multi-stage-dockerfile

โดย github

สร้าง Dockerfile แบบหลายสเตจที่ปรับแต่งให้เหมาะสมและปลอดภัยสำหรับภาษาใดๆ หรือเฟรมเวิร์กใดๆ โดยจัดโครงสร้างการสร้างด้วยสเตจ builder และ runtime แยกกัน คัดลอกเฉพาะอาร์ติแฟกต์ที่จำเป็นเพื่อลดขนาดอิมเมจสุดท้ายและพื้นผิวการโจมตี เน้นการปรับแต่งการแคชเลเยอร์โดยจัดลำดับคำสั่งจากที่เปลี่ยนแปลงน้อยที่สุดไปยังบ่อยที่สุด ร่วมกับ .dockerignore และการรวมคำสั่ง แนะนำอิมเมจฐานที่เล็กที่สุด (Alpine, distroless หรือ official slim variants) พร้อมการระบุเวอร์ชันที่แน่นอนสำหรับ...

npx skills add https://github.com/github/awesome-copilot --skill multi-stage-dockerfile

Your goal is to help me create efficient multi-stage Dockerfiles that follow best practices, resulting in smaller, more secure container images.

Multi-Stage Structure

  • Use a builder stage for compilation, dependency installation, and other build-time operations
  • Use a separate runtime stage that only includes what's needed to run the application
  • Copy only the necessary artifacts from the builder stage to the runtime stage
  • Use meaningful stage names with the AS keyword (e.g., FROM node:18 AS builder)
  • Place stages in logical order: dependencies → build → test → runtime

Base Images

  • Start with official, minimal base images when possible
  • Specify exact version tags to ensure reproducible builds (e.g., python:3.11-slim not just python)
  • Consider distroless images for runtime stages where appropriate
  • Use Alpine-based images for smaller footprints when compatible with your application
  • Ensure the runtime image has the minimal necessary dependencies

Layer Optimization

  • Organize commands to maximize layer caching
  • Place commands that change frequently (like code changes) after commands that change less frequently (like dependency installation)
  • Use .dockerignore to prevent unnecessary files from being included in the build context
  • Combine related RUN commands with && to reduce layer count
  • Consider using COPY --chown to set permissions in one step

Security Practices

  • Avoid running containers as root - use USER instruction to specify a non-root user
  • Remove build tools and unnecessary packages from the final image
  • Scan the final image for vulnerabilities
  • Set restrictive file permissions
  • Use multi-stage builds to avoid including build secrets in the final image

Performance Considerations

  • Use build arguments for configuration that might change between environments
  • Leverage build cache efficiently by ordering layers from least to most frequently changing
  • Consider parallelization in build steps when possible
  • Set appropriate environment variables like NODE_ENV=production to optimize runtime behavior
  • Use appropriate healthchecks for the application type with the HEALTHCHECK instruction

Skills เพิ่มเติมจาก github

debugging-workflows
github
คู่มือการดีบัก GitHub Agentic Workflows - การวิเคราะห์ล็อก การตรวจสอบการรัน และการแก้ไขปัญหา
go-codemod
github
ใช้และทดสอบการปรับเปลี่ยนโค้ด Go สำหรับคำสั่ง gh aw fix
acreadiness-policy
github
ช่วยผู้ใช้เลือก เขียน หรือใช้ AgentRC policy นโยบายปรับแต่งการให้คะแนนความพร้อมโดยปิดการตรวจสอบที่ไม่เกี่ยวข้อง เปลี่ยนระดับผลกระทบ/ระดับ การตั้งค่า…
ai-ready
github
ทำให้ repo ใดๆ พร้อมสำหรับ AI — วิเคราะห์โค้ดเบสของคุณและสร้าง AGENTS.md, copilot-instructions.md, ขั้นตอนการทำงาน CI, เทมเพลต issue และอื่นๆ ขุดรีวิว PR ของคุณ…
create-oo-component-documentation
github
สร้างเอกสารประกอบที่ครอบคลุมและเป็นมาตรฐานสำหรับคอมโพเนนต์เชิงวัตถุตามแนวทางปฏิบัติที่ดีที่สุดในอุตสาหกรรมและมาตรฐานเอกสารทางสถาปัตยกรรม
dependabot
github
Dependabot เป็นเครื่องมือจัดการ dependencies ในตัวของ GitHub ที่มีความสามารถหลักสามประการ:
doublecheck
github
ไปป์ไลน์การตรวจสอบสามชั้นสำหรับผลลัพธ์ของ AI แยกข้อความที่สามารถตรวจสอบได้ ค้นหาแหล่งข้อมูลที่สนับสนุนหรือขัดแย้งผ่านการค้นหาเว็บ ดำเนินการตรวจสอบเชิงโต้แย้ง…
foundry-agent-sync
github
สร้างและซิงโครไนซ์เอเจนต์ AI ที่ใช้พรอมพ์โดยตรงภายใน Azure AI Foundry ผ่าน REST API จากไฟล์ JSON ในเครื่อง ซึ่งแตกต่างจากสกิลโครงสร้างพื้นฐานที่ทำได้เพียง...