Speckit.devops
bro-skills - Spec-Driven Development CLI
npx -y skills add wedabro/bro-skills --skill speckit.devopsAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Docker Infrastructure & Security Hardening Specialist β Port ENV-first.
SKILL.md
3.1 KB, as published. Nobody here has run it
π― Mission
Set up and manage a standardized and secure Docker system for the project. Published ports MUST always be configured via environment variables.
π₯ Input
.agent/memory/constitution.md(port range, security rules)- Existing
Dockerfile,docker-compose.yml(if available) .env.example
π Protocol
1. Port Allocation (ENV-first) β
ALWAYS configure ports via ENV:
.envfile (local) or server ENV (production)docker-compose.ymlreads:"${PUBLIC_PORT}:${WEB_CONTAINER_PORT}"- Document required port variables in
.env.example; do not hide missing configuration behind a fixed fallback. - CRITICAL: If
.envor system environment already has port variables defined (e.g.PUBLIC_PORT,ADMIN_PORT,API_PORTor equivalents), ABSOLUTELY SKIP port scanning/assignment and NEVER overwrite the existing port configuration.
Port scanning rules according to environment:
| Environment | Existing Ports in .env? | Docker running? | Act |
|---|---|---|---|
| Any | β Yes | Any | SKIP scan β use existing ports, DO NOT overwrite |
| Local | β No | β No (first time) | Scan available ports with socket/helper β select 3 consecutive empty ports |
| Local | β No | β Already running | SKIP scan β use current ports from docker/containers |
| Staging/Beta/Prod | β No | Any | ALWAYS initial scan for configuration β write to .env |
Check Docker is running (Local):
docker compose ps --format json 2>$null
# There are containers β SKIP port scan
# Empty/error β RUN port scan
- Pattern: Public FE
Nβ Admin FEN+1β Backend APIN+2
2. Local Docker (docker-compose.yml):
- Published and container ports read from ENV:
"${PUBLIC_PORT}:${WEB_CONTAINER_PORT}" - Volume mounts cho hot-reload code
- Named volumes for
node_modules(avoid host-container lock) - Health checks for each service
3. Production Docker (docker-compose.prod.yml):
- Multi-stage builds (builder β runner)
USER nodeorUSER appuser(DO NOT run as root)- Remove devDependencies in the final image
- Alpine/Slim base images
- Ports read from ENV (NO hard-code)
4. Security Checklist:
.dockerignore: block.env,.git,node_modules- No hard-code secrets in Dockerfile
- Only EXPOSE ports are needed
5. Documentation:
- Update
.agent/knowledge_base/infrastructure.mdwith the results - Update
.env.examplewith all port vars
π€ Output
- Files:
Dockerfile,docker-compose.yml,docker-compose.prod.yml,.dockerignore - Config:
.env(ports),.env.example(documented) - Doc:
.agent/knowledge_base/infrastructure.md(updated)
π« Guard Rails
- Flexibly configure ports via environment variables (.env) to avoid conflicts.
- DO NOT hard-code port numbers β ALWAYS use ENV vars.
- DO NOT run
docker compose down -von production. - DO NOT hard-code credentials into the Dockerfile.
- DO NOT scan ports when Docker local is already running (with containers).