docker
Build, run, and secure Docker containers with current best practices. Use for Dockerfile review, multi-stage builds, Compose orchestration, image hardening, and CI/CD integration.
What this skill does
# Docker Container Engineering
## Current Versions (Verify Before Use)
```bash
docker --version # Engine version
docker compose version # Compose plugin version
docker buildx version # BuildKit/buildx version
```
Check the [Docker Engine release notes](https://docs.docker.com/engine/release-notes/) for the latest stable.
## Core Principles
1. **Multi-stage builds are the default.** Every production Dockerfile should use multi-stage builds to minimize attack surface and image size.
2. **Non-root containers.** Every container should run as a non-root user unless impossible.
3. **Layer caching is a first-class concern.** Order Dockerfile instructions from least-frequently-changing to most-frequently-changing.
4. **Healthchecks are mandatory.** Every long-running container must define a `HEALTHCHECK`.
5. **Scan before push.** Every image should pass a security scan before registry upload.
## Dockerfile Review Checklist
### Structure
- [ ] Uses multi-stage build (at least 2 stages: builder + runtime)
- [ ] Base image is a slim or distroless variant (`alpine`, `slim`, `distroless`)
- [ ] No `latest` tag — pinned to specific digest or version
- [ ] `WORKDIR` is set before file operations
- [ ] `COPY` uses specific files, not `COPY . .` where possible
### Security
- [ ] Runs as non-root (`USER` directive or `--user` at runtime)
- [ ] No secrets in layers (use BuildKit secrets or runtime mounts)
- [ ] `EXPOSE` documents only necessary ports
- [ ] `HEALTHCHECK` is defined
- [ ] No unnecessary packages installed (`apt-get` cleaned, no dev tools in runtime)
- [ ] Image scanned with `docker scout` or Trivy
### Efficiency
- [ ] `.dockerignore` exists and excludes: `.git`, `node_modules`, `*.log`, `.env`
- [ ] Layer order respects cache invalidation (dependencies before code)
- [ ] `RUN` commands combined where logical (but not excessively long)
- [ ] BuildKit enabled (`DOCKER_BUILDKIT=1` or default in modern Docker)
## Multi-Stage Build Template
```dockerfile
# syntax=docker/dockerfile:1
FROM node:22-alpine AS builder
WORKDIR /app
COPY package*.json .
RUN npm ci --only=production
FROM node:22-alpine AS runtime
RUN addgroup -g 1001 -S nodejs && adduser -S nodejs -u 1001
WORKDIR /app
COPY --from=builder --chown=nodejs:nodejs /app/node_modules ./node_modules
COPY --chown=nodejs:nodejs . .
USER nodejs
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD node -e "require('http').get('http://localhost:3000/health', (r) => r.statusCode === 200 ? process.exit(0) : process.exit(1))"
CMD ["node", "server.js"]
```
## Docker Compose Patterns
### Development vs Production Separation
```yaml
# docker-compose.yml — production baseline
services:
app:
build: .
restart: unless-stopped
deploy:
resources:
limits:
cpus: '1.0'
memory: 512M
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3000/health"]
interval: 30s
timeout: 3s
retries: 3
```
```yaml
# docker-compose.override.yml — development only
services:
app:
volumes:
- .:/app
environment:
- NODE_ENV=development
command: npm run dev
```
### Validation
```bash
docker compose config # validate and merge
docker compose config --profiles # check profile separation
```
## Security Scanning
```bash
# Docker Scout (built-in, requires login)
docker scout quickview myimage:latest
docker scout cves myimage:latest
# Trivy (open source)
trivy image myimage:latest
trivy filesystem .
# Snyk
snyk container test myimage:latest
```
## Common Anti-Patterns
| Anti-Pattern | Why It's Wrong | Fix |
|---|---|---|
| `FROM node:latest` | Non-reproducible builds, surprise updates | Pin to `node:22-alpine` or digest |
| Running as root | Container escape = host compromise | `USER` directive + file ownership |
| `COPY . .` without `.dockerignore` | Bloats image, leaks secrets | Explicit `.dockerignore` |
| `apt-get update && apt-get install` without cleanup | Bloated layers | `&& rm -rf /var/lib/apt/lists/*` |
| No healthcheck | Orchestrator can't detect failure | `HEALTHCHECK` in Dockerfile or compose |
| Secrets in ENV | Visible in `docker inspect` | BuildKit secrets or runtime mounts |
| Single-stage build | Large attack surface, slow deploys | Multi-stage: build → runtime |
## CI/CD Integration
```yaml
# .github/workflows/docker.yml
- name: Build and scan
run: |
docker build -t app:${{ github.sha }} .
docker scout cves app:${{ github.sha }} --exit-code --only-severity critical,high
docker run --rm app:${{ github.sha }} npm test
```
## Troubleshooting Flow
1. **Build fails:** Check layer cache — `docker build --no-cache` to isolate
2. **Image too large:** Run `dive myimage:latest` to analyze layer bloat
3. **Container exits immediately:** Check `CMD`/`ENTRYPOINT` and logs (`docker logs`)
4. **Permission denied:** Verify `USER` directive and file ownership in `COPY --chown`
5. **Healthcheck failing:** Test command inside container with `docker exec`
## Official Resources
- [Dockerfile reference](https://docs.docker.com/engine/reference/builder/)
- [Compose specification](https://docs.docker.com/compose/compose-file/)
- [Docker security best practices](https://docs.docker.com/develop/dev-best-practices/)
- [BuildKit documentation](https://docs.docker.com/build/buildkit/)
- [Docker Scout](https://docs.docker.com/scout/)
Related in Image & Video
watch
IncludedWatch a video (URL or local path). Downloads with yt-dlp, extracts auto-scaled frames with ffmpeg, pulls the transcript from captions (or Whisper API fallback), and hands the result to Claude so it can answer questions about what's in the video.
physical-ai-defect-image-generation
IncludedUse when the user wants to orchestrate defect image generation, run associated setup, or handle outputs on OSMO. The Day 0 path handles cold-start with USD-to-ROI, image-edit augmentation, and AnomalyGen to create initial PCBA datasets. The Day 1 path performs inference and labeling on real images. This skill helps with first-time asset setup, creation of finetuning checkpoints, and configuring deployment. Trigger keywords: defect image generation, dig workflow, dig pipeline, defect image detection workflow, aoi pipeline, aoi anomalygen, usd2roi anomalygen, day 0 pcba, day 1 pcba, day 1 real-photo alignment, day 1 manual roi, metal surface anomaly, glass defect, anomalygen finetune, setup_pcb, setup_metal, setup_glass, setup_pretrained, dig setup, dig datasets, dig pretrained checkpoint, dig image-edit endpoint.
accelint-react-best-practices
IncludedReact performance optimization and best practices. ALWAYS use this skill when working with any React code - writing components, hooks, JSX; refactoring; optimizing re-renders, memoization, state management; reviewing for performance; fixing hydration mismatches; debugging infinite re-renders, stale closures, input focus loss, animations restarting; preventing remounting; implementing transitions, lazy initialization, effect dependencies. Even simple React tasks benefit from these patterns. Covers React 19+ (useEffectEvent, Activity, ref props). Triggers - useEffect, useState, useMemo, useCallback, memo, inline components, nested components, components inside components, re-render, performance, hydration, SSR, Next.js, useDeferredValue, combined hooks.
elevenlabs-agents
IncludedBuild conversational AI voice agents with ElevenLabs Platform using React, JavaScript, React Native, or Swift SDKs. Configure agents, tools (client/server/MCP), RAG knowledge bases, multi-voice, and Scribe real-time STT. Use when: building voice chat interfaces, implementing AI phone agents with Twilio, configuring agent workflows or tools, adding RAG knowledge bases, testing with CLI "agents as code", or troubleshooting deprecated @11labs packages, Android audio cutoff, CSP violations, dynamic variables, or WebRTC config. Keywords: ElevenLabs Agents, ElevenLabs voice agents, AI voice agents, conversational AI, @elevenlabs/react, @elevenlabs/client, @elevenlabs/react-native, @elevenlabs/elevenlabs-js, @elevenlabs/agents-cli, elevenlabs SDK, voice AI, TTS, text-to-speech, ASR, speech recognition, turn-taking model, WebRTC voice, WebSocket voice, ElevenLabs conversation, agent system prompt, agent tools, agent knowledge base, RAG voice agents, multi-voice agents, pronunciation dictionary, voice speed control, elevenlabs scribe, @11labs deprecated, Android audio cutoff, CSP violation elevenlabs, dynamic variables elevenlabs, case-sensitive tool names, webhook authentication
humanizer
IncludedHumanize AI-generated text by detecting and removing patterns typical of LLM output. Rewrites text to sound natural, specific, and human. Uses 28 pattern detectors, 560+ AI vocabulary terms across 3 tiers, and statistical analysis (burstiness, type-token ratio, readability) for comprehensive detection. Use when asked to humanize text, de-AI writing, make content sound more natural/human, review writing for AI patterns, score text for AI detection, or improve AI-generated drafts. Covers content, language, style, communication, and filler categories.
generating-mermaid-diagrams
IncludedSalesforce architecture diagrams using Mermaid with ASCII fallback. Use this skill when generating text-based diagrams for Salesforce architecture, OAuth flows, ERDs, integration sequences, or Agentforce structure. TRIGGER when: user says "diagram", "visualize", "ERD", or asks for sequence diagrams, flowcharts, class diagrams, or architecture visualizations in Mermaid. DO NOT TRIGGER when: user wants PNG/SVG image output (use generating-visual-diagrams), or asks about non-Salesforce systems.