spring-boot-container

spring-boot-container is a cursor rule for Cursor from lsampaioweb/ai-instructions. It costs 0 tokens per session (542 once invoked), scanned A, original, MIT.

Container rules for running a Spring Boot application with Docker and Docker Compose. They cover image setup, user permissions, storage, health checks, and logging.

In plain words
What is it for?
Use them when writing a Dockerfile or Compose file for a Spring Boot service, including local run setups and production-style hardening.
Why use it?
They provide consistent container settings and reduce common security and runtime mistakes when packaging the application.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/lsampaioweb/ai-instructions/spring-boot-container
Clone the repo
git clone --depth 1 https://github.com/lsampaioweb/ai-instructions

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for spring-boot-container

README.md
[![agentmods](https://agentmods.dev/badge/rules/lsampaioweb/ai-instructions/spring-boot-container.svg)](https://agentmods.dev/rules/lsampaioweb/ai-instructions/spring-boot-container)
Your own site
<a href="https://agentmods.dev/rules/lsampaioweb/ai-instructions/spring-boot-container"><img src="https://agentmods.dev/badge/rules/lsampaioweb/ai-instructions/spring-boot-container.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 542 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00542
Opus 5 $0.00000 $0.00271
Sonnet 5 $0.00000 $0.00108
Haiku 4.5 $0.00000 $0.00054

Measured 3d ago against content hash 3d9f60d60456, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

spring-boot-container scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/spring-boot-container.mdc · 37 lines

How it starts

The opening of the file, as written. The whole thing — 37 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Spring Boot Container

Rules

  • Use an official Eclipse Temurin JRE image as the base image for runtime stages.
  • Keep container images pinned to explicit tags.
  • Keep build and runtime stages separated when multi-stage is used.
  • Keep compose services hardened with minimal privileges by default.
  • Set restart: "unless-stopped" as the default container restart policy.
  • Set read_only: true on all compose services.
  • Declare tmpfs mounts for writable runtime directories such as /tmp with noexec,nosuid options when read_only: true is set.
  • Set cap_drop: ["ALL"] on every compose service by default.
  • Set security_opt: ["no-new-privileges:true"] on every compose service.
  • Run the Spring Boot application as a non-root user inside the container.
  • Define a dedicated appuser with a non-zero UID for the application user.
  • Keep capability additions exceptional and justified inline for each service.
  • Keep socket mounts read-only and justified by explicit runtime needs.
  • Keep local container run flows documented per scenario (standalone app flow or shared infrastructure flow).
  • Keep healthchecks explicit and service-appropriate (actuator endpoints for Spring apps, native probes for infrastructure services).
  • Set healthcheck with interval=30s, timeout=5s, retries=3, and start_period=60s as defaults unless operational requirements differ.
  • Keep runtime configuration profile-aware and externalized.
  • Activate the Spring profile via the SPRING_PROFILES_ACTIVE environment variable.
  • Configure JVM flags via the JAVA_TOOL_OPTIONS environment variable.
  • Expose port 8080 in Dockerfile by default unless the application explicitly configures a different server port.
  • Set explicit CPU and memory resource limits (cpus, mem_limit, mem_reservation) on every compose service.

Safety Guards

  • Never bake profile selection into the Dockerfile layer.
  • Never hardcode heap or memory flags in the CMD or ENTRYPOINT instruction.
  • Never use JAVA_OPTS as the JVM flags variable when using ENTRYPOINT ["java", "-jar"]; use JAVA_TOOL_OPTIONS instead.
  • Never expose internal-only ports without explicit need and documentation.
  • Never ship container defaults that bypass runtime safety controls.

Read the full file on GitHub · 37 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 37 lines · 0 tokens per session scan A 3d9f60d60456

Subscribe to this mod's changes

spring-boot-container is a cursor rule published in the GitHub repository lsampaioweb/ai-instructions (1 stars, last pushed 11d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 542 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.