Writing and maintaining a Dockerfile for every .NET project is no longer necessary: the SDK can build the image by itself, using the project's information.
One command
dotnet publish -c Release --os linux --arch x64 -t:PublishContainer
The result is an image in the local container engine, named after the project. For web applications it works with no configuration; for console applications you enable it with the EnableSdkContainerSupport property.
Customising the image
<PropertyGroup>
<ContainerRepository>company/catalog-api</ContainerRepository>
<ContainerImageTags>1.4.0;latest</ContainerImageTags>
<ContainerFamily>noble-chiseled</ContainerFamily>
</PropertyGroup>
Chiseled images contain only the bare minimum needed to run the application: no shell, no package manager. They are smaller and offer far less attack surface.
Secure by default
Recent .NET images run the application as a non-privileged user and the default port is 8080, which does not require administrator permissions. These choices reduce the damage in case of a vulnerability.
Publishing to a registry
dotnet publish -c Release -t:PublishContainer \
-p:ContainerRegistry=registry.company.com \
-p:ContainerRepository=catalog-api
In continuous integration pipelines this removes a whole step: no Docker to install on the build agent to create the image, and the configuration lives in the project file, versioned together with the code.
Comments (0)
No comments yet.