containerize

A procedure for packaging an application as a small, non-root OCI container image, a portable package that includes software and its runtime. It covers Go builds with ko and other languages with multi-stage Dockerfiles.

In plain words
What is it for?
Use it to build and verify container images for Go, Python, or other applications, including multi-platform images.
Why use it?
It creates a reproducible deployment package and includes checks such as scanning, signing, and generating a software bill of materials.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fmind/dotfiles/containerize
Any agent
npx skills add fmind/dotfiles --skill containerize
Clone the repo
git clone --depth 1 https://github.com/fmind/dotfiles

Made for: Claude Code, Codex.

Per session 47 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,424 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00047 $0.01424
Opus 5 $0.00023 $0.00712
Sonnet 5 $0.00009 $0.00285
Haiku 4.5 $0.00005 $0.00142

Measured yesterday against content hash 93558da57b93, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

containerize scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/containerize/SKILL.md · 99 lines

How it starts

The opening of the file, as written. The whole thing — 99 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Containerize an Application

Build a small, non-root, reproducible OCI image and verify it before it ships. Pairs with k8s-local for the local dev loop and security-scan for image scanning.

Choose an Approach

  1. Go → ko (default, no Dockerfile): builds a minimal, shell-less, multi-arch, reproducible image straight from a package path (base defaults to cgr.dev/chainguard/static, override with KO_DEFAULTBASEIMAGE). Pin it per project (go get -tool github.com/google/ko, then go tool ko) so builds stay reproducible even where a global toolchain already provides ko.

    export KO_DOCKER_REPO=registry.localhost:5050/<slug>   # or a real registry
    go tool ko build ./cmd/<slug> --bare --platform=linux/amd64,linux/arm64
    
  2. Python (or any other language) → multi-stage Dockerfile on a distroless or minimal base (optimized with uv). Copy and customize the image digests and the <slug> console-script entry point:

    # Build locally for current platform
    docker build -t <registry>/<slug>:<tag> .
    
    # Build multi-platform using Buildx (recommended for multi-arch registries)
    docker buildx build --platform linux/amd64,linux/arm64 -t <registry>/<slug>:<tag> --push .
    

Verify Before Ship

  1. Resolve the immutable digest emitted by the registry after the push. Use that digest for every scan, signature, SBOM, and deployment reference; never sign a mutable tag.
  2. Scan the built image (fail on HIGH/CRITICAL — see security-scan):
    trivy --config trivy.yaml image <registry>/<slug>@<digest>
    
  3. Sign and verify keyless with Sigstore (OIDC, no long-lived keys). Verification must bind the certificate to the expected workflow identity and OIDC issuer:
    cosign sign --yes <registry>/<slug>@<digest> # --yes is mandatory: cosign prompts by default and hangs any CI job or agent session
    cosign verify \
      --certificate-identity '<expected-certificate-identity>' \
      --certificate-oidc-issuer '<expected-oidc-issuer>' \
      <registry>/<slug>@<digest>
    
  4. SBOM for a portable component inventory:
    trivy --config trivy.yaml image --format cyclonedx -o sbom.json <registry>/<slug>@<digest>
    

Read the full file on GitHub · 99 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 99 lines · 47 tokens per session scan A 93558da57b93

Subscribe to this mod's changes

containerize is a skill published in the GitHub repository fmind/dotfiles (4 stars, last pushed 2d ago), licensed MIT. It adds 47 tokens to every session and 1,424 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

dotfiles-bootstrap

Bootstrap a workstation with the dotfiles framework. Takes a GitHub user / owner+repo / explicit clone URL and runs dot init (which shells out to chezmoi) with the right safety prompts. Honors the active agent profile (ask / plan / apply / audit) so it defaults to dry-run in safer modes and full apply in apply.

sebastienrousseau/dotfiles · 88 tokens

vibe

Delegate a coding task to a cheap AI model (Mistral Vibe by default, but any provider Vibe knows about — DeepSeek, Gemini Flash, etc.) and supervise the result via git diff. Claude orchestrates, the cheap model codes. Claude consumes 500-1500 tokens per delegation regardless of how many file reads the delegate does…

sebastienrousseau/dotfiles · 137 tokens

aiq-research

Use when asked to run deep research or AI-Q research through a reachable NVIDIA AI-Q Blueprint backend.

laurigates/dotfiles · 25 tokens

obsidian-bases

Obsidian Bases database feature for YAML-based interactive note views. Use when creating .base files, writing filter queries, building formulas, configuring table/card views, or working with Obsidian properties and frontmatter databases.

laurigates/dotfiles · 49 tokens

telegram

Send notifications, interactive questions, or multiple-choice polls to the user via Telegram. Use when the user asks to be notified ("ping me", "notify me on Telegram", "ask me when..."), when a long-running task finishes and the user is likely away, when an irreversible action needs out-of-band confirmation, or when…

laurigates/dotfiles · 117 tokens

chezmoi-expert

Comprehensive chezmoi dotfiles management expertise including templates, cross-platform configuration, file naming conventions, and troubleshooting. Covers source directory management, reproducible environment setup, and chezmoi templating with Go templates. Use when user mentions chezmoi, dotfiles, cross-platform…

laurigates/dotfiles · 88 tokens