Install
$ agentstack add skill-thienanblog-awesome-ai-agent-skills-vps-docker-traefik-deploy ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
VPS Docker Traefik Deploy
Overview
Use this skill to turn an application stack into a real production deployment plan with secure host setup, reverse proxying, registry-based releases, private admin access, persistent storage, backups, and rollback.
Prefer Ubuntu LTS or Debian stable. Prefer immutable image tags. Prefer Traefik for public ingress and SSH tunnels for admin-only access.
Workflow
- Establish facts before changing anything.
- Minimize the public network surface.
- Baseline the host with a non-root operator account.
- Install Docker from the official stable channel.
- Deploy Traefik separately from the app stack.
- Keep state outside container writable layers.
- Deploy app images by pull, not by rebuilding on the server.
- Validate health, backup, restore, rollback, and pruning.
Establish Facts
Confirm these points first:
- operating system and version
- public domains and subdomains
- TLS strategy: HTTP challenge or DNS challenge
- public services: website, API, websocket, admin UI, registry
- private services: database, Redis, dashboards
- registry type: managed or self-hosted
- persistent data locations
- backup destination and retention
- restore expectations
- whether a single VPS is still acceptable
If the project already has deployment docs, read them first and treat them as the application-specific contract.
Public Exposure Rules
Default public ports:
22/tcpfor SSH80/tcpfor HTTP redirect and ACME when needed443/tcpfor HTTPS
Keep these private unless there is a strong reason:
- Traefik dashboard
- MariaDB or PostgreSQL
- Redis
- private registry
- app service ports that can sit behind Traefik
- internal admin tools
If a GUI tool is required, bind the service to 127.0.0.1 only and use an SSH tunnel from the operator workstation.
Output Requirements
When using this skill, produce a deployment answer that includes:
- target topology
- exact public ports
- folder layout
- user and permission model
- Docker and Traefik install method
- DNS record plan
- Traefik routing plan
- registry flow
- persistent data plan
- storage growth plan
- backup and restore plan
- rollout and rollback commands
Mandatory Guardrails
- Do not recommend public exposure of database, Redis, registry, or proxy dashboards by default.
- Do not recommend deploying as the host root account.
- Do not recommend mutable
latesttags for production. - Do not keep important state only inside container writable layers.
- Do not call a plan complete unless backup and rollback are addressed.
Reference Files
Read these files only when needed:
- [references/server-baseline.md](references/server-baseline.md)
Use for Ubuntu 24.04 host prep, non-root users, SSH hardening, swap, firewall, Docker install.
- [references/traefik-dns.md](references/traefik-dns.md)
Use for Traefik layout, dashboard tunneling, DNS, subdomains, Cloudflare, and routing patterns.
- [references/registry-storage-backup.md](references/registry-storage-backup.md)
Use for private registries, image retention, bind mounts versus volumes, S3-compatible storage, backup, restore, and cleanup.
- [references/deploy-checklist.md](references/deploy-checklist.md)
Use for rollout steps, post-deploy verification, rollback, and maintenance cadence.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: thienanblog
- Source: thienanblog/awesome-ai-agent-skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.