Sign in

Pradumna Saraf

@pradumnasaraf.dev
249 followers 8 following 232 posts

Open Source Developer | Docker Captain | Microsoft MVP | DevOps | Owner @rebasemedia All my links: links.pradumnasaraf.dev

PostsRepliesMedia
Pradumna Saraf @pradumnasaraf.dev · 14/09/2026
One small GitHub CLI feature that makes agentic workflows a lot easier. You can now attach images directly to issues, PRs, and comments. This was a blocker for me in my agentic flows using tools like Claude Code, GitHub Copilot, etc. Nice to see this added!
010
Pradumna Saraf @pradumnasaraf.dev · 12/09/2026
Happy to share that I have been named a Microsoft MVP in Developer Technologies (DevOps) for 2026-2027! 🏆 Thank you to the @mvpaward.bsky.social, and MVP team for their support, and congratulations to everyone newly awarded or returning this cycle. #MVP #MVPBuzz
010
Pradumna Saraf @pradumnasaraf.dev · 07/09/2026
In Docker, `docker debug` provides a debugging environment to run containers without changing the original image. It’s especially useful when your container is missing the tools you need, and it includes built-in tools like entrypoint to inspect how a container started.
Terminal window showing the output of the `docker debug` command, displaying Docker ASCII art, built-in commands, and system information on a grey background.
000
Pradumna Saraf @pradumnasaraf.dev · 30/08/2026
Really impressed with Omarchy. Put it on my 2013 MacBook Air with 4GB RAM, and it's crazy responsive. Doesn't feel like a 13-year-old machine at all. Everything you need is already there. Of course, the first thing I ran was Docker containers.
000
Pradumna Saraf @pradumnasaraf.dev · 26/08/2026
In Docker Compose, you can use `pre_start` to run commands before your container starts. It’s useful for tasks such as running database migrations, preparing files, or performing any setup your app needs before it starts.
A dark-themed compose.yml file shows an app service with image “myapp” and a pre_start command running “./migrate.sh”.
000
Pradumna Saraf @pradumnasaraf.dev · 18/08/2026
Docker has outgrown being just a "container platform". It's evolving fast and gaining new capabilities. I've been writing a lot about Docker recently. Check it out here: pradumnasaraf.dev/blog/tag/doc...
A webpage displays a list of articles tagged with “docker,” featuring five article cards with titles, dates, and brief descriptions. The layout includes a search bar and sorting options.
000
Pradumna Saraf @pradumnasaraf.dev · 11/08/2026
Docker copies your whole folder into the build before it runs anything. That is slow, and worse, your .env can end up inside the image. Deleting it later does not help; the layer keeps it. A .dockerignore next to your Dockerfile stops both: simple file, powerful effect.
A .dockerignore file containing: .git, .gitignore, node_modules, dist, build, .env, .env.*, *.log, .DS_Store
110
Pradumna Saraf @pradumnasaraf.dev · 05/08/2026
In case you missed it: Vercel now supports Dockerfile deployments. That means you can host almost any stack there, not just frontends. I wrote a short guide using a small Go app and a multi-stage Docker build. dev.to/pradumnasara...
dev.to
Deploy a Dockerfile on Vercel
Yes, you heard it right, you can now run a Dockerfile on Vercel. Vercel was the go-to place where...
010
Pradumna Saraf @pradumnasaraf.dev · 01/08/2026
You can now use OIDC to authenticate GitHub Actions with Docker Hub. No more PATs sitting in your repo secrets. Each run gets a short-lived token instead. Nothing to rotate. Nothing to leak. @docker.com
000
Pradumna Saraf @pradumnasaraf.dev · 27/07/2026
Two Docker commands worth knowing. One shows what is in your build cache. The other shows your images, containers and volumes. Run both before you delete anything. @docker.com
A terminal window shows two Docker commands with comments explaining how to inspect build cache and system disk usage.
100
Pradumna Saraf @pradumnasaraf.dev · 19/07/2026
Weekend project: Agent PR Police A GitHub Action that catches PRs opened by AI coding agents. It labels the PR and drops a comment saying which agent opened it and what it changed, so reviewers know. Built with Go and runs as a Docker action. github.com/Pradumnasara...
github.com
GitHub - Pradumnasaraf/agent-pr-police: GitHub Action that detects pull requests opened by AI coding agents, labels them, and posts a summary of what they changed.
GitHub Action that detects pull requests opened by AI coding agents, labels them, and posts a summary of what they changed. - Pradumnasaraf/agent-pr-police
010
Pradumna Saraf @pradumnasaraf.dev · 13/07/2026
You can now deploy Docker containers directly on Vercel. I wrote a step-by-step guide showing how to deploy a Dockerfile on Vercel using a Golang application. Check it out: dev.to/pradumnasara... @docker.com @vercel.com
dev.to
Deploy a Dockerfile on Vercel
Yes, you heard it right, you can now run a Dockerfile on Vercel. Vercel was the go-to place where...
010
Pradumna Saraf @pradumnasaraf.dev · 09/07/2026
Tomorrow!
100
Pradumna Saraf @pradumnasaraf.dev · 03/07/2026
This book is different from any other one I've read. Recently, I was one of the technical reviewers for the book "Operational AI with Docker". This was my first time reviewing a book, and I loved it. There's something special about being part of a book from the early idea stage, watching it..
100
Pradumna Saraf @pradumnasaraf.dev · 01/07/2026
In Docker Compose, you can use post_start to run commands after your container starts. It's useful for things like fixing file permissions, creating folders, or running any one-time setup before your app is ready. @docker.com
Docker Compose example showing how to use `post_start` to run a command after a container starts, with a YAML snippet that changes ownership of the `/app/uploads` directory.
000
Pradumna Saraf @pradumnasaraf.dev · 22/06/2026
Rebuilding or pulling a new version of an image with the same name and tag can leave behind dangling images. Use the following command to list all dangling Docker images and reclaim disk space by removing them. @docker.com
A screenshot of a bash shell script displaying code and command-line interface elements.
000
Pradumna Saraf @pradumnasaraf.dev · 10/06/2026
AI coding agents are powerful, but they shouldn't have unrestricted access to your system. Learn how Docker sandboxes can provide a secure environment for running agents without compromising developer productivity. dev.to/pradumnasara...
dev.to
Run AI Coding Agents Safely with Docker Sandboxes
AI agents can run commands, modify files, and download files from untrusted sources directly on a...
641
Pradumna Saraf @pradumnasaraf.dev · 08/06/2026
Excited to share that I've been renewed as a Docker Captain! 🐳 It's been a crazy journey; learned a ton and made some great new friends along the way. Huge thanks to Eva and the Docker team (@docker.com), and the incredible Docker community for the continued trust and support.
A person wearing a captain's hat smiles at the camera. Text reads "Docker Captain 2026" with Docker logo and message about being awarded another year as Docker Captain.
000
Pradumna Saraf @pradumnasaraf.dev · 02/06/2026
Tomorrow!
Screenshot of an article titled "Run AI Coding Agents Safely with Docker Sandboxes" showing an illustrated banner with Docker and technology icons.
100
Pradumna Saraf @pradumnasaraf.dev · 19/05/2026
The Docker Compose environment variable support goes beyond just ${VAR}. Useful when you want safer configurations without hardcoding values. `:-` → use a default value (optional configuration) `:?` → stop with an error message (required values like secrets) @docker.com
A compose.yml file with example Docker Compose service configuration, including environment variables and default values with comments.
000
Pradumna Saraf @pradumnasaraf.dev · 12/05/2026
Check out my new blog on how to run Claude Code locally for free with Docker (@docker.com) Model Runner. dev.to/pradumnasara...
dev.to
Run Claude Code Locally for Free with Docker Model Runner
We know that the Claude Code is phenomenal for development and code. But we can easily run out of...
010
Pradumna Saraf @pradumnasaraf.dev · 07/05/2026
Tomorrow!
Image of a user running Claudecode with Docker model runner on a computer screen, showcasing the interface and code.
000
Pradumna Saraf @pradumnasaraf.dev · 27/04/2026
Two supply chain attacks. Same pattern. Trivy and KICS show how compromised credentials can turn trusted CI/CD pipelines into a delivery path for malicious artifacts. Docker shared an informative blog breaking down what actually happened: www.docker.com/blog/trivy-k... @docker.com
Screenshot of a Docker blog post titled "Trivy, KICS, and the shape of supply chain attacks so far in 2026," discussing supply chain security incidents and analysis.
000
Pradumna Saraf @pradumnasaraf.dev · 13/04/2026
Are you running out of tokens in OpenCode or Claude Code? Check out my recent guides on running them locally. I wrote official Docker guides on using OpenCode & Claude Code with Docker Model Runner. OpenCode: docs.docker.com/guides/openc... Claude Code: docs.docker.com/guides/claud...
Screenshot of Docker Docs page titled “Use OpenCode with Docker Model Runner,” showing a guide on connecting OpenCode to Docker Model Runner, with steps, prerequisites, and an acknowledgment crediting Pradumna Saraf.Screenshot of Docker Docs page titled “Use Claude Code with Docker Model Runner,” showing a guide on running Claude Code with Docker Model Runner, including steps, prerequisites, and an acknowledgment crediting Pradumna Saraf.
010
Pradumna Saraf @pradumnasaraf.dev · 06/04/2026
Use `stop_grace_period` to give your app time to shut down properly. When you stop a container, @Docker waits before force-killing it. This helps finish requests, save data, and avoid unexpected issues. @docker.com
Illustration of a compose.yml file showing a Docker Compose service named api using the image myapp with stop_grace_period: 20s configured.
000
Reposted by Pradumna Saraf
Docker @docker.com · 14/03/2026
Meet Pradumna Saraf. Docker Captain. Open source advocate. Community builder. In this spotlight, he shares his journey into containers and cloud-native, and what keeps him excited about the future of development. Read more: bit.ly/46WNUjF
021
Pradumna Saraf @pradumnasaraf.dev · 21/03/2026
Switching to a Docker Hardened Image (DHI) is a simple change. The Docker workflow remains the same, but the base image is built with fewer packages, reduced attack surface, and better security defaults. @docker.com
A dark-themed Dockerfile code snippet compares an original and a hardened version. The original uses "FROM node: 24," and the hardened uses "FROM dhi.io/node: 24."
110
Pradumna Saraf @pradumnasaraf.dev · 12/03/2026
In Docker Compose, you can use `cache_from` in the `build` section to reuse layers from an existing image and speed up builds This is especially useful in CI environments where a local build cache doesn’t exist. @docker.com
The code block window titled "compose.yml" shows YAML code for a Docker service. It features build context, Dockerfile, and cache settings.
021
Pradumna Saraf @pradumnasaraf.dev · 05/03/2026
Play with Docker is now deprecated and no longer available. If you’re looking for a simple browser-based Docker playground, you can use LabSpaces instead. It will spin up environments instantly and experiment with Docker without installing anything locally. @docker.com
010
Pradumna Saraf @pradumnasaraf.dev · 23/02/2026
In case you missed it, I wrote a new blog about Docker Compose profiles and how they let you enable or disable services based on what you actually need. Check it out: dev.to/pradumnasara...
dev.to
Using Profiles with Docker Compose
Most applications don’t need all Docker Compose services running all the time with the core...
000
Pradumna Saraf @pradumnasaraf.dev · 20/02/2026
If you are repeating the same config and environment variables across multiple Docker Compose files, use YAML anchors. You can define the config once and reuse it everywhere. This keeps your compose files cleaner, easier to update, and more maintainable. @docker.com
A dark-themed code editor displays a `compose.yml` file, which defines three Docker Compose services: `api`, `worker`, and `scheduler`. All three services share the same configuration for `image: myapp:latest`, `restart: unless-stopped`, `volumes: - .:/app`, and environment variables `NODE_ENV: production` and `LOG_LEVEL: info`. Their unique commands are `npm run api`, `npm run worker`, and `npm run scheduler`, respectively. A large red 'X' graphic is prominently featured in the top right corner of the editor window.A dark-themed code editor displays a Docker Compose file named `compose.yml`. The file defines a reusable `x-common` configuration block, which includes `restart: unless-stopped`, a volume mount of `.:/app`, and environment variables `NODE_ENV: production` and `LOG_LEVEL: info`. Below this, three services are defined: `api`, `worker`, and `scheduler`. Each service uses `myapp:latest` as its image, merges the `*common` configuration, and has a unique `npm run` command (e.g., `npm run api` for the api service). A prominent green checkmark icon is positioned in the top right corner of the window.
000
Pradumna Saraf @pradumnasaraf.dev · 02/02/2026
Check out my new blog on Docker Compose profiles and how they let you enable or disable services based on what you actually need: dev.to/pradumnasara... @docker.com
dev.to
Using Profiles with Docker Compose
In this setup, the backend, frontend, and database form the core of the application and are started...
000
Pradumna Saraf @pradumnasaraf.dev · 21/01/2026
I'll write a short blog on Docker Compose profiles and publish it soon!
100
Pradumna Saraf @pradumnasaraf.dev · 20/01/2026
I'll write a short blog and publish it soon!
000
Pradumna Saraf @pradumnasaraf.dev · 16/01/2026
Being too rigid with tools can hold developers back from better solutions.
000
Pradumna Saraf @pradumnasaraf.dev · 12/01/2026
Did you know Docker Compose has profiles? You can keep heavy services like Prometheus and Grafana turned off by default, and only start them when you actually need monitoring. You can start them by running: docker compose --profile monitoring up @docker.com
Screenshot of a `compose.yml` file showing Docker Compose services with profiles. The `app` service runs by default, while `prometheus` and `grafana` services are configured with a `monitoring` profile and only run when that profile is enabled.
020
Pradumna Saraf @pradumnasaraf.dev · 06/01/2026
Check out my new blog on container security using Docker Hardened Images. I explain what they are, why they matter, and how they help reduce security risks in containers with a simple demo. dev.to/pradumnasara... @docker.com
dev.to
Improving Container Security with Docker Hardened Images
Container security remains a significant concern. Base images are bloated and contain unnecessary/or...
000
Pradumna Saraf @pradumnasaraf.dev · 22/12/2025
Huge respect to companies that maintain their SDKs along with up-to-date documentation. It’s not easy when APIs change frequently.
000
Pradumna Saraf @pradumnasaraf.dev · 21/12/2025
Tomorrow!
Blog editor showing the post “Improving Container Security with Docker Hardened Images,” featuring a Docker logo graphic, author avatar, and publish controls.
100
Pradumna Saraf @pradumnasaraf.dev · 17/12/2025
One of the biggest announcements from Docker (@docker.com) this year, at least for me: Docker Hardened Images (DHI) are now free for every developer. Making secure, minimal, production-ready images available to everyone changes how we think about container security.
A screenshot of the Docker Hub website's "Hardened Images" page. The left sidebar shows user "pradumnasaraf" with navigation links like Repositories, Hardened Images (selected), Collaborations, Settings, Billing, and Usage. The main content area features a banner titled "Docker Hardened Images" with the text "Choose secure, minimal, production-ready images. They're free to use." and a "How it works" button. Below this are a search bar, a "Filter by" dropdown, and a "Make a request" button. The page then displays sections for "Recently added" hardened images (Time MCP Server, MongoDB MCP Server, Memory MCP Server, Docker Hub MCP Server, Grafana MCP Server, GitHub MCP Server) and "Featured" images and Helm charts, including Dart (a hardened image) and Traefik Helm chart.
000
Pradumna Saraf @pradumnasaraf.dev · 11/12/2025
In case you missed it, I recently wrote about how you can run LLMs with Docker Compose using Docker Model Runner to speed up your AI development. Check it out here: dev.to/pradumnasara...
dev.to
Running AI Models with Docker Compose
Docker Compose has completely changed the game in how we run and connect a multi-service application....
000
Pradumna Saraf @pradumnasaraf.dev · 10/12/2025
Using the "-ft" flag with Docker logs helps you follow the logs and monitor the output of a running container in real-time. Otherwise, without the flag, you have to keep typing the log command to get output. "-f" is for follow, and "-t" is for timestamps. @docker.com
000
Pradumna Saraf @pradumnasaraf.dev · 05/12/2025
People used to fight over JavaScript frameworks. That still happens, just quieter. Now the fight is between LLM models, and it is a very expensive one.
000
Pradumna Saraf @pradumnasaraf.dev · 01/12/2025
Exciting news! I’m honoured to share that I am officially a Microsoft MVP in DevOps! 🎉 I didn’t see this coming. People inside and outside the program say the award is like the “Oscars of tech,” and I’m truly grateful to Microsoft (@microsoft.com) for recognising me. #mvpbuzz
Clear glass and blue acrylic MVP award with globe engraving. "Microsoft Most Valuable Professional 2025" text. Recognizes technical contributions.Blue crystal award with "MVP" logo for Microsoft Most Valuable Professional. Date "2025" on a clear base. The trophy sits on a wooden surface.
020
Pradumna Saraf @pradumnasaraf.dev · 26/11/2025
Hacktoberfest is over, but spam PRs are not.
GitHub pull request page showing a proposed change to introduction.md, adding "Akobir" to a list. The pull request is open and titled "Update introduction.md to include 'Akobir' #117".
000
Pradumna Saraf @pradumnasaraf.dev · 24/11/2025
Thank you, @aerabi.com, for gifting a copy of your newly published book, Docker and Kubernetes Security, and for bringing it all the way from Germany to Istanbul. I will go through it soon. If you want to learn @docker.com and Kubernetes security, I highly recommend this book.
A hand holds a blue book cover titled "Docker Kubernetes Security" by Mohammad-Ali A'râbi. The top left features the "DS DockerSecurity.io" logo and website, with "[v1.0.0]" on the top right. A white square with a plus sign is positioned between "Docker" and "Kubernetes" in the main title. Below, it details "Supply Chain Security + Runtime Protection" alongside a stylized white and light blue whale tail design. The author's name, "Mohammad-Ali A'râbi", is prominent at the bottom, with "Forewords by Hamida Rebai and Liran Tal" beneath it. A black keyboard is partially visible below the book, against a vibrant, blurred orange and red background.A white piece of paper features a handwritten dedication in blue ink at the top, reading "To the best Captain in India," followed by the signature "Mohammad-Ali." Below this, printed in a gothic-style font, is the title "Docker and Kubernetes Security." Underneath the title is a black illustration of a stylized archer, possibly a man, riding a lion-like mythological creature with a bow and arrow. The paper is placed in front of a computer monitor displaying a vibrant, blurry red and orange abstract wallpaper with a row of indistinct application icons at the bottom.
151
Pradumna Saraf @pradumnasaraf.dev · 18/11/2025
One of the unexpected things that happened at Docker Summit in Istanbul was that I won the Most Active Docker Captain award. It was a weird and happy moment because going from just passionately using Docker to actually winning an award from them feels like a full-circle moment. @docker.com
An awards ceremony where a young man in a black "CAPTAIN SUMMIT" t-shirt and jeans accepts a blue plaque from a young woman, also in a "CAPTAIN SUMMIT" t-shirt and light jeans, who holds a microphone. Behind them, a projector screen displays "Congratulations!" and a photo of the man, identified as "Pradumna Saraf."A clear glass plaque stands on a light wooden desk. Etched onto the glass are the words "Tip o' the Captain's Hat" above a circular emblem featuring a cartoon bird wearing a captain's hat, flanked by stylized wings. Below the emblem, the words "-docker- Captains" are etched. The background includes a light wall and a blurred dark monitor to the right.
100
Pradumna Saraf @pradumnasaraf.dev · 18/11/2025
One of the unexpected things that happened at Docker Summit in Istanbul was that I won the Most Active Docker Captain award. It was a weird and happy moment because going from just passionately using Docker to actually winning an award from them feels like a full-circle moment. @docker.com
A clear glass plaque stands on a light wooden desk. Etched onto the glass are the words "Tip o' the Captain's Hat" above a circular emblem featuring a cartoon bird wearing a captain's hat, flanked by stylized wings. Below the emblem, the words "-docker- Captains" are etched. The background includes a light wall and a blurred dark monitor to the right.
100
Pradumna Saraf @pradumnasaraf.dev · 12/11/2025
You can define multiple AI models in Docker Compose. For example, if your app uses an LLM for chat and an embedding model for semantic search, both can be declared together in one file. No need to run models separately and then use them in your compose app. @docker.com
A screenshot of a `compose.yml` configuration file displayed in a code editor. The file defines a `services` section with an `app` service that uses the `my-app` image and requires `llm` and `embedding-model`. Below this, a `models` section specifies `llm` as `ai/smollm2` and `embedding-model` as `ai/all-minilm`.
000
Pradumna Saraf @pradumnasaraf.dev · 05/11/2025
Docker Captains Summit 2025 in Istanbul🇹🇷 was an incredible experience! Over 50 Captains from 20+ countries came together for amazing discussions, cultural exchanges, and ideas to make Docker even better. Huge thanks to the Docker DevRel team for organising everything so smoothly!
110