☁️ DevOps & Cloud · Containers
Write production-grade Dockerfiles
Multi-stage builds, slim bases, layer-order discipline, and non-root runtime for small secure images.
intermediate~30 minDevOps EngineersSREsCloud Architects
Steps
- 1Start from slim/distroless variants pinned by digest, not :latest
- 2Order layers least-to-most volatile; lock dependency manifests first
- 3Multi-stage: build artifacts in builder, copy ONLY runtime needs
- 4Run as non-root USER; expose no debug ports by default
- 5Add HEALTHCHECK matching your orchestration's probe
- 6Scan images in CI; fail on critical CVEs with a waiver process
Common Pitfalls
- ▲Copying node_modules across stages including dev deps
- ▲apt-get upgrade layers busting cache every build
Success Signals
- ✓Image size under 200MB typical service
- ✓Zero critical CVEs shipped
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill containers-dockerfile-productionInstall globally
$ npx skills add aniruddhaadak80/skills --skill containers-dockerfile-production -gTags
#docker#containers#devops-cloud