awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
hexops-graveyard avatar

hexops-graveyard/dockerfile

0
View on GitHub↗
4,085 stars·155 forks·Dockerfile·13 views

Dockerfile

This project is a collection of best practices and curated templates for building secure, stable, and production-ready Docker images. It provides standards for OCI image optimization and a guide for implementing industry-standard configurations in container environments.

The repository offers specific patterns for security hardening, such as implementing non-root user execution with static IDs to prevent host privilege escalation. It also provides structural templates for multi-stage builds to separate build-time dependencies from the final runtime environment.

Additional capabilities cover container process management using lightweight init systems to handle system signals and prevent zombie processes. The project also includes methods for ensuring build reproducibility through version-pinned base images and network configurations to resolve DNS failures across legacy Linux and macOS runtimes.

Features

  • Container Image Building - Provides a comprehensive set of standards and templates for building secure and optimized production container images.
  • Docker Image Building - Provides a comprehensive set of standards and templates for building secure, production-ready Docker images.
  • Multi-Stage Container Builds - Provides structural patterns for multi-stage builds to reduce attack surface and final image size.
  • Multi-Stage Build Pipelines - Ships curated multi-stage build templates that separate build-time dependencies from the final runtime environment.
  • Image Optimization Standards - Establishes guidelines for pinning base images and structuring entrypoints to ensure efficient and reproducible OCI builds.
  • Hardened Container Images - Provides patterns for creating pre-configured, secure container images designed for production environments.
  • Non-Root Process Identities - Implements non-privileged user identities with static IDs to prevent host privilege escalation.
  • Container Security Hardening - Hardens container security by restricting application privileges and implementing non-root execution.
  • Reproducible Build Environments - Ensures consistent container builds by pinning base image versions and managing dependency updates.
  • Base Image Pinning - Locks specific base image tags to ensure consistent builds and prevent breaking changes from upstream updates.
  • OCI Container Process Management - Manages process lifecycles and signal propagation within OCI compliant container runtimes.
  • Reproducible Build Systems - Ensures consistent and deterministic image builds across environments by pinning base image versions.
  • Process Signal Forwarding - Implements mechanisms to propagate termination signals from the container init process to child processes.
  • Container Init Process - Uses a lightweight init system as PID 1 to handle system signals and manage zombie processes.

Star history

Star history chart for hexops-graveyard/dockerfileStar history chart for hexops-graveyard/dockerfile

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Curated searches featuring Dockerfile

Hand-picked collections where Dockerfile appears.
  • Dockerfile Best Practice Linters

Open-source alternatives to Dockerfile

Similar open-source projects, ranked by how many features they share with Dockerfile.
  • collabnix/dockerlabscollabnix avatar

    collabnix/dockerlabs

    8,008View on GitHub↗

    dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of containerization and microservice architecture. It provides instructional material and hands-on exercises covering image optimization, security training, infrastructure setup, and cluster orchestration. The project features specific courses and guides focused on reducing image size through multi-stage builds, securing workloads via vulnerability scanning and encrypted networks, and deploying multi-node clusters with high availability using Swarm orchestration. The materials cover a br

    PHPadvancebeginnersdocker
    View on GitHub↗8,008
  • docker-library/official-imagesdocker-library avatar

    docker-library/official-images

    6,972View on GitHub↗

    This project is a collection of curated and standardized Docker base images that serve as reliable starting points for building containerized applications. It functions as an OCI container image repository and a build template library, providing a central source of truth for images that adhere to Open Container Initiative standards for portability. The project utilizes an automated image lifecycle pipeline to build, tag, and push images, ensuring that dependencies remain current and security patches are applied. It specifically supports cross-platform distribution by providing a multi-archite

    Shell
    View on GitHub↗6,972
  • krallin/tinikrallin avatar

    krallin/tini

    11,129View on GitHub↗

    Tini is a lightweight process management tool designed to act as the entrypoint for OCI compliant containers. It functions as a minimal init process that manages the lifecycle of a primary child process, preventing the root process from ignoring critical termination signals. The project focuses on signal proxying and zombie process reaping. It forwards system signals from the container runtime to child processes and process groups to ensure graceful shutdowns. Additionally, it automatically collects terminated child processes to prevent the process table from filling with defunct entries. Ti

    Ccdockerinit
    View on GitHub↗11,129
  • bitnami/containersbitnami avatar

    bitnami/containers

    4,441View on GitHub↗

    This project is a cloud-native software distribution and an OCI container image library. It provides a collection of pre-configured, hardened container images and Docker Compose application stacks designed for consistent deployment across cloud and on-premises environments. The images are production-ready and compiled using standardized security configurations and vulnerability scanning to reduce attack surfaces. These hardened application images are designed to minimize manual setup and security risks during deployment. The project covers container vulnerability management, production-ready

    Shellbitnamicontainersdocker
    View on GitHub↗4,441
See all 30 alternatives to Dockerfile→

Frequently asked questions

What does hexops-graveyard/dockerfile do?

This project is a collection of best practices and curated templates for building secure, stable, and production-ready Docker images. It provides standards for OCI image optimization and a guide for implementing industry-standard configurations in container environments.

What are the main features of hexops-graveyard/dockerfile?

The main features of hexops-graveyard/dockerfile are: Container Image Building, Docker Image Building, Multi-Stage Container Builds, Multi-Stage Build Pipelines, Image Optimization Standards, Hardened Container Images, Non-Root Process Identities, Container Security Hardening.

What are some open-source alternatives to hexops-graveyard/dockerfile?

Open-source alternatives to hexops-graveyard/dockerfile include: collabnix/dockerlabs — dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of… docker-library/official-images — This project is a collection of curated and standardized Docker base images that serve as reliable starting points for… krallin/tini — Tini is a lightweight process management tool designed to act as the entrypoint for OCI compliant containers. It… bitnami/containers — This project is a cloud-native software distribution and an OCI container image library. It provides a collection of… yeasy/docker_practice — This project is a Docker educational resource and a collection of practical examples designed for learning… yelp/dumb-init — dumb-init is a lightweight process supervisor and minimal init system designed to run as the primary process in a…