PluginBench
Rule

docker

via PatrickJS/awesome-cursorrules

Production-ready Docker with pinned versions, multi-stage builds, non-root users, and security scanning.

What is docker?

Enforces Docker best practices for secure, minimal, and reproducible container images. Use this rule when building Dockerfiles and docker-compose configurations to ensure production-grade security, layer optimization, and operational reliability.

  • Pin base image versions and avoid :latest tags in production
  • Use multi-stage builds to reduce image size and attack surface
  • Run containers as non-root users with proper file ownership
  • Implement health checks and structured logging to stdout/stderr
  • Scan images with docker scout or trivy to detect vulnerabilities
  • Configure custom bridge networks and named volumes for secure networking

Applies to

File patterns this rule matches.

Dockerfile
Dockerfile.*
docker-compose*.yml
docker-compose*.yaml
.dockerignore
Rule definition (reference)

Source of truth, from the repository.

Docker Rules

Expert Docker practitioner. Minimal, secure, reproducible images.

Dockerfile

  • Pin versions: FROM node:20.11-alpine3.19 (never :latest)
  • Multi-stage builds for compiled languages
  • Layer cache: copy package files → install → copy source
  • Combine RUN commands with && to minimize layers
  • USER non-root before CMD
  • HEALTHCHECK on all services
  • COPY --chown=appuser:appuser for file ownership

Security

  • Never run as root
  • No secrets in Dockerfile or image layers
  • No .env files copied into image
  • Scan with docker scout or trivy in CI

.dockerignore

  • Always present: node_modules, .git, .log, .env, test files

Volumes

  • Named volumes for persistence
  • Bind mounts for dev only, never production

Networking

  • Custom bridge networks, not host networking
  • Reference services by name in compose

Logging

  • Always stdout/stderr — never log to files inside container

Forbidden

  • No :latest tags in production
  • No ADD when COPY works
  • No root user in production
  • No secrets in build args or image layers

Related rules

Expert guidance for DragonRuby game development with Ruby best practices.

**/*
41k
via PatrickJS/awesome-cursorrules

Expert guidance for Drupal 11 development with PHP 8.x and Symfony 6 best practices.

**/*
41k
via PatrickJS/awesome-cursorrules

Expert Elixir development guidelines with Phoenix, Ecto, and modern tooling best practices.

**/*
41k
via PatrickJS/awesome-cursorrules

Expert Elixir/Phoenix/Docker development guidance with conventional commits and follow-up questions.

**/*
41k
via PatrickJS/awesome-cursorrules

C/C++ rules for STM32 HAL, interrupts, DMA, and memory-constrained embedded systems.

["**/*.c" +7
41k
via PatrickJS/awesome-cursorrules

Standardized engineering ticket templates with detailed requirements, acceptance criteria, and implementation guidance.

**/*
41k
via PatrickJS/awesome-cursorrules