Docker

codewithmukesh/dotnet-claude-kit/skills/docker

作者 codewithmukesh23300897f4d1無授權條款754 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫2 個月前更新

Docker containerization for .NET 10 applications. Covers multi-stage builds, .NET container images, non-root user configuration, health checks, and .dockerignore. Load this skill when containerizing an application with a Dockerfile, optimizing image size, setting up Docker Compose for local development, or when the user mentions "Docker", "Dockerfile", "container", "docker-compose", "image", "multi-stage", "non-root", ".dockerignore", or "container health check". For Dockerfile-less SDK publishing (`dotnet publish /t:PublishContainer`), load the container-publish skill instead.

僅含說明DevOps & Cloud
AI 產生的概覽

為 .NET 10 應用提供 Docker 容器化指引:多階段 Dockerfile、非 root 使用者、健康探測與 Compose。

功能
此技能為使用 Docker 容器化 .NET 10 應用提供參考指引。內容涵蓋多階段 Dockerfile 模式、.NET SDK 與 ASP.NET 執行階段映像、非 root 使用者設定、用於 NuGet 還原的層快取、.dockerignore 內容、健康探測方式,以及供本機開發使用的 Docker Compose。它也列出反模式,例如在執行階段使用 SDK 映像、在還原前複製原始碼,以及以 root 身分執行。
適用情境
在為 .NET 應用撰寫或審查 Dockerfile、最佳化映像大小、設定本機開發用的 Docker Compose,或設定容器健康檢查時使用。當使用者提到 Docker、Dockerfile、container、docker-compose、multi-stage、non-root、.dockerignore 或容器健康檢查時也適用。
執行需求
此技能未附帶指令碼或資源,僅為說明性指示。依其範例操作需要 Docker、.NET 10 SDK 與 ASP.NET 執行階段映像;若使用協調層健康探測,還需要 Docker Compose 或 Kubernetes。

Docker

Core Principles

  1. Multi-stage builds always — Separate build and runtime stages. Build in the SDK image, run in the ASP.NET runtime image.
  2. Non-root by default — .NET container images support USER app by default since .NET 8. Never run as root in production.
  3. Layer caching matters — Copy .csproj files and restore before copying source code. This caches NuGet dependencies across builds.
  4. Health probes at the orchestrator level — Expose a /health/live endpoint and let Kubernetes/Compose probe it. Chiseled and default aspnet images have no shell or curl, so in-image HEALTHCHECK commands have nothing to run with.

Patterns

Multi-Stage Dockerfile for Web API

dockerfile
# Stage 1: BuildFROM mcr.microsoft.com/dotnet/sdk:10.0 AS buildWORKDIR /src
# Copy project files and restore (cached layer)COPY ["src/MyApp.Api/MyApp.Api.csproj", "src/MyApp.Api/"]COPY ["src/MyApp.Domain/MyApp.Domain.csproj", "src/MyApp.Domain/"]COPY ["Directory.Build.props", "."]COPY ["Directory.Packages.props", "."]RUN dotnet restore "src/MyApp.Api/MyApp.Api.csproj"
# Copy everything and buildCOPY . .RUN dotnet publish "src/MyApp.Api/MyApp.Api.csproj" \    -c Release \    -o /app/publish \    --no-restore
# Stage 2: RuntimeFROM mcr.microsoft.com/dotnet/aspnet:10.0 AS runtimeWORKDIR /app
# Non-root user (default in .NET 8+ images)USER app
COPY --from=build /app/publish .
EXPOSE 8080
ENTRYPOINT ["dotnet", "MyApp.Api.dll"]

Container Health Probes

Prefer orchestrator-level probes (Kubernetes livenessProbe, Compose healthcheck) over a Dockerfile HEALTHCHECK — the standard aspnet and chiseled images ship no shell, no curl, and no wget, so there is nothing inside the container to run the probe with. Point the orchestrator at /health/live:

yaml
# docker-compose — probe from outside the app processservices:  api:    healthcheck:      test: ["CMD-SHELL", "wget -qO- http://localhost:8080/health/live || exit 1"]      interval: 30s      timeout: 3s      retries: 3# Note: CMD-SHELL requires a shell + wget in the image. Use a non-chiseled# variant for this, or better: let Kubernetes httpGet probes do it —# they run from the kubelet, needing nothing inside the image.

If you must have an in-image HEALTHCHECK, base the runtime stage on a non-chiseled image that includes wget — never re-run the app binary as the probe command; that starts a second instance instead of checking the first.

.dockerignore

**/.git**/.vs**/bin**/obj**/node_modules**/Dockerfile***/docker-compose***/tests

Docker Compose for Local Development

Key .NET-specific concerns — pass connection strings via environment, use depends_on with health checks:

yaml
services:  api:    build:      context: .      dockerfile: src/MyApp.Api/Dockerfile    ports:      - "5000:8080"    environment:      - ASPNETCORE_ENVIRONMENT=Development      - ConnectionStrings__Default=Host=postgres;Database=myapp;Username=postgres;Password=postgres      - ConnectionStrings__Redis=redis:6379    depends_on:      postgres:        condition: service_healthy  # Add postgres/redis services with healthcheck — standard boilerplate

Optimized Build with .slnx

For solutions with multiple projects, restore only the necessary projects.

dockerfile
FROM mcr.microsoft.com/dotnet/sdk:10.0 AS buildWORKDIR /src
# Copy solution and all project filesCOPY *.slnx .COPY Directory.Build.props .COPY Directory.Packages.props .COPY src/**/*.csproj ./src/
# Restore project structureRUN for file in src/**/*.csproj; do \    mkdir -p $(dirname $file) && mv $file $(dirname $file)/; \    doneRUN dotnet restore
COPY . .RUN dotnet publish src/MyApp.Api -c Release -o /app/publish --no-restore

Health Check Endpoint

csharp
// In Program.cs — lightweight health endpoint for Dockerapp.MapGet("/health/live", () => Results.Ok("healthy"))    .ExcludeFromDescription();

Anti-patterns

Don't Use SDK Image for Runtime

dockerfile
# BAD — SDK image is 900MB+, includes compilersFROM mcr.microsoft.com/dotnet/sdk:10.0COPY . .RUN dotnet run
# GOOD — separate build and runtime, runtime image is ~200MBFROM mcr.microsoft.com/dotnet/aspnet:10.0

Don't Copy Everything Before Restore

dockerfile
# BAD — any source change invalidates the NuGet cacheCOPY . .RUN dotnet restore
# GOOD — copy only project files first, then restoreCOPY ["src/MyApp.Api/MyApp.Api.csproj", "src/MyApp.Api/"]RUN dotnet restore "src/MyApp.Api/MyApp.Api.csproj"COPY . .

Don't Run as Root

dockerfile
# BAD — running as root (security risk)FROM mcr.microsoft.com/dotnet/aspnet:10.0COPY --from=build /app .ENTRYPOINT ["dotnet", "MyApp.Api.dll"]
# GOOD — use the built-in non-root userFROM mcr.microsoft.com/dotnet/aspnet:10.0USER appCOPY --from=build /app .ENTRYPOINT ["dotnet", "MyApp.Api.dll"]

Decision Guide

ScenarioRecommendation
Web API containerMulti-stage build with aspnet runtime image
Worker serviceMulti-stage build with dotnet/runtime image
Local developmentDocker Compose with service dependencies
CI buildsMulti-stage build (self-contained)
Image size optimizationUse Alpine variant + trimming for small images
Health monitoring/health endpoint + orchestrator probe (K8s httpGet / Compose healthcheck)
SecretsEnvironment variables or mounted secrets, never in image

來源與署名

來源:codewithmukesh/dotnet-claude-kit位於skills/docker提交2330089

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 codewithmukesh/dotnet-claude-kit 的技能

Wrap Up

codewithmukesh

在 session 結束時把已完成工作、待辦事項與經驗寫入交接檔案,並在 session 開始時重新載入。

Productivity & Workflow7542 個月前更新

Workflow Mastery

codewithmukesh

Claude Code workflow mastery for .NET developers. Covers parallel execution with git worktrees, plan mode strategy, verification loops, auto-formatting hooks, permission setup for dotnet CLI, prompting techniques, subagent patterns, and context discipline — token budget management, MCP-first navigation, lazy loading, and subagent isolation — all adapted for the .NET ecosystem. Load this skill when setting up Claude Code for a .NET project, optimizing workflows, running parallel sessions, when context is running low or sessions feel sluggish, when exploring a large codebase efficiently, or when the user mentions "productivity", "workflow", "parallel", "worktree", "plan mode", "permissions", "hooks", "10x", "setup Claude Code", "speed up development", "context", "tokens", "budget", "running out of context", "too many files", or "large codebase". Inspired by tips from Boris Cherny (creator of Claude Code) and the Anthropic team.

待分類7542 個月前更新

Vertical Slice

codewithmukesh

指導 .NET 開發者以垂直切片架構組織應用程式,涵蓋功能資料夾、端點分組與處理常式模式。

Software Development7542 個月前更新

Testing

codewithmukesh

Testing strategy for .NET 10 applications. Covers xUnit v3, WebApplicationFactory for integration tests, Testcontainers for real database testing, Verify for snapshot testing, and the AAA pattern. Load this skill when writing tests, setting up test infrastructure, reviewing test coverage, or when the user mentions "test", "xUnit", "WebApplicationFactory", "Testcontainers", "integration test", "unit test", "bUnit", "snapshot test", "Verify", "test coverage", "AAA pattern", "WireMock", or "FakeTimeProvider".

待分類7542 個月前更新

Tdd

codewithmukesh

Guided test-driven development workflow for .NET 10 using xUnit v3, WebApplicationFactory, Testcontainers, and Verify snapshots. Follows the strict red-green-refactor cycle. Use when: "TDD", "test-driven", "let's TDD this", "red green refactor", "write the test first", or when building a feature with clear acceptance criteria.

待分類7542 個月前更新

Spec

codewithmukesh

透過結構化提問,把模糊的功能想法轉化為雙方確認並持久化的規格文件。

Productivity & Workflow7542 個月前更新