Agent skill

Container Publish

by codewithmukesh in codewithmukesh/dotnet-claude-kit

Dockerfile-less containerization using the .NET 10 SDK container publishing feature.

MITAuto-check passedDevOps & Cloud

Install Container Publish

skills CLI
$ npx skills add codewithmukesh/dotnet-claude-kit --skill container-publish -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codewithmukesh/dotnet-claude-kit container-publish --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/container-publish .claude/skills/container-publish && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
container-publish
GitHub stars
751
Used in
1 other repo
Token cost
~1.8k tokens
SKILL.md length
342 words
Files
1
Skills in repo
47
Repo updated
First seen
Licence
MIT

At a glance

Dockerfile-less containerization using the .NET 10 SDK container publishing feature.

  • Works in 4 steps: No Dockerfile needed — The .NET 10 SDK… → Chiseled images for production — Use… → Non-root by default — .NET 10 container… → …
  • Wants to containerize without a Dockerfile
  • SKILL.md covers Core Principles, Patterns, Anti-patterns and Decision Guide
  • Calls dotnet, docker and az; needs GITHUB_TOKEN

What it does

Container Publish is an agent skill from codewithmukesh/dotnet-claude-kit. Dockerfile-less containerization using the .NET 10 SDK container publishing feature. Covers MSBuild properties, chiseled images, multi-arch builds, and registry publishing — all without writing a Dockerfile. Load this skill when the user wants to containerize without a Dockerfile, or mentions "dotnet publish container", "PublishContainer", "ContainerRepository", "ContainerFamily", "chiseled", "distroless", "container publish", "SDK container", "no Dockerfile", or "containerize without Docker".

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers. It works with Docker and .NET. The repository describes itself as: Make Claude Code a .NET 10 Expert. The licence is MIT.

When your agent uses it

  • Wants to containerize without a Dockerfile
  • Mentions dotnet publish container
  • PublishContainer
  • ContainerRepository

Example prompts

  • “dotnet publish container”
  • “PublishContainer”
  • “ContainerRepository”
  • “/container-publish”

Requirements

  • Docker
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. No Dockerfile needed — The .NET 10 SDK builds OCI-compliant container images directly from dotnet publish /t:PublishContainer. No…
  2. Chiseled images for production — Use noble-chiseled base images: no shell, no package manager, 7 Linux components vs 100+. Smallest attack…
  3. Non-root by default — .NET 10 container images run as the app user automatically. Never override to root in production.
  4. Configuration in the .csproj — All container settings are MSBuild properties, versioned with your project. No separate files to drift.

What it can do on your machine

Read from SKILL.md and the folder at commit 2330089. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet
    • docker
    • az
    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Container Publish loads about 1.8k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 342 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from codewithmukesh/dotnet-claude-kit at commit 2330089, republished under its MIT licence (© codewithmukesh). 342 words, ~1,844 tokens.

Download SKILL.mdSave it as .claude/skills/container-publish/SKILL.md (or your agent's skills folder).
name
container-publish
description
Dockerfile-less containerization using the .NET 10 SDK container publishing feature. Covers MSBuild properties, chiseled images, multi-arch builds, and registry publishing — all without writing a Dockerfile. Load this skill when the user wants to containerize without a Dockerfile, or mentions "dotnet publish container", "PublishContainer", "ContainerRepository", "ContainerFamily", "chiseled", "distroless", "container publish", "SDK container", "no Dockerfile", or "containerize without Docker".

Container Publishing (No Dockerfile)

Core Principles

  1. No Dockerfile needed — The .NET 10 SDK builds OCI-compliant container images directly from dotnet publish /t:PublishContainer. No Dockerfile to write or maintain.
  2. Chiseled images for production — Use noble-chiseled base images: no shell, no package manager, 7 Linux components vs 100+. Smallest attack surface.
  3. Non-root by default — .NET 10 container images run as the app user automatically. Never override to root in production.
  4. Configuration in the .csproj — All container settings are MSBuild properties, versioned with your project. No separate files to drift.

Patterns

Minimal Container Publish

No project file changes needed. Just publish:

bash
dotnet publish /t:PublishContainer --os linux --arch x64

This creates a container image in your local Docker daemon using the default aspnet:10.0 base image.

Production-Ready .csproj Configuration
xml
<Project Sdk="Microsoft.NET.Sdk.Web">

  <PropertyGroup>
    <TargetFramework>net10.0</TargetFramework>
    <ContainerRepository>mycompany/myapp-api</ContainerRepository>
    <ContainerFamily>noble-chiseled</ContainerFamily>
  </PropertyGroup>

  <ItemGroup>
    <ContainerPort Include="8080" Type="tcp" />
    <ContainerEnvironmentVariable Include="ASPNETCORE_HTTP_PORTS" Value="8080" />
    <ContainerEnvironmentVariable Include="DOTNET_EnableDiagnostics" Value="0" />
    <ContainerLabel Include="org.opencontainers.image.vendor" Value="MyCompany" />
  </ItemGroup>

</Project>
Publishing to a Registry

Authenticate with docker login first, then specify the registry:

bash
# GitHub Container Registry
docker login ghcr.io
dotnet publish /t:PublishContainer --os linux --arch x64 \
    -p ContainerRegistry=ghcr.io \
    -p ContainerImageTag=1.0.0

# Azure Container Registry
az acr login --name myregistry
dotnet publish /t:PublishContainer --os linux --arch x64 \
    -p ContainerRegistry=myregistry.azurecr.io

# Docker Hub (requires username prefix in repository)
dotnet publish /t:PublishContainer --os linux --arch x64 \
    -p ContainerRegistry=docker.io \
    -p ContainerRepository=myuser/myapp
Multi-Architecture Images

Build images for multiple platforms with a single publish:

xml
<PropertyGroup>
    <RuntimeIdentifiers>linux-x64;linux-arm64</RuntimeIdentifiers>
    <ContainerRuntimeIdentifiers>linux-x64;linux-arm64</ContainerRuntimeIdentifiers>
</PropertyGroup>
bash
dotnet publish /t:PublishContainer

This produces an OCI Image Index — registries serve the correct architecture automatically.

Multiple Tags
bash
# Bash — note the quoting for semicolons
dotnet publish /t:PublishContainer --os linux --arch x64 \
    -p ContainerImageTags='"1.0.0;latest"'

Or in the project file:

xml
<ContainerImageTags>1.0.0;latest</ContainerImageTags>
Save as Tarball (No Docker Required)

No container runtime needed on the build machine. Useful for CI scanning:

bash
dotnet publish /t:PublishContainer --os linux --arch x64 \
    -p ContainerArchiveOutputPath=./images/myapp.tar.gz

# Scan with Trivy before pushing
trivy image --input ./images/myapp.tar.gz
Chiseled Image Variants
ContainerFamilyUse CaseShellSize
(default)General purpose (Debian)Yes~220 MB
noble-chiseledProduction (no shell)No~110 MB
noble-chiseled-extraProduction with localization (ICU)No~120 MB
alpineSmall size, has shellYes~112 MB
xml
<!-- Standard chiseled (InvariantGlobalization=true) -->
<ContainerFamily>noble-chiseled</ContainerFamily>

<!-- Chiseled with ICU for localization -->
<ContainerFamily>noble-chiseled-extra</ContainerFamily>

For Native AOT, the SDK auto-selects chiseled-aot:

xml
<PublishAot>true</PublishAot>
<!-- SDK picks runtime-deps:10.0-noble-chiseled-aot automatically -->
CI/CD with GitHub Actions
yaml
jobs:
  publish:
    runs-on: ubuntu-latest
    permissions:
      packages: write
    steps:
      - uses: actions/checkout@v5
      - uses: actions/setup-dotnet@v5
        with:
          dotnet-version: '10.0.x'
      - uses: docker/login-action@v3
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}
      - run: |
          dotnet publish src/MyApp.Api/MyApp.Api.csproj \
            /t:PublishContainer --os linux --arch x64 \
            -p ContainerRegistry=ghcr.io \
            -p ContainerRepository=${{ github.repository_owner }}/myapp \
            -p ContainerImageTag=${{ github.sha }}

Anti-patterns

Don't Use the Deprecated Property Names
xml
<!-- BAD — ContainerImageName is deprecated -->
<ContainerImageName>myapp</ContainerImageName>

<!-- GOOD — use ContainerRepository -->
<ContainerRepository>myapp</ContainerRepository>
Don't Use PublishProfile=DefaultContainer
bash
# BAD — old approach, inconsistent across project types
dotnet publish -p:PublishProfile=DefaultContainer

# GOOD — use the MSBuild target directly
dotnet publish /t:PublishContainer
Don't Forget to Target Linux
bash
# BAD on Windows — may produce a Windows container
dotnet publish /t:PublishContainer

# GOOD — explicitly target Linux
dotnet publish /t:PublishContainer --os linux --arch x64
Don't Skip Authentication Before Push
bash
# BAD — fails with CONTAINER1013 error
dotnet publish /t:PublishContainer -p ContainerRegistry=ghcr.io

# GOOD — authenticate first
docker login ghcr.io
dotnet publish /t:PublishContainer -p ContainerRegistry=ghcr.io
Don't Use SDK Publishing When You Need OS Packages
xml
<!-- BAD — SDK container publish cannot run apt-get or install native packages -->
<!-- There is no RUN equivalent -->

<!-- GOOD — create a custom base image with a Dockerfile first, then reference it -->
<ContainerBaseImage>myregistry/custom-base:1.0</ContainerBaseImage>

Decision Guide

ScenarioRecommendation
Standard ASP.NET Core APISDK container publishing with noble-chiseled
Worker service / console appSDK container publishing (native .NET 10 support)
Needs native OS packagesDockerfile (or custom base image + SDK publishing)
Azure FunctionsDockerfile (not supported by SDK publishing)
CI without Docker daemonTarball output with ContainerArchiveOutputPath
Multi-arch deployment (x64 + arm64)ContainerRuntimeIdentifiers property
Production image sizenoble-chiseled (~110 MB) or Native AOT (~10 MB)
Local developmentdotnet publish /t:PublishContainer --os linux --arch x64
Registry pushContainerRegistry + docker login

© codewithmukesh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/container-publish of codewithmukesh/dotnet-claude-kit.

Open the folder on GitHubat commit 2330089

Used in 1 other repository

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in codewithmukesh/dotnet-claude-kit, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Container Publish next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Container Publish compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Container Publish this skillcodewithmukesh/dotnet-claude-kit7511 repos~1.8kAutomated safety check: PassMIT
Dockerfile And Readme Templatingdotnet/dotnet-docker4.9k—~563Automated safety check: PassMIT
Porting Changesdotnet/dotnet-docker4.9k—~781Automated safety check: PassMIT
.NET Crash Dump Collectiondotnet/skills5.6k2 repos~1.1kAutomated safety check: PassMIT
Image Managementdotnet/dotnet-docker4.9k—~1.1kAutomated safety check: PassMIT
Foundationdb AspireSnowBankSDK/foundationdb-dotnet-client158—~3.4kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Official

    Modify Cottle templates that generate Dockerfiles and READMEs in dotnet/dotnet-docker.

    4.9k GitHub stars~563 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Porting Changes

    dotnet/dotnet-docker

    Official

    Plan and move changes between branches in dotnet/dotnet-docker.

    4.9k GitHub stars~781 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Image Management

    dotnet/dotnet-docker

    Official

    Manages .NET Docker images including adding images for new .NET versions, new Linux distros (Alpine, Ubuntu, Azure Linux), and new Windows versions.

    4.9k GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Foundationdb Aspire

    SnowBankSDK/foundationdb-dotnet-client

    How to run a FoundationDB cluster and connect to it from .NET — getting the IFdbDatabaseProvider that the keys/transactions/layers skills assume you already have.

    158 GitHub stars~3.4k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Corvus Bowtie Testing

    corvus-dotnet/Corvus.JsonSchema

    Test Corvus.JsonSchema against the JSON Schema Test Suite using Bowtie, the cross-implementation meta-validator.

    199 GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed

More from codewithmukesh/dotnet-claude-kit

All 47 skills in this repo
  • API Versioning

    codewithmukesh/dotnet-claude-kit

    API versioning strategies for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Scaffold

    codewithmukesh/dotnet-claude-kit

    Architecture-aware feature scaffolding for .NET 10 projects.

    751 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Architecture Advisor

    codewithmukesh/dotnet-claude-kit

    Architecture selection advisor for .NET applications. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Aspire

    codewithmukesh/dotnet-claude-kit

    .NET Aspire for cloud-native orchestration. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Caching

    codewithmukesh/dotnet-claude-kit

    Caching strategies for .NET 10 applications. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Works with

Categories

Questions about Container Publish

What does Container Publish do?

Dockerfile-less containerization using the .NET 10 SDK container publishing feature. Container Publish is an agent skill from codewithmukesh/dotnet-claude-kit.NET 10 SDK container publishing feature.

When should I use Container Publish?

Container Publish fits situations like: wants to containerize without a Dockerfile; mentions dotnet publish container; publishContainer; containerRepository.

How do I install Container Publish in Claude Code?

Run `npx skills add codewithmukesh/dotnet-claude-kit --skill container-publish -a claude-code`. Or copy the skill folder (skills/container-publish in codewithmukesh/dotnet-claude-kit) into .claude/skills/container-publish in your project. Claude Code loads it when a task matches its description.

How do I install Container Publish in Codex?

Run `npx skills add codewithmukesh/dotnet-claude-kit --skill container-publish -a codex`. Or copy the skill folder (skills/container-publish in codewithmukesh/dotnet-claude-kit) into .agents/skills/container-publish in your project. Codex loads it when a task matches its description.

Can I use Container Publish in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewithmukesh/dotnet-claude-kit --skill container-publish -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/container-publish, .gemini/skills/container-publish, .github/skills/container-publish and .opencode/skills/container-publish in your project.

What does Container Publish need to run?

Going by SKILL.md and its folder, Container Publish needs the command-line tools its instructions call (dotnet, docker, az and trivy) and credentials named GITHUB_TOKEN. Our summary lists: Docker; A credential in GITHUB_TOKEN.

Does Container Publish access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Container Publish safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Container Publish use?

Container Publish is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Container Publish use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Container Publish?

Skills that share tags, products or a category with Container Publish: Dockerfile And Readme Templating (dotnet/dotnet-docker, 4.9k stars), Porting Changes (dotnet/dotnet-docker, 4.9k stars), .NET Crash Dump Collection (dotnet/skills, 5.6k stars) and Image Management (dotnet/dotnet-docker, 4.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Container Publish?

codewithmukesh (a GitHub organization) maintains it in codewithmukesh/dotnet-claude-kit, which has 751 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on August 7, 2026.

Source: codewithmukesh/dotnet-claude-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.