ai-instructions spring-boot-container.instructions.md

ai-instructions spring-boot-container.instructions.md is an instructions file for GitHub Copilot from lsampaioweb/ai-instructions. It costs 504 tokens per session, scanned A, original, MIT.

A set of rules for packaging Spring Boot applications in Docker images and Docker Compose services.

In plain words
What is it for?
It is for writing Dockerfiles and Compose files, choosing runtime images, running as a non-root user, mounting writable directories, and adding health checks.
Why use it?
It reduces container security risks and makes application startup, health checks, permissions, storage, and restart behavior predictable.

Instructions file for GitHub Copilot

Written for GitHub Copilot: a Copilot chat mode or prompt.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/lsampaioweb/ai-instructions/spring-boot-container
Clone the repo
git clone --depth 1 https://github.com/lsampaioweb/ai-instructions

Made for: GitHub Copilot.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ai-instructions spring-boot-container.instructions.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/lsampaioweb/ai-instructions/spring-boot-container.svg)](https://agentmods.dev/instructions/lsampaioweb/ai-instructions/spring-boot-container)
Your own site
<a href="https://agentmods.dev/instructions/lsampaioweb/ai-instructions/spring-boot-container"><img src="https://agentmods.dev/badge/instructions/lsampaioweb/ai-instructions/spring-boot-container.svg" alt="Measured on agentmods" height="20"></a>
Per session 504 This file is loaded in full into every session.
When invoked 504 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00504 $0.00504
Opus 5 $0.00252 $0.00252
Sonnet 5 $0.00101 $0.00101
Haiku 4.5 $0.00050 $0.00050

Measured 2d ago against content hash f5d12b9ac435, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

ai-instructions spring-boot-container.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/spring-boot-container.instructions.md · 36 lines

How it starts

The opening of the file, as written. The whole thing — 36 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Spring Boot Container

Rules

  • Use an official Eclipse Temurin JRE image as the base image for runtime stages.
  • Keep container images pinned to explicit tags.
  • Keep build and runtime stages separated when multi-stage is used.
  • Keep compose services hardened with minimal privileges by default.
  • Set restart: "unless-stopped" as the default container restart policy.
  • Set read_only: true on all compose services.
  • Declare tmpfs mounts for writable runtime directories such as /tmp with noexec,nosuid options when read_only: true is set.
  • Set cap_drop: ["ALL"] on every compose service by default.
  • Set security_opt: ["no-new-privileges:true"] on every compose service.
  • Run the Spring Boot application as a non-root user inside the container.
  • Define a dedicated appuser with a non-zero UID for the application user.
  • Keep capability additions exceptional and justified inline for each service.
  • Keep socket mounts read-only and justified by explicit runtime needs.
  • Document the standalone app flow and the shared infrastructure flow as separate run scenarios.
  • Keep healthchecks explicit and service-appropriate (actuator endpoints for Spring apps, native probes for infrastructure services).
  • Set healthcheck with interval=30s, timeout=5s, retries=3, and start_period=60s as defaults unless operational requirements differ.
  • Keep runtime configuration profile-aware and externalized.
  • Activate the Spring profile via the SPRING_PROFILES_ACTIVE environment variable.
  • Configure JVM flags via the JAVA_TOOL_OPTIONS environment variable.
  • Expose port 8080 in Dockerfile by default unless the application explicitly configures a different server port.
  • Set explicit CPU and memory resource limits (cpus, mem_limit, mem_reservation) on every compose service.

Safety Guards

  • Never bake profile selection into the Dockerfile layer.
  • Never hardcode heap or memory flags in the CMD or ENTRYPOINT instruction.
  • Never use JAVA_OPTS as the JVM flags variable.
  • Never expose internal-only ports without explicit need and documentation.

Read the full file on GitHub · 36 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 36 lines · 504 tokens per session scan A f5d12b9ac435

Subscribe to this mod's changes

ai-instructions spring-boot-container.instructions.md is an instructions file published in the GitHub repository lsampaioweb/ai-instructions (1 stars, last pushed 13d ago), licensed MIT. It adds 504 tokens to every session, about $0.0025 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.