PromptShop

Docker Development

Use Docker containers for containerized application development.

Install

npx promptshop add docker-development

Details

What This Skill Does

The Docker Development skill provides an opinionated Docker workflow that turns bloated Dockerfiles into production-grade containers. It covers optimization, multi-stage builds, compose orchestration, and security hardening. This skill is useful for developers and devops engineers.

When to Use

Optimize a Dockerfile for size and speedImprove docker-compose.yml with best practicesAudit a Dockerfile or running container for security issuesReduce Docker image sizeSet up multi-stage buildsApply Docker best practices for a specific language

Key Features

Analyzes Dockerfile for optimization opportunitiesRecommends specific tags instead of :latestSuggests slim/alpine base image variantsCombines related RUN commandsOrders layers for optimal cachingGenerates or improves docker-compose.yml

Manual Installation

Smaller images. Faster builds. Secure containers. No guesswork.

Opinionated Docker workflow that turns bloated Dockerfiles into production-grade containers. Covers optimization, multi-stage builds, compose orchestration, and security hardening.

Not a Docker tutorial — a set of concrete decisions about how to build containers that don't waste time, space, or attack surface.

Slash Commands

CommandWhat it does
/docker:optimizeAnalyze and optimize a Dockerfile for size, speed, and layer caching
/docker:composeGenerate or improve docker-compose.yml with best practices
/docker:securityAudit a Dockerfile or running container for security issues

When This Skill Activates

Recognize these patterns from the user:

"Optimize this Dockerfile" "My Docker build is slow" "Create a docker-compose for this project" "Is this Dockerfile secure?" "Reduce my Docker image size" "Set up multi-stage builds" "Docker best practices for [language/framework]" Any request involving: Dockerfile, docker-compose, container, image size, build cache, Docker security

If the user has a Dockerfile or wants to containerize something → this skill applies.

Workflow

/docker:optimize — Dockerfile Optimization

Analyze current state

  • Read the Dockerfile
  • Identify base image and its size
  • Count layers (each RUN/COPY/ADD = 1 layer)
  • Check for common anti-patterns

Apply optimization checklist

BASE IMAGE ├── Use specific tags, never :latest in production ├── Prefer slim/alpine variants (debian-slim > ubuntu > debian) ├── Pin digest for reproducibility in CI: image@sha256:... └── Match base to runtime needs (don't use python:3.12 for a compiled binary)

LAYER OPTIMIZATION ├── Combine related RUN commands with &&
├── Order layers: least-changing first (deps before source code) ├── Clean package manager cache in the same RUN layer ├── Use .dockerignore to exclude unnecessary files └── Separate build deps from runtime deps

BUILD CACHE ├── COPY dependency files before source code (package.json, requirements.txt, go.mod) ├── Install deps in a separate layer from code copy ├── Use BuildKit cache mounts: --mount=type=cache,target=/root/.cache └── Avoid COPY . . before dependency installation

MULTI-STAGE BUILDS ├── Stage 1: build (full SDK, build tools, dev deps) ├── Stage 2: runtime (minimal base, only production artifacts) ├── COPY --from=builder only what's needed └── Final image should have NO build tools, NO source code, NO dev deps

Generate optimized Dockerfile

  • Apply all relevant optimizations
  • Add inline comments explaining each decision
  • Report estimated size reduction

Validate python3 scripts/dockerfile_analyzer.py Dockerfile

/docker:compose — Docker Compose Configuration

Identify services

  • Application (web, API, worker)
  • Database (postgres, mysql, redis, mongo)
  • Cache (redis, memcached)
  • Queue (rabbitmq, kafka)
  • Reverse proxy (nginx, traefik, caddy)

Apply compose best practices

SERVICES ├── Use depends_on with condition: service_healthy ├── Add healthchecks for every service ├── Set resource limits (mem_limit, cpus) ├── Use named volumes for persistent data └── Pin image versions

NETWORKING ├── Create explicit networks (don't rely on default) ├── Separate frontend and backend networks ├── Only expose ports that need external access └── Use internal: true for backend-only networks

ENVIRONMENT ├── Use env_file for secrets, not inline environment ├── Never commit .env files (add to .gitignore) ├── Use variable substitution: ${VAR:-default} └── Document all required env vars

DEVELOPMENT vs PRODUCTION ├── Use compose profiles or override files ├── Dev: bind mounts for hot reload, debug ports exposed ├── Prod: named volumes, no debug ports, restart: unless-stopped └── docker-compose.override.yml for dev-only config

Generate compose file

  • Output docker-compose.yml with healthchecks, networks, volumes
  • Generate .env.example with all required variables documented
  • Add dev/prod profile annotations

/docker:security — Container Security Audit

Dockerfile audit

CheckSeverityFix
Running as rootCriticalAdd USER nonroot after creating user
Using :latest tagHighPin to specific version
Secrets in ENV/ARGCriticalUse BuildKit secrets: --mount=type=secret
COPY with broad globMediumUse specific paths, add .dockerignore
Unnecessary EXPOSELowOnly expose ports the app uses
No HEALTHCHECKMediumAdd HEALTHCHECK with appropriate interval
Privileged instructionsHighAvoid --privileged, drop capabilities
Package manager cache retainedLowClean in same RUN layer

Runtime security checks

CheckSeverityFix
Container running as rootCriticalSet user in Dockerfile or compose
Writable root filesystemMediumUse read_only: true in compose
All capabilities retainedHighDrop all, add only needed: cap_drop: [ALL]
No resource limitsMediumSet mem_limit and cpus
Host network modeHighUse bridge or custom network
Sensitive mountsCriticalNever mount /etc, /var/run/docker.sock in prod
No log driver configuredLowSet logging: with size limits

Generate security report SECURITY AUDIT — [Dockerfile/Image name] Date: [timestamp]

CRITICAL: [count] HIGH: [count] MEDIUM: [count] LOW: [count]

[Detailed findings with fix recommendations]

Tooling

scripts/dockerfile_analyzer.py

CLI utility for static analysis of Dockerfiles.

Features: Layer count and optimization suggestions Base image analysis with size estimates Anti-pattern detection (15+ rules) Security issue flagging Multi-stage build detection and validation JSON and text output

Usage:

Analyze a Dockerfile

python3 scripts/dockerfile_analyzer.py Dockerfile

JSON output python3 scripts/dockerfile_analyzer.py Dockerfile --output json

Analyze with security focus python3 scripts/dockerfile_analyzer.py Dockerfile --security

Check a specific directory python3 scripts/dockerfile_analyzer.py path/to/Dockerfile

scripts/compose_validator.py

CLI utility for validating docker-compose files.

Features: Service dependency validation Healthcheck presence detection Network configuration analysis Volume mount validation Environment variable audit Port conflict detection Best practice scoring

Usage:

Validate a compose file

python3 scripts/compose_validator.py docker-compose.yml

JSON output python3 scripts/compose_validator.py docker-compose.yml --output json

Strict mode (fail on warnings) python3 scripts/compose_validator.py docker-compose.yml --strict

Multi-Stage Build Patterns

Pattern 1: Compiled Language (Go, Rust, C++)

Build stage

FROM golang:1.2