Agent skill

SDK Container Publishing

by Aaronontheweb in Aaronontheweb/dotnet-skills

Publish .NET services as container images with the built-in SDK tooling (dotnet publish /t:PublishContainer, Microsoft.NET.Build.Containers) - no Dockerfile required.

MITAuto-check passedDevOps & Cloud

Install SDK Container Publishing

skills CLI
$ npx skills add Aaronontheweb/dotnet-skills --skill sdk-container-publishing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Aaronontheweb/dotnet-skills sdk-container-publishing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Aaronontheweb/dotnet-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sdk-container-publishing .claude/skills/sdk-container-publishing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sdk-container-publishing
GitHub stars
1.2k
Token cost
~1.9k tokens
SKILL.md length
782 words
Files
6 (incl. references)
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Publish .NET services as container images with the built-in SDK tooling (dotnet publish /t:PublishContainer, Microsoft.NET.Build.Containers) - no Dockerfile required.

  • Tasks that involve Containers
  • SKILL.md covers When to Use This Skill, What This Is, The Three Output Modes and Key Facts, plus 6 more sections
  • Calls dotnet, docker and podman
  • Tasks that involve CI/CD

What it does

SDK Container Publishing is an agent skill from Aaronontheweb/dotnet-skills. Publish .NET services as container images with the built-in SDK tooling (dotnet publish /t:PublishContainer, Microsoft.NET.Build.Containers) - no Dockerfile required. Covers the MSBuild property surface, base-image inference, self-contained and AOT implications, and CI/CD publishing.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/ci-cd.md`, `references/property-reference.md` and `references/real-world-examples.md`).

It sits in DevOps & Cloud, covering Containers and CI/CD. It works with .NET and Docker. The repository describes itself as: Claude Code skills and sub-agents for .NET Developers. The licence is MIT.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve CI/CD

Example prompts

  • “/sdk-container-publishing”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 46003af. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet
    • docker
    • podman

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

SDK Container Publishing loads about 1.9k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 77 tokens; SKILL.md has 782 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Aaronontheweb/dotnet-skills at commit 46003af, republished under its MIT licence (© Aaronontheweb). 782 words, ~1,875 tokens.

Download SKILL.mdSave it as .claude/skills/sdk-container-publishing/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
sdk-container-publishing
description
Publish .NET services as container images with the built-in SDK tooling (dotnet publish /t:PublishContainer, Microsoft.NET.Build.Containers) - no Dockerfile required. Covers the MSBuild property surface, base-image inference, self-contained and AOT implications, and CI/CD publishing.
invocable
false

.NET SDK Container Publishing

When to Use This Skill

Use this skill when:

  • You want a container image for a .NET service and do not want to hand-write a Dockerfile
  • You want to know how to tag, name, or expose ports on an SDK-built image without a Dockerfile
  • You are wiring container publishing into CI / CD or a release pipeline
  • An SDK-built image pushes to the wrong registry, gets the wrong tag, or picks the wrong base image
  • You need a tarball of an image for scanning or air-gapped loading

Do not use it when:

  • You need a RUN step or arbitrary layer customization in the image. The SDK tooling cannot emulate RUN; write a Dockerfile instead.

What This Is

Since .NET 7, dotnet publish builds a container image natively. The Microsoft.NET.Build.Containers tooling ships with the SDK, so no Dockerfile is required and no Docker install is needed to produce an image. Docker or Podman is only required to run the image locally. This is documented in the containerize with dotnet publish tutorial.

The quickest path is one command:

bash
dotnet publish /t:PublishContainer -c Release

That compiles the app and emits an image in one step. The image name defaults to the project's AssemblyName. Override it with ContainerRepository (renamed from ContainerImageName in earlier versions - see the sdk-container-builds customization notes).

The Three Output Modes

The tooling writes the image in one of three ways. Pick based on where the image ends up.

ModeWhen to use
Local daemon (default)Local dev. Pushes to the running Docker or Podman daemon with no extra config.
TarballYou want a file to scan, transfer, or load later. Set ContainerArchiveOutputPath to a .tar.gz path, then docker load -i or podman load -i. Useful in security scanning workflows.
Registry pushShipping. Set ContainerRegistry (for example ghcr.io or an internal registry) and the image is pushed directly.

See the containerize a .NET app reference for the full property surface.

Key Facts

  • No Docker required to build. The SDK creates the image itself; a runtime is only needed to run it. See the SDK publish tutorial.
  • Image name defaults to AssemblyName. Set ContainerRepository to override.
  • Base image is inferred. Self-contained projects get mcr.microsoft.com/dotnet/runtime-deps, ASP.NET Core gets dotnet/aspnet, other apps get dotnet/runtime, tagged for the TFM. Since SDK 8.0.200 the inference is size and security aware: musl RIDs pick Alpine variants, PublishAot=true picks the chiseled AOT runtime-deps variant. See the base image inference notes.
  • The .NET 10 SDK tags images latest, not the version. If your publish relies on the version tag you must set ContainerImageTag explicitly. This is a real footgun in CI - see the tag drift entry in references/troubleshooting.md.
  • Windows images need an explicit base image. Microsoft no longer includes Windows variants in the manifest list. To target Windows, set ContainerBaseImage to a specific nanoserver tag (for example mcr.microsoft.com/dotnet/aspnet:8.0-nanoserver-ltsc2022). See the Windows note.
  • Multi-architecture images come from ContainerRuntimeIdentifiers (semicolon-delimited, a subset of RuntimeIdentifiers). The output is an OCI image index. Supported from SDK 8.0.405, 9.0.102, and 9.0.2xx onward.
  • Insecure registries are passed via the DOTNET_CONTAINER_INSECURE_REGISTRIES env var (comma-separated) starting in SDK 9.0.100. Since .NET 8.0.400 the SDK reads standard Docker / Podman config to decide HTTP vs HTTPS.
Show full SKILL.md (258 more words)Show less

The Minimal Property Set (the pattern we use)

Most of our services only override what they need and let the SDK infer the rest. A minimal csproj looks like this:

xml
<Project Sdk="Microsoft.NET.Sdk.Web">
  <PropertyGroup>
    <TargetFramework>net10.0</TargetFramework>
    <ContainerRepository>my-service</ContainerRepository>
    <ContainerImageTags>$(VersionPrefix);latest</ContainerImageTags>
  </PropertyGroup>

  <ItemGroup>
    <ContainerPort Include="8080" Type="tcp" />
  </ItemGroup>
</Project>

Notes:

  • No ContainerRegistry, no ContainerBaseImage, no ContainerUser. The SDK defaults these correctly for most ASP.NET services.
  • ContainerPort items expose ports without a Dockerfile.
  • Tags follow semver: the package version plus a floating latest.

For the full property catalog, see references/property-reference.md.

CI / CD Publishing

In CI, publish against a registry and tag with the release name. The tag-driven pattern we use:

bash
dotnet publish src/MyService/MyService.csproj \
  -p:VersionPrefix=${{ github.ref_name }} \
  -p:ContainerRegistry=docker.example.internal \
  -p:ContainerImageTag=${{ github.ref_name }} \
  -c Release /t:PublishContainer

Note ContainerImageTag is set explicitly because the SDK defaults to latest, not the version. See references/ci-cd.md for the full workflow and registry auth notes.

If you centralize image settings across a repo, put them in a Directory.Build.props with CI conditionals. We do this for version tags, labels, and the ContainerPublishInParallel=false anti-race flag. See references/real-world-examples.md.

Troubleshooting

The common failures (tag drift, wrong image name or registry, unavailable RUN, no daemon on the build host, insecure registry rejection, parallel-publish races, and multi-target publishing) are covered in depth in references/troubleshooting.md. Ask the reader to consult it rather than duplicating the full text here; the short version is: set ContainerImageTag explicitly, set ContainerRepository and ContainerRegistry explicitly, and use ContainerArchiveOutputPath when no daemon is available.

Self-Contained and AOT

Self-contained projects default to the runtime-deps base image. AOT projects get a chiseled AOT runtime-deps variant for smaller, more secure images. See references/self-contained-and-aot.md.

Verification

Confirm the image built and exists:

bash
# Image in the local daemon
docker images | grep <repository>

# Tarball produced
ls -la <ContainerArchiveOutputPath>

# Push succeeded (registry mode)
docker pull <ContainerRegistry>/<ContainerRepository>:<tag>
  • dotnet-skills:testcontainers - running containers in tests
  • dotnet-skills:aot-trimming - AOT and trimming, relevant to base-image selection

© Aaronontheweb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/sdk-container-publishing of Aaronontheweb/dotnet-skills.

  • SKILL.md
  • references/ci-cd.md
  • references/property-reference.md
  • references/real-world-examples.md
  • references/self-contained-and-aot.md
  • references/troubleshooting.md

Open the folder on GitHubat commit 46003af

Compare with similar skills

SDK Container Publishing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

SDK Container Publishing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
SDK Container Publishing this skillAaronontheweb/dotnet-skills1.2k—~1.9kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
GitHub Actions CreatorFNOSP/FlyNarwhal5091 repos~2.4kAutomated safety check: PassAGPL-3.0
Dockerfile And Readme Templatingdotnet/dotnet-docker4.9k—~563Automated safety check: PassMIT
Swig CI Reproswig/swig6.3k—~1.2kAutomated safety check: PassCustom licence
Porting Changesdotnet/dotnet-docker4.9k—~781Automated safety check: PassMIT

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • GitHub Actions Creator

    FNOSP/FlyNarwhal

    A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.

    509 GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Official

    Modify Cottle templates that generate Dockerfiles and READMEs in dotnet/dotnet-docker.

    4.9k GitHub stars~563 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Swig CI Repro

    swig/swig

    Reproduce a GitHub Actions Linux CI failure locally when it does not happen on your machine: a podman/docker image that mirrors the ubuntu-22.04 runner by reusing the real Tools/CI-linux-.sh install…

    6.3k GitHub stars~1.2k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Porting Changes

    dotnet/dotnet-docker

    Official

    Plan and move changes between branches in dotnet/dotnet-docker.

    4.9k GitHub stars~781 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed

More from Aaronontheweb/dotnet-skills

All 35 skills in this repo
  • .NET Trimming and Native AOT

    Aaronontheweb/dotnet-skills

    Guides making .NET libraries trimming-safe and Native-AOT compatible: the MSBuild properties, trimming attributes, warning codes and a playbook of safe patterns.

    1.2k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Cscheck

    Aaronontheweb/dotnet-skills

    Write and simplify C property-based, model-based, and executable specification tests with CsCheck.

    1.2k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Akka.Hosting Actor Patterns

    Aaronontheweb/dotnet-skills

    Shows how to build entity actors with Akka.Hosting so the same code runs in local unit tests and in a sharded cluster in production.

    1.2k GitHub starsUsed in 1 repo~5k tokens
    Auto-check passed
  • Akka.NET Best Practices

    Aaronontheweb/dotnet-skills

    Guidance for Akka.NET actor systems covering EventStream versus DistributedPubSub, supervision, Props versus DependencyResolver, work distribution and testable cluster code.

    1.2k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Akka.NET Management and Discovery

    Aaronontheweb/dotnet-skills

    Sets up Akka.Management and Cluster.Bootstrap so Akka.NET clusters form through service discovery on Kubernetes, Azure or config instead of static seed nodes.

    1.2k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Akka.NET Testing Patterns

    Aaronontheweb/dotnet-skills

    Shows how to test Akka.NET actors with Akka.Hosting.TestKit: swapping services for fakes, using TestProbes, and checking persistence, plus when the older TestKit still fits.

    1.2k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed

Works with

Categories

Questions about SDK Container Publishing

What does SDK Container Publishing do?

Publish .NET services as container images with the built-in SDK tooling (dotnet publish /t:PublishContainer, Microsoft.NET.Build.Containers) - no Dockerfile required. SDK Container Publishing is an agent skill from Aaronontheweb/dotnet-skills.Containers) - no Dockerfile required.

When should I use SDK Container Publishing?

SDK Container Publishing fits situations like: tasks that involve Containers; tasks that involve CI/CD.

How do I install SDK Container Publishing in Claude Code?

Run `npx skills add Aaronontheweb/dotnet-skills --skill sdk-container-publishing -a claude-code`. Or copy the skill folder (skills/sdk-container-publishing in Aaronontheweb/dotnet-skills) into .claude/skills/sdk-container-publishing in your project. Claude Code loads it when a task matches its description.

How do I install SDK Container Publishing in Codex?

Run `npx skills add Aaronontheweb/dotnet-skills --skill sdk-container-publishing -a codex`. Or copy the skill folder (skills/sdk-container-publishing in Aaronontheweb/dotnet-skills) into .agents/skills/sdk-container-publishing in your project. Codex loads it when a task matches its description.

Can I use SDK Container Publishing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Aaronontheweb/dotnet-skills --skill sdk-container-publishing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdk-container-publishing, .gemini/skills/sdk-container-publishing, .github/skills/sdk-container-publishing and .opencode/skills/sdk-container-publishing in your project.

What does SDK Container Publishing need to run?

Going by SKILL.md and its folder, SDK Container Publishing needs the command-line tools its instructions call (dotnet, docker and podman). Our summary lists: Docker.

Does SDK Container Publishing access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is SDK Container Publishing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does SDK Container Publishing use?

SDK Container Publishing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does SDK Container Publishing use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.7k tokens, read only when the agent opens those files.

What are the alternatives to SDK Container Publishing?

Skills that share tags, products or a category with SDK Container Publishing: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), GitHub Actions Creator (FNOSP/FlyNarwhal, 509 stars), Dockerfile And Readme Templating (dotnet/dotnet-docker, 4.9k stars) and Swig CI Repro (swig/swig, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains SDK Container Publishing?

Aaronontheweb (a GitHub user) maintains it in Aaronontheweb/dotnet-skills, which has 1,206 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 10, 2026.

Source: Aaronontheweb/dotnet-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.