Docker 破壞性操作防護
Docker 破壞性操作防護
在清理 Docker 資源前辨識資料損失範圍並要求確認。
Docker · 官方來源 · 安全
來源狀態
可用來源
資源類型
Skill
與類似 Skill 有什麼不同?
- Docker 建置最佳化
Docker Build Strategies 改善映像建置與分層;Docker Destructive Guardrails 約束 prune、刪除 volume 等破壞性操作。
來源描述的能力
這些是來源描述的可能操作,不代表 2lus 已授予權限或已測試。
- Shell 指令
- Docker 操作
這個 Skill 是什麼?
將 container、image、cache 與 volume 的清理風險分開,讓 Agent 先交代確切目標與可回復性;這是行為規範,不是強制權限隔離。
可以做什麼?何時適合使用?
- 清理 NAS 閒置資源。
- 判斷 prune 是否包含資料卷。
- 移除舊容器前確認掛載資料。
如何使用
- 先使用獲准的唯讀資訊確認 Docker context、主機與目標資源。
- 列出依賴、掛載資料、不可回復項目與備份狀態。
- 把擬執行指令及精確目標交給操作者確認,未批准不刪除。
使用前你需要準備
- 待審查來源與權限
- 威脅假設及不能操作的範圍
你可以替換:
[scope]、[permissions]
環境與相依需求
- Docker CLI 與辨識目前 daemon/context 的能力;高風險操作需有權操作者批准。
使用範例與 Prompt
以下是 2lus 撰寫的示範需求;請替換為你有權處理的檔案與專案,不代表已執行或保證結果。
入門
解釋 docker system prune 與 volume 清理的風險差異,只提供說明,不執行命令。
實務
我要清理 NAS 的 Docker 資源;先列出唯讀盤點方式,區分可重建 cache 與 persistent data,等待我確認。
進階
審查這份清理腳本,逐項標示精確目標、資料卷依賴、不可逆影響和備份前提;將任何刪除命令改為需人工批准的計畫。
實用提醒
- 把「沒有容器使用」與「資料不再需要」視為不同判斷。
限制與注意事項
- 提示規則可能被 Agent 忽略,不能代替主機權限、備份或獨立審批。
安全注意事項
- 禁止未確認範圍的 prune、volume remove 或廣泛清理;隱藏資源名稱時仍需保留可追溯目標。
使用與設定
來源 README 的互動式安裝方式;選擇需要的 Skill 與宿主。此處只能複製,不會執行。
npx skills add docker/skills官方文件 ↗
支援平台
Claude Code — 文件記載,未做實機相容性測試 官方文件 ↗
Codex — 文件記載,未做實機相容性測試 官方文件 ↗
Cursor — 文件記載,未做實機相容性測試 官方文件 ↗
GitHub Copilot — 文件記載,未做實機相容性測試 官方文件 ↗
來源與授權
來源查核日期(非安全認證): 2026-09-29
Apache-2.0
原始來源 ↗ 授權條款 ↗ 官方文件 ↗相關 Skills
使用第三方 Skill 前,請先檢查來源、權限與執行內容。安裝指令只供查看與複製,不會由 2lus 執行。
2lus AI Skills Library 提供 Skill 的整理與使用導覽。第三方 Skill 的內容、授權與可用性以原始來源為準。使用或安裝前,請自行確認其權限與執行內容。
Docker Destructive Guardrails
Identify potential Docker data loss before cleanup and require an explicit decision.
Docker · Official source · Security
Source status
Active source
Resource type
Skill
How is this different from similar skills?
- Docker Build Strategies
Docker Build Strategies improves image construction and layers; Docker Destructive Guardrails constrains pruning, volume deletion and other destructive actions.
Documented capabilities
These are operations described upstream, not permissions granted or tested by 2lus.
- Shell commands
- Docker operations
What is this skill?
Distinguish container, image, cache and volume risks so an agent explains exact targets and recoverability. This is behavioral guidance, not an enforced sandbox.
Use cases and when to use it
- Review unused NAS resources.
- Determine whether prune includes persistent data.
- Check mounts before removing old containers.
How to use it
- Use authorized read-only inventory to identify the daemon, context and targets.
- List dependencies, mounts, irreversible effects and backup status.
- Present exact commands and targets for approval; do not delete without it.
What you need
- Source and permissions to review
- Threat assumptions and prohibited actions
You can replace:
[scope], [permissions]
Environment and dependencies
- Docker CLI access, daemon/context awareness and approval from an authorized operator.
Usage and prompt examples
These example requests were written by 2lus. Substitute files and projects you may use; examples are not executed results or guarantees.
Beginner
Explain the risk differences between system pruning and volume cleanup. Execute nothing.
Practical
I need to clean a NAS. Propose read-only Docker inventory, distinguish rebuildable cache from persistent data, then wait for approval.
Advanced
Audit this cleanup script for exact targets, volume dependencies, irreversible effects and backup prerequisites. Convert deletions into a plan requiring human approval.
Tips
- Unused by a container does not mean no longer valuable.
Limitations
- Instructions cannot replace host permissions, backups or independent approval.
Security notes
- Do not run broad prune or volume removal without confirmed scope and recovery planning.
Usage and setup
Interactive installation documented in the README; select skills and host. This page only copies the command.
npx skills add docker/skillsDocumentation ↗
Supported agents
Claude Code — Documented; not runtime-tested Documentation ↗
Codex — Documented; not runtime-tested Documentation ↗
Cursor — Documented; not runtime-tested Documentation ↗
GitHub Copilot — Documented; not runtime-tested Documentation ↗
Sources and license
Source check date (not a safety certification): 2026-09-29
Apache-2.0
Original source ↗ License terms ↗ Documentation ↗Related skills
Before using a third-party skill, review its source, permissions and executable content. Commands are for viewing and copying only; 2lus does not execute them.
2lus AI Skills Library provides curated educational guides. Third-party content, licenses and availability are governed by their original sources. Review permissions and executable content before use or installation.