Agent skill

Docker Patterns

by xu-xiang in xu-xiang/everything-claude-code-zh

用于本地开发、容器安全、网络、卷策略和多服务编排的 Docker 与 Docker Compose 模式. An agent skill from xu-xiang/everything-claude-code-zh.

MITAuto-check: notesDevOps & Cloud

Install Docker Patterns

skills CLI
$ npx skills add xu-xiang/everything-claude-code-zh --skill docker-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xu-xiang/everything-claude-code-zh docker-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/docker-patterns .claude/skills/docker-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker-patterns
GitHub stars
2k
Token cost
~1.7k tokens
SKILL.md length
55 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

用于本地开发、容器安全、网络、卷策略和多服务编排的 Docker 与 Docker Compose 模式. An agent skill from xu-xiang/everything-claude-code-zh.

  • Tasks that involve Containers
  • SKILL.md covers 激活时机, 用于本地开发的 Docker Compose, 网络(Networking) and 卷策略(Volume Strategies), plus 4 more sections
  • Calls docker; needs API_KEY and POSTGRES_PASSWORD

What it does

Docker Patterns is an agent skill from xu-xiang/everything-claude-code-zh. 用于本地开发、容器安全、网络、卷策略和多服务编排的 Docker 与 Docker Compose 模式。

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers. It works with Docker. The repository describes itself as: everything-claude-code 中文翻译项目:完整的 Claude Code 配置集合(agents, skills, hooks, commands, rules, MCPs)。源自 Anthropic 黑客松获胜者的实战配置,助力中文工程师高效理解与使用 Claude Code。 The licence is MIT.

When your agent uses it

  • Tasks that involve Containers

Example prompts

  • “/docker-patterns”

Requirements

  • Node.js
  • Docker
  • A credential in API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit dfbf946. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Docker Patterns loads about 1.7k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 55 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:266
    - .env                     # 严禁将 .env 提交到 git
  • NoteMentions a .env fileSKILL.md:289
    .env
  • NoteMentions a .env fileSKILL.md:290
    .env.*
  • NoteMentions a .env fileSKILL.md:363
    # 使用 .env 文件(加入 gitignore)或 Docker secrets

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xu-xiang/everything-claude-code-zh at commit dfbf946, republished under its MIT licence (© xu-xiang). 55 words, ~1,712 tokens.

Download SKILL.mdSave it as .claude/skills/docker-patterns/SKILL.md (or your agent's skills folder).
name
docker-patterns
description
用于本地开发、容器安全、网络、卷策略和多服务编排的 Docker 与 Docker Compose 模式。
origin
ECC

Docker 模式 (Docker Patterns)

容器化开发的 Docker 和 Docker Compose 最佳实践。

激活时机

  • 为本地开发设置 Docker Compose
  • 设计多容器架构
  • 排查容器网络或卷(Volume)问题
  • 审查 Dockerfile 的安全性与镜像大小
  • 从本地开发迁移到容器化工作流(Workflow)

用于本地开发的 Docker Compose

标准 Web 应用技术栈
yaml
# docker-compose.yml
services:
  app:
    build:
      context: .
      target: dev                     # 使用多阶段构建 Dockerfile 的 dev 阶段
    ports:
      - "3000:3000"
    volumes:
      - .:/app                        # 绑定挂载用于热重载
      - /app/node_modules             # 匿名卷 -- 保留容器内的依赖
    environment:
      - DATABASE_URL=postgres://postgres:postgres@db:5432/app_dev
      - REDIS_URL=redis://redis:6379/0
      - NODE_ENV=development
    depends_on:
      db:
        condition: service_healthy
      redis:
        condition: service_started
    command: npm run dev

  db:
    image: postgres:16-alpine
    ports:
      - "5432:5432"
    environment:
      POSTGRES_USER: postgres
      POSTGRES_PASSWORD: postgres
      POSTGRES_DB: app_dev
    volumes:
      - pgdata:/var/lib/postgresql/data
      - ./scripts/init-db.sql:/docker-entrypoint-initdb.d/init.sql
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U postgres"]
      interval: 5s
      timeout: 3s
      retries: 5

  redis:
    image: redis:7-alpine
    ports:
      - "6379:6379"
    volumes:
      - redisdata:/data

  mailpit:                            # 本地邮件测试
    image: axllent/mailpit
    ports:
      - "8025:8025"                   # Web UI 界面
      - "1025:1025"                   # SMTP 端口

volumes:
  pgdata:
  redisdata:
开发与生产环境的 Dockerfile
dockerfile
# 阶段:依赖安装 (dependencies)
FROM node:22-alpine AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci

# 阶段:开发环境 (dev - 支持热重载、调试工具)
FROM node:22-alpine AS dev
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .
EXPOSE 3000
CMD ["npm", "run", "dev"]

# 阶段:构建 (build)
FROM node:22-alpine AS build
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .
RUN npm run build && npm prune --production

# 阶段:生产环境 (production - 最小化镜像)
FROM node:22-alpine AS production
WORKDIR /app
RUN addgroup -g 1001 -S appgroup && adduser -S appuser -u 1001
USER appuser
COPY --from=build --chown=appuser:appgroup /app/dist ./dist
COPY --from=build --chown=appuser:appgroup /app/node_modules ./node_modules
COPY --from=build --chown=appuser:appgroup /app/package.json ./
ENV NODE_ENV=production
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=3s CMD wget -qO- http://localhost:3000/health || exit 1
CMD ["node", "dist/server.js"]
覆盖文件(Override Files)
yaml
# docker-compose.override.yml (自动加载,仅限开发环境设置)
services:
  app:
    environment:
      - DEBUG=app:*
      - LOG_LEVEL=debug
    ports:
      - "9229:9229"                   # Node.js 调试器端口

# docker-compose.prod.yml (生产环境显式指定)
services:
  app:
    build:
      target: production
    restart: always
    deploy:
      resources:
        limits:
          cpus: "1.0"
          memory: 512M
bash
# 开发环境 (自动加载 override)
docker compose up

# 生产环境
docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d

网络(Networking)

服务发现(Service Discovery)

在同一个 Compose 网络中的服务可以通过服务名解析:

# 在 "app" 容器中:
postgres://postgres:postgres@db:5432/app_dev    # "db" 解析为 db 容器
redis://redis:6379/0                             # "redis" 解析为 redis 容器
自定义网络(Custom Networks)
yaml
services:
  frontend:
    networks:
      - frontend-net

  api:
    networks:
      - frontend-net
      - backend-net

  db:
    networks:
      - backend-net              # 仅 api 可达,frontend 不可达

networks:
  frontend-net:
  backend-net:
仅暴露必要的端口
yaml
services:
  db:
    ports:
      - "127.0.0.1:5432:5432"   # 仅宿主机可访问,外部网络不可见
    # 在生产环境中完全省略 ports -- 仅在 Docker 网络内部可访问

卷策略(Volume Strategies)

yaml
volumes:
  # 命名卷 (Named volume): 在容器重启间持久化,由 Docker 管理
  pgdata:

  # 绑定挂载 (Bind mount): 将宿主机目录映射到容器(用于开发)
  # - ./src:/app/src

  # 匿名卷 (Anonymous volume): 防止绑定挂载覆盖容器生成的特定内容
  # - /app/node_modules
常用模式
yaml
services:
  app:
    volumes:
      - .:/app                   # 源代码 (绑定挂载用于热重载)
      - /app/node_modules        # 保护容器的 node_modules 不被宿主机覆盖
      - /app/.next               # 保护构建缓存

  db:
    volumes:
      - pgdata:/var/lib/postgresql/data          # 持久化数据
      - ./scripts/init.sql:/docker-entrypoint-initdb.d/init.sql  # 初始化脚本

容器安全(Container Security)

Dockerfile 硬化
dockerfile
# 1. 使用特定的标签 (绝不使用 :latest)
FROM node:22.12-alpine3.20

# 2. 以非 root 用户运行
RUN addgroup -g 1001 -S app && adduser -S app -u 1001
USER app

# 3. 移除能力 (Capabilites,在 compose 中配置)
# 4. 尽可能使用只读根文件系统
# 5. 不在镜像层中存储密钥
Compose 安全
yaml
services:
  app:
    security_opt:
      - no-new-privileges:true
    read_only: true
    tmpfs:
      - /tmp
      - /app/.cache
    cap_drop:
      - ALL
    cap_add:
      - NET_BIND_SERVICE          # 仅当需要绑定 < 1024 端口时
密钥管理(Secret Management)
yaml
# 推荐:使用环境变量(在运行时注入)
services:
  app:
    env_file:
      - .env                     # 严禁将 .env 提交到 git
    environment:
      - API_KEY                  # 从宿主机环境继承

# 推荐:Docker Secrets (Swarm 模式)
secrets:
  db_password:
    file: ./secrets/db_password.txt

services:
  db:
    secrets:
      - db_password

# 不良实践:硬编码在镜像中
# ENV API_KEY=sk-proj-xxxxx      # 严禁这样做

.dockerignore

node_modules
.git
.env
.env.*
dist
coverage
*.log
.next
.cache
docker-compose*.yml
Dockerfile*
README.md
tests/

调试(Debugging)

常用命令
bash
# 查看日志
docker compose logs -f app           # 持续追踪 app 日志
docker compose logs --tail=50 db     # 查看 db 最后 50 行日志

# 在运行中的容器内执行命令
docker compose exec app sh           # 进入 app 终端
docker compose exec db psql -U postgres  # 连接到 postgres

# 查看状态
docker compose ps                     # 查看运行中的服务
docker compose top                    # 查看每个容器内的进程
docker stats                          # 查看资源使用情况

# 重新构建
docker compose up --build             # 重新构建镜像并启动
docker compose build --no-cache app   # 强制完整重新构建

# 清理
docker compose down                   # 停止并移除容器
docker compose down -v                # 同时移除卷(破坏性操作)
docker system prune                   # 移除未使用的镜像/容器
调试网络问题
bash
# 在容器内检查 DNS 解析
docker compose exec app nslookup db

# 检查连通性
docker compose exec app wget -qO- http://api:3000/health

# 检查网络
docker network ls
docker network inspect <project>_default

反模式(Anti-Patterns)

# 不良实践:在没有编排工具的情况下在生产环境使用 docker compose
# 生产环境的多容器负载应使用 Kubernetes, ECS, 或 Docker Swarm

# 不良实践:在没有卷的情况下在容器中存储数据
# 容器是瞬态的 -- 重新启动且没有卷时所有数据都会丢失

# 不良实践:以 root 用户运行
# 务必创建并使用非 root 用户

# 不良实践:使用 :latest 标签
# 锁定到特定版本以确保构建可复现

# 不良实践:一个巨大的容器包含所有服务
# 关注点分离:每个容器一个进程

# 不良实践:将密钥放入 docker-compose.yml
# 使用 .env 文件(加入 gitignore)或 Docker secrets

© xu-xiang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/docker-patterns of xu-xiang/everything-claude-code-zh.

Open the folder on GitHubat commit dfbf946

Compare with similar skills

Docker Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker Patterns this skillxu-xiang/everything-claude-code-zh2k—~1.7kAutomated safety check: NotesMIT
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell15k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Omnigent Docker Compose Deploy

    omnigent-ai/omnigent

    Brings up the Omnigent server and Postgres as a Docker compose stack on any Docker host, and covers the Dockerfile's runtime and host build targets for extending it to a new platform.

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from xu-xiang/everything-claude-code-zh

All 78 skills in this repo
  • Configure Ecc

    xu-xiang/everything-claude-code-zh

    Everything Claude Code 的交互式安装程序 — 引导用户选择并安装技能和规则到用户级或项目级目录,验证路径,并可选择优化已安装文件。

    2k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Continuous Learning V2

    xu-xiang/everything-claude-code-zh

    基于本能(Instinct)的学习系统,通过钩子(hooks)观察会话,创建带有置信度评分的原子本能,并将其演化为技能(Skills)、命令(Commands)或智能体(Agents)。v2.1 版本增加了项目作用域(project-scoped)的本能,以防止跨项目污染。

    2k GitHub stars~2.1k tokensUpdated 7 mo ago
    Auto-check passed
  • API Design

    xu-xiang/everything-claude-code-zh

    生产级 API 的 REST API 设计模式,包括资源命名、状态码、分页、过滤、错误响应、版本控制和速率限制. An agent skill from xu-xiang/everything-claude-code-zh.

    2k GitHub stars~2.7k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及适用于 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及针对 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed

Works with

Categories

Questions about Docker Patterns

What does Docker Patterns do?

用于本地开发、容器安全、网络、卷策略和多服务编排的 Docker 与 Docker Compose 模式. An agent skill from xu-xiang/everything-claude-code-zh. Docker Patterns is an agent skill from xu-xiang/everything-claude-code-zh.

When should I use Docker Patterns?

Docker Patterns fits situations like: tasks that involve Containers.

How do I install Docker Patterns in Claude Code?

Run `npx skills add xu-xiang/everything-claude-code-zh --skill docker-patterns -a claude-code`. Or copy the skill folder (skills/docker-patterns in xu-xiang/everything-claude-code-zh) into .claude/skills/docker-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Docker Patterns in Codex?

Run `npx skills add xu-xiang/everything-claude-code-zh --skill docker-patterns -a codex`. Or copy the skill folder (skills/docker-patterns in xu-xiang/everything-claude-code-zh) into .agents/skills/docker-patterns in your project. Codex loads it when a task matches its description.

Can I use Docker Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xu-xiang/everything-claude-code-zh --skill docker-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker-patterns, .gemini/skills/docker-patterns, .github/skills/docker-patterns and .opencode/skills/docker-patterns in your project.

What does Docker Patterns need to run?

Going by SKILL.md and its folder, Docker Patterns needs the command-line tools its instructions call (docker) and credentials named API_KEY and POSTGRES_PASSWORD. Our summary lists: Node.js; Docker; A credential in API_KEY.

Does Docker Patterns access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker Patterns safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Docker Patterns use?

Docker Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker Patterns use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Docker Patterns?

Skills that share tags, products or a category with Docker Patterns: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker Patterns?

xu-xiang (a GitHub user) maintains it in xu-xiang/everything-claude-code-zh, which has 1,973 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on March 5, 2026.

Source: xu-xiang/everything-claude-code-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.