awesome-repositories.com
المدونة
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
hexops-graveyard avatar

hexops-graveyard/dockerfile

0
View on GitHub↗
4,085 نجوم·155 تفرعات·Dockerfile·4 مشاهدات

Dockerfile

هذا المشروع عبارة عن مجموعة من أفضل الممارسات والقوالب المنسقة لبناء صور Docker آمنة ومستقرة وجاهزة للإنتاج. يوفر معايير لتحسين صور OCI ودليلاً لتنفيذ التكوينات القياسية في بيئات الحاويات.

يقدم المستودع أنماطاً محددة لتعزيز الأمان، مثل تنفيذ العمليات كمستخدم غير جذري (non-root) بمعرفات ثابتة لمنع تصعيد الامتيازات على المضيف. كما يوفر قوالب هيكلية للبناء متعدد المراحل لفصل تبعيات وقت البناء عن بيئة وقت التشغيل النهائية.

تغطي الإمكانيات الإضافية إدارة عمليات الحاوية باستخدام أنظمة init خفيفة الوزن للتعامل مع إشارات النظام ومنع العمليات الزومبي. يتضمن المشروع أيضاً طرقاً لضمان قابلية إعادة إنتاج البناء من خلال صور أساسية مثبتة الإصدار وتكوينات الشبكة لحل إخفاقات DNS عبر بيئات تشغيل Linux و macOS القديمة.

Features

  • Container Image Building - Provides a comprehensive set of standards and templates for building secure and optimized production container images.
  • Docker Image Building - Provides a comprehensive set of standards and templates for building secure, production-ready Docker images.
  • Multi-Stage Container Builds - Provides structural patterns for multi-stage builds to reduce attack surface and final image size.
  • Multi-Stage Build Pipelines - Ships curated multi-stage build templates that separate build-time dependencies from the final runtime environment.
  • Image Optimization Standards - Establishes guidelines for pinning base images and structuring entrypoints to ensure efficient and reproducible OCI builds.
  • Hardened Container Images - Provides patterns for creating pre-configured, secure container images designed for production environments.
  • Non-Root Process Identities - Implements non-privileged user identities with static IDs to prevent host privilege escalation.
  • Container Security Hardening - Hardens container security by restricting application privileges and implementing non-root execution.
  • Reproducible Build Environments - Ensures consistent container builds by pinning base image versions and managing dependency updates.
  • Base Image Pinning - Locks specific base image tags to ensure consistent builds and prevent breaking changes from upstream updates.
  • OCI Container Process Management - Manages process lifecycles and signal propagation within OCI compliant container runtimes.
  • Reproducible Build Systems - Ensures consistent and deterministic image builds across environments by pinning base image versions.
  • Process Signal Forwarding - Implements mechanisms to propagate termination signals from the container init process to child processes.
  • Container Init Process - Uses a lightweight init system as PID 1 to handle system signals and manage zombie processes.

سجل النجوم

مخطط تاريخ النجوم لـ hexops-graveyard/dockerfileمخطط تاريخ النجوم لـ hexops-graveyard/dockerfile

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Start searching with AI

مجموعات مختارة تضم Dockerfile

مجموعات منسقة بعناية يظهر فيها Dockerfile.
  • أدوات فحص أفضل ممارسات Dockerfile

الأسئلة الشائعة

ما هي وظيفة hexops-graveyard/dockerfile؟

هذا المشروع عبارة عن مجموعة من أفضل الممارسات والقوالب المنسقة لبناء صور Docker آمنة ومستقرة وجاهزة للإنتاج. يوفر معايير لتحسين صور OCI ودليلاً لتنفيذ التكوينات القياسية في بيئات الحاويات.

ما هي الميزات الرئيسية لـ hexops-graveyard/dockerfile؟

الميزات الرئيسية لـ hexops-graveyard/dockerfile هي: Container Image Building, Docker Image Building, Multi-Stage Container Builds, Multi-Stage Build Pipelines, Image Optimization Standards, Hardened Container Images, Non-Root Process Identities, Container Security Hardening.

ما هي البدائل مفتوحة المصدر لـ hexops-graveyard/dockerfile؟

تشمل البدائل مفتوحة المصدر لـ hexops-graveyard/dockerfile: collabnix/dockerlabs — dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of… docker-library/official-images — This project is a collection of curated and standardized Docker base images that serve as reliable starting points for… krallin/tini — Tini is a lightweight process management tool designed to act as the entrypoint for OCI compliant containers. It… bitnami/containers — This project is a cloud-native software distribution and an OCI container image library. It provides a collection of… yeasy/docker_practice — This project is a Docker educational resource and a collection of practical examples designed for learning… yelp/dumb-init — dumb-init is a lightweight process supervisor and minimal init system designed to run as the primary process in a…

بدائل مفتوحة المصدر لـ Dockerfile

مشاريع مفتوحة المصدر مشابهة، مرتبة حسب عدد الميزات المشتركة مع Dockerfile.
  • collabnix/dockerlabsالصورة الرمزية لـ collabnix

    collabnix/dockerlabs

    8,008عرض على GitHub↗

    dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of containerization and microservice architecture. It provides instructional material and hands-on exercises covering image optimization, security training, infrastructure setup, and cluster orchestration. The project features specific courses and guides focused on reducing image size through multi-stage builds, securing workloads via vulnerability scanning and encrypted networks, and deploying multi-node clusters with high availability using Swarm orchestration. The materials cover a br

    PHPadvancebeginnersdocker
    عرض على GitHub↗8,008
  • docker-library/official-imagesالصورة الرمزية لـ docker-library

    docker-library/official-images

    6,972عرض على GitHub↗

    This project is a collection of curated and standardized Docker base images that serve as reliable starting points for building containerized applications. It functions as an OCI container image repository and a build template library, providing a central source of truth for images that adhere to Open Container Initiative standards for portability. The project utilizes an automated image lifecycle pipeline to build, tag, and push images, ensuring that dependencies remain current and security patches are applied. It specifically supports cross-platform distribution by providing a multi-archite

    Shell
    عرض على GitHub↗6,972
  • krallin/tiniالصورة الرمزية لـ krallin

    krallin/tini

    11,129عرض على GitHub↗

    Tini is a lightweight process management tool designed to act as the entrypoint for OCI compliant containers. It functions as a minimal init process that manages the lifecycle of a primary child process, preventing the root process from ignoring critical termination signals. The project focuses on signal proxying and zombie process reaping. It forwards system signals from the container runtime to child processes and process groups to ensure graceful shutdowns. Additionally, it automatically collects terminated child processes to prevent the process table from filling with defunct entries. Ti

    Ccdockerinit
    عرض على GitHub↗11,129
  • bitnami/containersالصورة الرمزية لـ bitnami

    bitnami/containers

    4,441عرض على GitHub↗

    This project is a cloud-native software distribution and an OCI container image library. It provides a collection of pre-configured, hardened container images and Docker Compose application stacks designed for consistent deployment across cloud and on-premises environments. The images are production-ready and compiled using standardized security configurations and vulnerability scanning to reduce attack surfaces. These hardened application images are designed to minimize manual setup and security risks during deployment. The project covers container vulnerability management, production-ready

    Shellbitnamicontainersdocker
    عرض على GitHub↗4,441
  • عرض جميع البدائل الـ 30 لـ Dockerfile→