Container Publishing (No Dockerfile)
Core Principles
- No Dockerfile needed — The .NET 10 SDK builds OCI-compliant container images directly from
dotnet publish /t:PublishContainer. No Dockerfile to write or maintain. - Chiseled images for production — Use
noble-chiseledbase images: no shell, no package manager, 7 Linux components vs 100+. Smallest attack surface. - Non-root by default — .NET 10 container images run as the
appuser automatically. Never override to root in production. - Configuration in the .csproj — All container settings are MSBuild properties, versioned with your project. No separate files to drift.
Patterns
Minimal Container Publish
No project file changes needed. Just publish:
This creates a container image in your local Docker daemon using the default aspnet:10.0 base image.
Production-Ready .csproj Configuration
Publishing to a Registry
Authenticate with docker login first, then specify the registry:
Multi-Architecture Images
Build images for multiple platforms with a single publish:
This produces an OCI Image Index — registries serve the correct architecture automatically.
Multiple Tags
Or in the project file:
Save as Tarball (No Docker Required)
No container runtime needed on the build machine. Useful for CI scanning:
Chiseled Image Variants
For Native AOT, the SDK auto-selects chiseled-aot:


