how many pulls does the image get?", "why is the Docker Hub repository so big?", "clean up old tags", "delete untagged images", "which tags do we publish?", the legacy repositories (triliumnext/notes, zadam/trilium) and their mirroring, the main-docker.yml copy-to-Docker-Hub step, mirror-legacy-docker.yml, Docker Hub categories, stars or the overview. Includes hub.mjs (stats, tag listing/deletion, the…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in DevOps & Cloud, covering Containers. It works with Docker. The repository describes itself as: Build your personal knowledge base with Trilium Notes. The licence is AGPL-3.0.

When your agent uses it

  • Working on Triliums published Docker images on Docker Hub
  • GHCR rather than on the Dockerfiles — how many pulls does the image get?
  • Why is the Docker Hub repository so big?
  • Clean up old tags

Example prompts

  • “how many pulls does the image get?”
  • “why is the Docker Hub repository so big?”
  • “clean up old tags”
  • “/maintaining-docker-hub”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in DOCKERHUB_TOKEN
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Deleting a tag frees nothing. The image stays, pullable by digest, and keeps counting toward
  2. Deleting an image index deletes its per-platform images. Trilium's index holds 8 manifests (4
  3. A digest a tag still uses cannot be deleted — the registry answers 403. That holds through
  4. Untagged images are listed by GET /v2/namespaces//repositories//manifests

What it can do on your machine

Read from SKILL.md and the folder at commit 80be026. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DOCKERHUB_TOKEN
    • GITHUB_TOKEN
    • ZADAM_DOCKERHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Maintaining Docker Hub loads about 2.3k tokens when it runs. Until then it costs about 191 tokens; SKILL.md has 1,133 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~191
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:20
    redentials come from `docker login` (`~/.docker/config.json` or its `credsStore` helper), or from

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TriliumNext/Trilium at commit 80be026, republished under its AGPL-3.0 licence (© TriliumNext). 1,133 words, ~2,345 tokens.

Download SKILL.mdSave it as .claude/skills/maintaining-docker-hub/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
maintaining-docker-hub
description
Use when working on Trilium's published Docker images on Docker Hub or GHCR rather than on the Dockerfiles — "how many pulls does the image get?", "why is the Docker Hub repository so big?", "clean up old tags", "delete untagged images", "which tags do we publish?", the legacy repositories (triliumnext/notes, zadam/trilium) and their mirroring, the main-docker.yml copy-to-Docker-Hub step, mirror-legacy-docker.yml, Docker Hub categories, stars or the overview. Includes hub.mjs (stats, tag listing/deletion, the manifest inventory and a safe untagged-image purge, all dry-run by default) and the storage model that decides how a cleanup works. Do NOT use for building or running the image locally (see the Developer Guide's Docker page).

Maintaining Trilium's Docker Hub repositories

Everything below is done through one script, hub.mjs. Don't write throwaway Python or curl loops against the Hub API — the pagination caps, token expiry, rate limits and the storage model below each broke a hand-rolled attempt once.

bash
H=.claude/skills/maintaining-docker-hub/hub.mjs
node $H stats triliumnext/trilium triliumnext/notes zadam/trilium   # pulls, stars, storage, weekly series
node $H tags triliumnext/trilium --prefix sha-                       # list; add --delete to delete
node $H inventory triliumnext/trilium                                # every manifest, untagged included
node $H purge triliumnext/trilium --older-than 7                     # dry run; add --delete to delete

Credentials come from docker login (~/.docker/config.json or its credsStore helper), or from DOCKERHUB_USERNAME + DOCKERHUB_TOKEN. stats and listing work for anyone signed in; deleting needs an owner of the namespace. Every delete is the user's call — run the dry run, report its numbers, and wait for an explicit go-ahead before --delete. A delete is not reversible.

The repositories

RepositoryRolePulls / week (Sep 2026)Credentials in CI
triliumnext/triliumthe image~140KDOCKERHUB_USERNAME / DOCKERHUB_TOKEN
ghcr.io/triliumnext/triliumbuild target; every tag, sha-* included—GITHUB_TOKEN
triliumnext/notespre-rename image, last own build v0.95.0~29.6Ksame as the image
zadam/triliumthe original Trilium image, last own build 0.63.7~24K (from totals)zadam + ZADAM_DOCKERHUB_TOKEN

stats prints the weekly series Docker Hub embeds in the repository page (repoPullsData); it is published for organization repositories only, so zadam/trilium has none and its rate has to be derived from pull_count snapshots (the Wayback Machine has archived copies of hub.docker.com/v2/repositories/<repo>). Pulls count manifest requests, so auto-updaters (Watchtower, Diun) polling an unchanged tag inflate them — read them as "installations still tracking this", not downloads.

What is published where

.github/workflows/main-docker.yml builds on GHCR and copies to Docker Hub in its merge job:

  • sha-<commit> — GHCR only. Until 2026-10 they were copied to Docker Hub too, which left 1,672 sha-* tags and ~10K untagged images there (974 GB in triliumnext/trilium, 658 GB in triliumnext/notes). The copy loop skips them now; do not undo that.
  • main, v<version>, stable, latest — both registries. stable/latest only for a version tag without a hyphen.
  • <branch-name> — both, from a manual run of the workflow on a branch (/ becomes -, e.g. feature-deployment_fixes). Delete it on Docker Hub once the branch is merged.

.github/workflows/mirror-legacy-docker.yml copies ghcr.io/triliumnext/trilium:stable to triliumnext/notes:stable+latest and zadam/trilium:latest after each stable release (the mirror_legacy job). The old version tags and zadam/trilium:0.63-latest are left alone, so pinned installs keep their version. A manual run with an empty tags input writes the release tags. The container contract (port 8080, /home/node/trilium-data, USER_UID/USER_GID) has not changed since 0.63, and a migration writes a before-migration backup; desktop clients of the old version stop syncing until replaced (SYNC_VERSION 32/36 → 39). The zadam account's token is a personal access token, which Docker Hub cannot restrict to one repository — it must carry an expiry date.

How Docker Hub stores images

These four facts decide every cleanup — verified against the live repositories in 2026-10:

  1. Deleting a tag frees nothing. The image stays, pullable by digest, and keeps counting toward storage_size. Tag cleanup is cosmetic; storage only drops when the untagged image is deleted.
  2. Deleting an image index deletes its per-platform images. Trilium's index holds 8 manifests (4 platforms + 4 attestations); after DELETE of the index all of them answer 404. So a purge deletes indexes only — never walk the children (that would be 13K wasted requests).
  3. A digest a tag still uses cannot be deleted — the registry answers 403. That holds through an index: a sha-* build of a release commit has the same digest as v<version>, and its children are the release's children. purge also subtracts a keep list (every live tag's index and children), so the 403 is a second line, not the only one.
  4. Untagged images are listed by GET /v2/namespaces/<ns>/repositories/<name>/manifests (last_evaluated_key pagination), which is what inventory and purge read. It is not in Docker's public API reference; the older /images endpoints return 404. It reports the per-platform images of a tagged index as untagged single manifests — they are not orphans.

storage_size tracks deletions within minutes. Its "before" values were real: the triliumnext/trilium purge took it from 974 GB to 18 GB, triliumnext/notes from 658 GB to 19 GB.

Show full SKILL.md (497 more words)Show less

Recipes

Clean a repository (after a burst of unwanted tags, or periodically):

  1. node $H tags <repo> --prefix <p> → report the count → with consent, --delete. The listing returns at most 1,000 tags and its count lags several minutes; re-run until it reports 0.
  2. node $H purge <repo> [--older-than N] → report the dry run → with consent, --delete. purge refuses to run while the repository has 1,000+ tags, because the keep list would be incomplete — finish step 1 first.
  3. Verify: docker manifest inspect <repo>:<tag> for latest, stable, main and a couple of versions, and node $H stats <repo> for the storage figure.

About 60–250 deletes a minute at the default --concurrency 4; the rate varies by time of day.

Open issue — main keeps leaving untagged images. Each push to main moves the main tag and leaves the previous index untagged on Docker Hub: ~12 a day in early 2026-10, ~640 MB each. Either keep main on GHCR only (as with sha-*; then document ghcr.io/triliumnext/trilium:main for anyone tracking it) or run purge --older-than 7 periodically. Until one lands, expect the inventory to show recent untagged indexes.

Traps

  • Docker Hub's Image Management page shows the per-platform images of tagged indexes as untagged and has no "untagged" filter. Never tell the user to bulk-delete untagged Image rows there — it breaks docker pull of releases. Indexes only, or use purge.
  • Two tokens, two lifetimes. The Hub API (hub.docker.com) wants a JWT from POST /v2/auth/token; the registry (registry-1.docker.io) wants one from auth.docker.io with scope repository:<repo>:pull,push,delete. Both expire after minutes; hub.mjs renews on 401. A long run that does not renew dies at ~650 requests with a wall of 401s.
  • Rate limits. The Hub API answers 429 after a few thousand requests; the script backs off. Don't probe tags one by one anonymously — it hits the limit within a minute.
  • Stopping a background run: pkill -f "hub.mjs purge" also matches the shell that issued it if the pattern appears in that command line. Use the PID, or ps -eo pid,args | grep "[n]ode .*hub.mjs".
  • GHCR and Docker Hub digests match only for images CI copied with crane copy (all of triliumnext/trilium, and triliumnext/notes from v0.95.0). Older triliumnext/notes images were built per registry. The inventory makes GHCR unnecessary as a digest source anyway.

Visibility

  • Categories (stats prints them): the knowledge-base peers use Content management system (Wiki.js, BookStack, MediaWiki, XWiki, Outline, Docmost); triliumnext/trilium adds Machine learning & AI. Most note apps set none.
  • Stars need a signed-in visit to the repository page, and docker pull never shows the page — links from the README badge, the User Guide's Docker page and the legacy repositories' overviews are what bring visitors. Never ask for stars in the app or in issue replies.
  • The legacy repositories' overview and short description must say they mirror triliumnext/trilium and that users should switch image names.
  • docs/Developer Guide/Developer Guide/Building/Docker Hub maintenance.md — the human-facing version of this page; keep the two in step.
  • cutting-a-release — a release is what moves stable/latest and triggers the legacy mirror.

© TriliumNext, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/maintaining-docker-hub of TriliumNext/Trilium.

  • SKILL.md
  • hub.mjs

Open the folder on GitHubat commit 80be026

Compare with similar skills

Maintaining Docker Hub next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Maintaining Docker Hub compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Maintaining Docker Hub this skillTriliumNext/Trilium38k—~2.3kAutomated safety check: WarnAGPL-3.0
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell16k—~4.9kAutomated safety check: PassApache-2.0
Ssh Skillbadseal/ssh-skill538—~2.4kAutomated safety check: NotesNone

Similar skills

  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    16k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Ssh Skill

    badseal/ssh-skill

    A skill your agent uses when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download…

    538 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Wp Env

    WordPress/agent-skills

    A skill your agent uses when setting up, configuring, or troubleshooting local WordPress development environments with @wordpress/env (wp-env).

    2.2k GitHub stars~2.2k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed

More from TriliumNext/Trilium

All 23 skills in this repo
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Developing Electron Desktop

    TriliumNext/Trilium

    A skill your agent uses when working on the Trilium Electron desktop app (apps/desktop) — adding or changing an electronApi method / IPC channel, touching preload.ts, main.ts, services/window.ts or…

    38k GitHub stars~5.7k tokensUpdated today
    Auto-check passed
  • Evolving The Data Model

    TriliumNext/Trilium

    A skill your agent uses when adding a DB migration or a new column/field to a Becca entity in Trilium ("add a migration", "new column on notes/attributes", "ALTER TABLE", "add a field to…

    38k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Adding Internal API Route

    TriliumNext/Trilium

    A skill your agent uses when adding, moving, or wiring an internal REST endpoint in Trilium (a new /api/ route) — choosing between a core-shared handler (packages/trilium-core/src/routes/index.ts…

    38k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Adding LLM MCP Tools

    TriliumNext/Trilium

    A skill your agent uses when adding, changing, or reviewing an LLM/MCP tool in Trilium (the defineTools definitions under packages/trilium-core/src/services/llm/tools/ —…

    38k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Ckeditor5 Plugin Development

    TriliumNext/Trilium

    Write, extend, and review CKEditor 5 plugins in the Trilium (TriliumNext Notes) monorepo — the rich-text-note editor under packages/ckeditor5, whose plugins live in src/plugins/.

    38k GitHub stars~4.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Maintaining Docker Hub

What does Maintaining Docker Hub do?

A skill your agent uses when working on Trilium's published Docker images on Docker Hub or GHCR rather than on the Dockerfiles — "how many pulls does the image get?", "why is the Docker Hub…. Maintaining Docker Hub is an agent skill from TriliumNext/Trilium.yml, Docker Hub categories, stars or the overview.

When should I use Maintaining Docker Hub?

Maintaining Docker Hub fits situations like: working on Triliums published Docker images on Docker Hub; GHCR rather than on the Dockerfiles — how many pulls does the image get?; why is the Docker Hub repository so big?; clean up old tags.

How do I install Maintaining Docker Hub in Claude Code?

Run `npx skills add TriliumNext/Trilium --skill maintaining-docker-hub -a claude-code`. Or copy the skill folder (.claude/skills/maintaining-docker-hub in TriliumNext/Trilium) into .claude/skills/maintaining-docker-hub in your project. Claude Code loads it when a task matches its description.

How do I install Maintaining Docker Hub in Codex?

Run `npx skills add TriliumNext/Trilium --skill maintaining-docker-hub -a codex`. Or copy the skill folder (.claude/skills/maintaining-docker-hub in TriliumNext/Trilium) into .agents/skills/maintaining-docker-hub in your project. Codex loads it when a task matches its description.

Can I use Maintaining Docker Hub in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TriliumNext/Trilium --skill maintaining-docker-hub -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/maintaining-docker-hub, .gemini/skills/maintaining-docker-hub, .github/skills/maintaining-docker-hub and .opencode/skills/maintaining-docker-hub in your project.

What does Maintaining Docker Hub need to run?

Going by SKILL.md and its folder, Maintaining Docker Hub needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and docker) and credentials named DOCKERHUB_TOKEN, GITHUB_TOKEN and ZADAM_DOCKERHUB_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in DOCKERHUB_TOKEN; A credential in GITHUB_TOKEN.

Does Maintaining Docker Hub access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Maintaining Docker Hub safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Maintaining Docker Hub use?

Maintaining Docker Hub is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Maintaining Docker Hub use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Maintaining Docker Hub?

Skills that share tags, products or a category with Maintaining Docker Hub: GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars) and Build Openshell Mxc Windows (NVIDIA/OpenShell, 16k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Maintaining Docker Hub?

TriliumNext (a GitHub organization) maintains it in TriliumNext/Trilium, which has 38,265 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 10, 2026.

Source: TriliumNext/Trilium on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.