Veröffentlicht · wird verbessert
ASP.NET Core-Anleitung · 6/6
Dieses Kapitel ist vorerst nur auf Englisch verfügbar.
An ASP.NET Core app is a regular process that hosts the Kestrel web server. Deploying it means publishing the compiled output, running it with production configuration, and usually placing it behind a reverse proxy or inside a container.
# framework-dependent: the server needs the ASP.NET Core runtime
dotnet publish -c Release -o ./publish
dotnet ./publish/TodoApi.dll
# self-contained for Linux x64: the runtime is included
dotnet publish -c Release -r linux-x64 --self-contained -o ./publish
./publish/TodoApi| Mode | Advantages | Trade-offs |
|---|---|---|
| Framework-dependent | small output; runtime patched separately | runtime must be installed on the server |
| Self-contained | no runtime needed on the server | larger output; you ship runtime updates |
Minimal API apps can also be published with Native AOT (<PublishAot>true</PublishAot>, or the webapiaot template) for fast startup and a small footprint, with some limits such as no MVC controllers.
The environment defaults to Production. Supply secrets and connection strings through environment variables or a secret store, and choose the listening address with ASPNETCORE_URLS or ASPNETCORE_HTTP_PORTS:
export ConnectionStrings__Default="Host=db;Database=todo;Username=app;Password=change-me"
export ASPNETCORE_URLS="http://127.0.0.1:5000"
dotnet ./publish/TodoApi.dllKestrel is production-ready, but a reverse proxy such as Nginx, Apache, IIS or a cloud load balancer often terminates TLS, hosts several sites on one IP and adds request limits. Because the proxy talks to Kestrel over plain HTTP, the app must read the original scheme and client IP from the X-Forwarded-* headers:
using Microsoft.AspNetCore.HttpOverrides;
builder.Services.Configure<ForwardedHeadersOptions>(options =>
{
options.ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto;
});
var app = builder.Build();
app.UseForwardedHeaders(); // before other middlewareBy default only a proxy on the same machine is trusted; if it runs elsewhere, add its address to KnownProxies. A matching Nginx site:
server {
listen 80;
server_name example.com;
location / {
proxy_pass http://127.0.0.1:5000;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}On Linux, keep the app running with a systemd service:
[Unit]
Description=Todo API
[Service]
WorkingDirectory=/var/www/todoapi
ExecStart=/usr/bin/dotnet /var/www/todoapi/TodoApi.dll
Restart=always
User=www-data
Environment=ASPNETCORE_ENVIRONMENT=Production
Environment=ASPNETCORE_URLS=http://127.0.0.1:5000
[Install]
WantedBy=multi-user.targetOn Windows, IIS hosts apps through the ASP.NET Core Module, installed with the .NET Hosting Bundle.
The SDK can build a container image without a Dockerfile:
dotnet publish --os linux --arch x64 /t:PublishContainer -p:ContainerRepository=todoapi -p:ContainerImageTag=1.0
docker run --rm -p 8080:8080 todoapi:1.0Or write a multi-stage Dockerfile. Match the image tags to the project's TargetFramework:
FROM mcr.microsoft.com/dotnet/sdk:10.0 AS build
WORKDIR /src
COPY *.csproj ./
RUN dotnet restore
COPY . .
RUN dotnet publish -c Release -o /app --no-restore
FROM mcr.microsoft.com/dotnet/aspnet:10.0
WORKDIR /app
COPY --from=build /app .
USER $APP_UID
ENTRYPOINT ["dotnet", "TodoApi.dll"]Official .NET images listen on port 8080 by default and include a non-root user (APP_UID). Add a health endpoint for orchestrators and load balancers with builder.Services.AddHealthChecks() and app.MapHealthChecks("/healthz").
dotnet publish produces framework-dependent or self-contained output.appsettings.json./t:PublishContainer or a multi-stage Dockerfile.
0 Kommentare
Anmelden · Melde dich an, um einen Kommentar zu schreiben.
Schreib den ersten Kommentar.