loading experience

.NET

Containers for .NET apps without a Dockerfile

The .NET SDK builds container images directly with dotnet publish: smaller, non-root and with no file to maintain.

Containers for .NET apps without a Dockerfile

Writing and maintaining a Dockerfile for every .NET project is no longer necessary: the SDK can build the image by itself, using the project's information.

The SDK builds the image with no Dockerfile to maintain.
The SDK builds the image with no Dockerfile to maintain.

One command

dotnet publish -c Release --os linux --arch x64 -t:PublishContainer

The result is an image in the local container engine, named after the project. For web applications it works with no configuration; for console applications you enable it with the EnableSdkContainerSupport property.

Customising the image

<PropertyGroup>
  <ContainerRepository>company/catalog-api</ContainerRepository>
  <ContainerImageTags>1.4.0;latest</ContainerImageTags>
  <ContainerFamily>noble-chiseled</ContainerFamily>
</PropertyGroup>

Chiseled images contain only the bare minimum needed to run the application: no shell, no package manager. They are smaller and offer far less attack surface.

Secure by default

Recent .NET images run the application as a non-privileged user and the default port is 8080, which does not require administrator permissions. These choices reduce the damage in case of a vulnerability.

Publishing to a registry

dotnet publish -c Release -t:PublishContainer \
  -p:ContainerRegistry=registry.company.com \
  -p:ContainerRepository=catalog-api

In continuous integration pipelines this removes a whole step: no Docker to install on the build agent to create the image, and the configuration lives in the project file, versioned together with the code.

Comments (0)

No comments yet.

Leave a comment