docker
Docker containerization best practices for building, securing, and deploying containers.
Works with
--- name: docker description: Docker containerization best practices for building, securing, and deploying containers. license: Apache-2.0 --- # Docker Development You are an expert in Docker containerization, image building, and container orchestration. ## Core Principles - Build minimal, secure container images - Follow the principle of one process per container - Use official base images when possible - Implement proper layer caching strategies - Never store secrets in images ## Dockerfile Best Practices ### Multi-Stage Builds - Use multi-stage builds to reduce image size - Separate build and runtime stages - Copy only necessary artifacts to final image ### Layer Optimization - Order instructions from least to most frequently changing - Combine RUN commands to reduce layers - Use .dockerignore to exclude unnecessary files - Clean up package manager caches in same layer ### Base Images - Use specific version tags, not `latest` - Prefer slim or alpine variants for smaller size - Scan base images for vulnerabilities - Consider distroless images for production ## Security Best Practices - Run containers as non-root user - Use read-only file systems where possible - Implement health checks - Scan images for vulnerabilities regularly - Use secrets management, not environment variables for sensitive data - Implement resource limits (CPU, memory) ## Docker Compose ### Configuration - Use version 3+ compose files - Define networks explicitly - Use volumes for persistent data - Implement depends_on with health checks - Use environment files for configuration ### Development Workflow - Mount source code for hot reloading - Use override files for environment-specific config - Implement proper logging drivers - Use build args for build-time variables ## CI/CD Integration - Build images in CI pipelines - Tag images with git commit SHA - Push to secure container registries - Implement automated vulnerability scanning - Use image signing for verification ## Networking - Use user-defined bridge networks - Implement service discovery via DNS - Expose only necessary ports - Use network aliases for service communication ## Logging and Monitoring - Use appropriate logging drivers - Implement structured logging - Forward logs to centralized system - Monitor container metrics - Implement proper health checks
More DevOps & Infrastructure skills
azure-ai
microsoft/azure-skills
Use for Azure AI: Search, Speech, OpenAI, Document Intelligence. Helps with search, vector/hybrid search, speech-to-text, text-to-speech, transcription, OCR. WHEN: AI Search, query search, vector search, hybrid search, semantic search, speech-to-text, text-to-speech, transcribe, OCR, convert text to speech.
appinsights-instrumentation
microsoft/azure-skills
Guidance for instrumenting webapps with Azure Application Insights. Provides telemetry patterns, SDK setup, and configuration references. WHEN: how to instrument app, App Insights SDK, telemetry patterns, what is App Insights, Application Insights guidance, instrumentation examples, APM best practices.
azure-storage
microsoft/azure-skills
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake. Answers questions about storage access tiers (hot, cool, cold, archive), when to use each tier, and tier comparison. Provides object storage, SMB file shares, async messaging, NoSQL key-value, and big data analytics. Includes lifecycle management. USE FOR: blob storage, file shares, queue storage, table storage, data lake, upload files, download blobs, storage accounts, access tiers, storage tiers, hot cool cold archive, storage tier comparison, when to use storage tiers, lifecycle management, Azure Storage concepts. DO NOT USE FOR: SQL databases, Cosmos DB (use azure-prepare), messaging with Event Hubs or Service Bus (use azure-messaging).

