Comprehensive Dockerfile optimization guide sourced exclusively from official Docker documentation. Contains 48 rules across 8 categories, prioritized by impact to guide automated refactoring and code generation.
When to Apply
Reference these guidelines when:
Writing new Dockerfiles or modifying existing ones
Optimizing Docker build times (layer caching, cache mounts, context management)
Reducing Docker image size (multi-stage builds, minimal base images)
Read individual reference files for detailed explanations and code examples:
Section definitions - Category structure and impact levels
Rule template - Template for adding new rules
Reference Files
File
Description
references/_sections.md
Category definitions and ordering
assets/templates/_template.md
Template for new rules
metadata.json
Version and reference information
1---2name: dockerfile-optimise3description: Dockerfile Optimization Best Practices4---5# Dockerfile Optimization Best Practices67Comprehensive Dockerfile optimization guide sourced exclusively from official Docker documentation. Contains 48 rules across 8 categories, prioritized by impact to guide automated refactoring and code generation.89## When to Apply1011Reference these guidelines when:12- Writing new Dockerfiles or modifying existing ones13- Optimizing Docker build times (layer caching, cache mounts, context management)14- Reducing Docker image size (multi-stage builds, minimal base images)15- Hardening container security (secret mounts, non-root users, attestations)16- Setting up CI/CD pipelines with Docker builds17- Reviewing Dockerfiles for anti-patterns1819## Rule Categories by Priority2021| Priority | Category | Impact | Prefix |22|----------|----------|--------|--------|23| 1 | Layer Caching & Ordering | CRITICAL | `cache-` |24| 2 | Multi-Stage Builds | CRITICAL | `stage-` |25| 3 | Base Image Selection | HIGH | `base-` |26| 4 | Build Context Management | HIGH | `ctx-` |27| 5 | Security & Secrets | HIGH | `sec-` |28| 6 | Dependency Management | MEDIUM-HIGH | `dep-` |29| 7 | Instruction Patterns | MEDIUM | `inst-` |30| 8 | Quality & Validation | MEDIUM | `lint-` |3132## Quick Reference3334### 1. Layer Caching & Ordering (CRITICAL)3536- [`cache-layer-order`](references/cache-layer-order.md) - Order layers by change frequency37- [`cache-copy-deps-first`](references/cache-copy-deps-first.md) - Copy dependency files before source code38- [`cache-copy-link`](references/cache-copy-link.md) - Use COPY --link for cache-efficient layer copying39- [`cache-mount-package`](references/cache-mount-package.md) - Use cache mounts for package managers40- [`cache-apt-combine`](references/cache-apt-combine.md) - Combine apt-get update with install41- [`cache-external`](references/cache-external.md) - Use external cache for CI/CD builds42- [`cache-invalidation`](references/cache-invalidation.md) - Avoid unnecessary cache invalidation43- [`cache-minimize-layers`](references/cache-minimize-layers.md) - Consolidate related RUN instructions4445### 2. Multi-Stage Builds (CRITICAL)4647- [`stage-separate-build-runtime`](references/stage-separate-build-runtime.md) - Separate build and runtime stages48- [`stage-named-stages`](references/stage-named-stages.md) - Use named build stages49- [`stage-parallel-branches`](references/stage-parallel-branches.md) - Exploit parallel stage execution50- [`stage-target-builds`](references/stage-target-builds.md) - Use target builds for dev/prod51- [`stage-copy-artifacts-only`](references/stage-copy-artifacts-only.md) - Copy only final artifacts between stages52- [`stage-reusable-base`](references/stage-reusable-base.md) - Create reusable base stages5354### 3. Base Image Selection (HIGH)5556- [`base-minimal-image`](references/base-minimal-image.md) - Use minimal base images57- [`base-official-images`](references/base-official-images.md) - Use Docker Official Images58- [`base-pin-versions`](references/base-pin-versions.md) - Pin base image versions with digests59- [`base-arg-version`](references/base-arg-version.md) - Use ARG before FROM to parameterize base images60- [`base-rebuild-regularly`](references/base-rebuild-regularly.md) - Rebuild images regularly with --pull61- [`base-distroless`](references/base-distroless.md) - Use distroless or scratch images for production6263### 4. Build Context Management (HIGH)6465- [`ctx-dockerignore`](references/ctx-dockerignore.md) - Use .dockerignore to exclude unnecessary files66- [`ctx-bind-mounts`](references/ctx-bind-mounts.md) - Use bind mounts instead of COPY for build-only files67- [`ctx-minimize-context`](references/ctx-minimize-context.md) - Keep build context small68- [`ctx-syntax-directive`](references/ctx-syntax-directive.md) - Use syntax directive for latest BuildKit features (prerequisite for cache mounts, secret mounts, heredocs, COPY --link)6970### 5. Security & Secrets (HIGH)7172- [`sec-secret-mounts`](references/sec-secret-mounts.md) - Use secret mounts for sensitive data73- [`sec-non-root-user`](references/sec-non-root-user.md) - Run as non-root user74- [`sec-no-secrets-in-args`](references/sec-no-secrets-in-args.md) - Never pass secrets via ARG or ENV75- [`sec-ssh-mounts`](references/sec-ssh-mounts.md) - Use SSH mounts for private repository access76- [`sec-attestations`](references/sec-attestations.md) - Enable SBOM and provenance attestations77- [`sec-no-unnecessary-packages`](references/sec-no-unnecessary-packages.md) - Avoid installing unnecessary packages78- [`sec-ephemeral-containers`](references/sec-ephemeral-containers.md) - Design ephemeral, stateless containers7980### 6. Dependency Management (MEDIUM-HIGH)8182- [`dep-cache-mount-apt`](references/dep-cache-mount-apt.md) - Use cache mount for apt package manager83- [`dep-cache-mount-npm`](references/dep-cache-mount-npm.md) - Use cache mount for npm, yarn, and pnpm84- [`dep-cache-mount-pip`](references/dep-cache-mount-pip.md) - Use cache mount for pip85- [`dep-version-pin`](references/dep-version-pin.md) - Pin package versions for reproducibility86- [`dep-cleanup-caches`](references/dep-cleanup-caches.md) - Clean package manager caches in the same layer8788### 7. Instruction Patterns (MEDIUM)8990- [`inst-json-cmd`](references/inst-json-cmd.md) - Use JSON form for CMD and ENTRYPOINT91- [`inst-healthcheck`](references/inst-healthcheck.md) - Define HEALTHCHECK for container orchestration92- [`inst-heredoc-scripts`](references/inst-heredoc-scripts.md) - Use heredocs for multi-line scripts93- [`inst-entrypoint-exec`](references/inst-entrypoint-exec.md) - Use exec in entrypoint scripts94- [`inst-workdir-absolute`](references/inst-workdir-absolute.md) - Use absolute paths with WORKDIR95- [`inst-copy-over-add`](references/inst-copy-over-add.md) - Prefer COPY over ADD9697### 8. Quality & Validation (MEDIUM)9899- [`lint-build-checks`](references/lint-build-checks.md) - Enable Docker build checks100- [`lint-pipefail`](references/lint-pipefail.md) - Use pipefail for piped RUN commands101- [`lint-labels`](references/lint-labels.md) - Use standard labels for image metadata102- [`lint-sort-arguments`](references/lint-sort-arguments.md) - Sort multi-line arguments alphabetically103- [`lint-single-concern`](references/lint-single-concern.md) - One concern per container104105## How to Use106107Read individual reference files for detailed explanations and code examples:108109- [Section definitions](references/_sections.md) - Category structure and impact levels110- [Rule template](assets/templates/_template.md) - Template for adding new rules111112## Reference Files113114| File | Description |115|------|-------------|116| [references/_sections.md](references/_sections.md) | Category definitions and ordering |117| [assets/templates/_template.md](assets/templates/_template.md) | Template for new rules |118| [metadata.json](metadata.json) | Version and reference information |
Run npx skillmds@latest add comeonoliver/dockerfile-optimise in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Dockerfile Optimization Best Practices It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
ComeOnOliver (@comeonoliver) published this skill. Their other Agent Skills are listed on their SkillMD profile.