$ recombobulate _
home / tips / ask-claude-to-audit-your-dockerfile-for-size-and-security
143

Ask Claude to Audit Your Dockerfile for Size and Security

recombobulate @recombobulate · Mar 26, 2026 · Workflows
ask-claude-to-audit-your-dockerfile-for-size-and-security

A 1.2GB Docker image often only needs to be 120MB. Paste your Dockerfile and ask Claude to find what's bloating it.

Review this Dockerfile and identify specific changes to reduce the final image size
and improve security. Consider: multi-stage builds, layer caching order, removing
dev dependencies, Alpine vs slim base images, and any unnecessary packages.

Claude will spot the common culprits — COPY . . before installing dependencies (which busts the cache on every code change), apt-get without --no-install-recommends and cleanup, running as root, and choosing node:18 when node:18-alpine would shave 700MB.

Then ask for the rewrite:

Rewrite this Dockerfile using a multi-stage build. Stage 1 compiles assets and
installs all dependencies. Stage 2 is an Alpine-based runtime image that copies
only the production artifacts and runs as a non-root user.

For security, ask Claude to scan for hardcoded secrets, check that the final image doesn't include .git directories, and verify that sensitive build args aren't baked into layers.

The time investment is one prompt. The payoff is faster CI, smaller registries, and a smaller attack surface in production.

Your Dockerfile is probably 10 lines of good intentions and 5 lines of accidental bloat — Claude finds them instantly.

~/recombobulate $ tip --comments --count=0

Log in to leave a comment.

~/recombobulate $ tip --related --limit=3
0
Run Claude Code in GitHub Actions to Automatically Review Every Pull Request

Set up Claude Code as an automated reviewer in your CI pipeline — on every pull request, it reads the diff, checks for bugs, security issues, missing tests, and convention violations, then posts its findings as a PR comment. Your human reviewers get a head start because the obvious issues are already flagged before they look.

recombobulate @recombobulate · 1 month ago
0
Ask Claude to Build a Deployment Checklist from Your Actual Infrastructure

Before deploying, tell Claude to read your project — migrations, environment variables, queue workers, scheduled tasks, caching, third-party integrations — and generate a deployment checklist that's specific to your app. Not a generic "did you run migrations?" list, but one that knows YOUR infrastructure and catches the things YOUR deploy can break.

recombobulate @recombobulate · 1 month ago
0
Ask Claude to Generate a README from Your Actual Codebase — Not a Template

Instead of writing a README from memory or copying a template, tell Claude to read your project and generate one that's actually accurate — real setup instructions from your config, real architecture from your directory structure, real API examples from your routes, and real prerequisites from your dependency files.

recombobulate @recombobulate · 1 month ago