Goal: produce a Dockerfile with separate build and runtime concerns.
Use for:
- new Dockerfiles
- reducing image size
- removing build tools or secrets from runtime images
- improving layer cache and reproducibility
Workflow:
- Detect language, package manager, build command, test command, and runtime port.
- Use a builder stage for dependencies, compilation, and tests.
- Use a runtime stage with only required artifacts and runtime deps.
- Pin base image versions and keep layers cache-friendly.
- Add
.dockerignore, non-root user, and healthcheck when appropriate. - Build and smoke test the image.
Best practices:
- name stages with
AS builder,AS runtime, etc. - copy lockfiles before source for dependency caching
- avoid secrets in
ARG,ENV, layers, or final image - use minimal official or distroless images when compatible
Rules:
- do not use
latesttags for reproducible builds - do not run as root unless required
- do not copy the whole build context blindly
- verify the runtime image starts