Container security from build to runtime. Image scanning, minimal base images, rootless execution, secrets management, supply chain verification, and runtime policies with concrete Dockerfile examples.
Run Trivy before every push. Fail CI on HIGH or CRITICAL vulnerabilities.
trivy image myapp:latest --severity HIGH,CRITICAL --exit-code 1
Use Grype as a second scanner. Different scanners catch different CVEs.
grype myapp:latest --fail-on high
Store scan results as build artifacts for trending.
trivy image myapp:latest --format json --output scan-results.json
Use distroless or scratch for runtime. Multi-stage builds separate build tools from runtime. See references/dockerfile-hardening.md for complete BAD/GOOD Dockerfile patterns for Go, Node.js, and static binaries.
Always create a non-root user and switch to it. For distroless, use the built-in nonroot user (UID 65532). See references/dockerfile-hardening.md for rootless patterns.
BAD: Baking secrets into the image. They persist in layers even if deleted.
FROM node:24-alpine
ENV DATABASE_PASSWORD=supersecret
COPY . /app
CMD ["node", "server.js"]
GOOD: Inject secrets at runtime via environment variables or mounted files.
docker run -e DATABASE_PASSWORD="$(cat /secure/db-password)" myapp:latest
For Kubernetes, use Secrets mounted as volumes or environment variables.
env:
- name: DATABASE_PASSWORD
valueFrom:
secretKeyRef:
name: db-credentials
key: password
Use BuildKit secrets for credentials needed during build (e.g., private registry tokens).
BAD: Copying .env file into the image.
COPY .env /build/.env
RUN npm install --registry=https://private.npm.com
GOOD: Mount secrets during build without persisting them.
# syntax=docker/dockerfile:1
RUN --mount=type=secret,id=npmrc,target=/root/.npmrc \
npm install --registry=https://private.npm.com
Build with:
docker buildx build --secret id=npmrc,src=.npmrc .
Ensure secrets never enter the build context.
.env
.env.*
*.key
*.pem
secrets/
credentials.json
Scan committed Dockerfiles for hardcoded tokens.
gitleaks detect --source . --no-git
Sign after building. Verify before deploying.
cosign sign myregistry.com/myapp:v1.0.0
Verify signature before pull.
cosign verify --key cosign.pub myregistry.com/myapp:v1.0.0
Create a Software Bill of Materials for every release.
syft myapp:latest -o json > sbom.json
trivy image --format cyclonedx --output sbom.json myapp:latest
Attach SBOM to the image as an OCI artifact.
cosign attach sbom --sbom sbom.json myregistry.com/myapp:v1.0.0
BAD: Using mutable tags. Tags can be overwritten.
FROM node:24-alpine
GOOD: Pin by digest. Digest is immutable.
FROM node:24-alpine@sha256:abc123...
Find digests with:
docker pull node:24-alpine
docker inspect node:24-alpine | jq -r '.[0].RepoDigests[0]'
Admission control (Gatekeeper, Kyverno), seccomp profiles, and Falco runtime monitoring. See references/runtime-security.md for policy YAML examples and Falco rules.
hadolint Dockerfile
gitleaks detect --source . --no-git
docker build -t myapp:latest .
trivy image myapp:latest --exit-code 1 --severity HIGH,CRITICAL
cosign sign myregistry.com/myapp:v1.0.0
syft myapp:latest -o json > sbom.json
docker tag myapp:latest myregistry.com/myapp:v1.0.0
docker push myregistry.com/myapp:v1.0.0
cosign verify --key cosign.pub myregistry.com/myapp:v1.0.0
Complete BAD/GOOD Dockerfile comparisons and common mistakes. See references/dockerfile-hardening.md for full examples.
npx skills add medy-gribkov/container-security下载完整 Skill 目录,包含 SKILL.md 及所有相关文件
Search for places (restaurants, cafes, etc.) via Google Places API proxy on localhost.
Interact with GitHub using the `gh` CLI. Use `gh issue`, `gh pr`, `gh run`, and `gh api` for issues, PRs, CI runs, and advanced queries.
Create or update AgentSkills. Use when designing, structuring, or packaging skills with scripts, references, and assets.
Start voice calls via the OpenClaw voice-call plugin.
Notion API for creating and managing pages, databases, and blocks.
Gemini CLI for one-shot Q&A, summaries, and generation.
Category:developer