Learning from, understanding, and supporting DevOps artifacts for docker
Jordan Henkel, Christian Bird, Shuvendu K. Lahiri, Thomas W. Reps
Abstract
With the growing use of DevOps tools and frameworks, there is an increased need for tools and techniques that support more than code. The current state-of-the-art in static developer assistance for tools like Docker is limited to shallow syntactic validation. We identify three core challenges in the realm of learning from, understanding, and supporting developers writing DevOps artifacts: (i) nested languages in DevOps artifacts, (ii) rule mining, and (iii) the lack of semantic rule-based analysis. To address these challenges we introduce a toolset, binnacle, that enabled us to ingest 900,000 GitHub repositories. Focusing on Docker, we extracted approximately 178,000 unique Dockerfiles, and also identified a Gold Set of Dockerfiles written by Docker experts. We addressed challenge (i) by reducing the number of effectively uninterpretable nodes in our ASTs by over 80% via a technique we call phased parsing. To address challenge (ii), we introduced a novel rule-mining technique capable of recovering two-thirds of the rules in a benchmark we curated. Through this automated mining, we were able to recover 16 new rules that were not found during manual rule collection. To address challenge (iii), we manually collected a set of rules for Dockerfiles from commits to the files in the Gold Set. These rules encapsulate best practices, avoid docker build failures, and improve image size and build latency. We created an analyzer that used these rules, and found that, on average, Dockerfiles on GitHub violated the rules five times more frequently than the Dockerfiles in our Gold Set. We also found that industrial Dockerfiles fared no better than those sourced from GitHub. The learned rules and analyzer in binnacle can be used to aid developers in the IDE when creating Dockerfiles, and in a post-hoc fashion to identify issues in, and to improve, existing Dockerfiles.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Shipwright: A Human-in-the-Loop System for Dockerfile RepairJordan Henkel, Denini Silva, Leopoldo Teixeira, Marcelo d'Amorim et al.ICSE 2021 · 31 citations
- Empirical Study of the Docker Smells Impact on the Image SizeThomas DurieuxICSE 2024 · 11 citations
- Fractal: Fault-Tolerant Shell-Script DistributionZhicheng Huang, Ramiz Dundar, Yizheng Xie, Konstantinos Kallas et al.NSDI 2026 · 4 citations
- Bugs in Pods: Understanding Bugs in Container Runtime SystemsJiongchi Yu, Xiaofei Xie, Cen Zhang, Sen Chen et al.ISSTA 2024 · 3 citations
- Dockerfile Flakiness: Characterization and RepairTaha Shabani, Noor Nashid, Parsa Alian, Ali MesbahICSE 2025 · 2 citations
Related papers
- Automatic Dockerfile Generation with Large Language ModelsJun Lyu, He Zhang, Yusong Yuan, Lanxin Yang et al.ICSE 2026
- Automating Dockerfile Refactoring to Multi-stage BuildsDongjin Chen, Wenhua Yang, Minxue Pan, Yu ZhouFSE 2026
- Refactorings and Technical Debt in Docker Projects: An Empirical StudyEmna Ksontini, Marouane Kessentini, Thiago do Nascimento Ferreira, Foyzul HassanASE 2021 · 17 citations
- DocCGen: Document-based Controlled Code GenerationSameer Pimparkhede, Mehant Kammakomati, Srikanth Tamilselvam, Prince Kumar et al.EMNLP 2024 · 4 citations
- Your Build Scripts Stink: The State of Code Smells in Build ScriptsMahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski et al.ASE 2025 · 1 citation
