Part 9 · 1 chapters · ~8 min

In Production: What .NET Is Paired With

Kestrel behind Nginx, YARP or cloud load balancers, IIS hosting on Windows, containers and chiselled images, Azure App Service and AKS, configuration and Key Vault, MassTransit over RabbitMQ or Azure Service Bus with the outbox, Postgres or SQL Server, OpenTelemetry via ActivitySource and Meter, health checks and graceful shutdown, and .NET Aspire.

10

A typical stack

code
# Dockerfile: multi-stage build onto a small, non-root runtime image
FROM mcr.microsoft.com/dotnet/sdk:10.0 AS build
WORKDIR /src
COPY . .
RUN dotnet publish Ledger.Api -c Release -o /app
FROM mcr.microsoft.com/dotnet/aspnet:10.0-noble-chiseled
COPY --from=build /app /app
ENTRYPOINT ["dotnet", "/app/Ledger.Api.dll"]

// MassTransit with the transactional outbox over EF Core
builder.Services.AddMassTransit(x => {
    x.AddEntityFrameworkOutbox<LedgerDb>(o => { o.UsePostgres(); o.UseBusOutbox(); });
    x.AddConsumer<SubmitPayoutConsumer>();
    x.UsingRabbitMq((ctx, cfg) => cfg.ConfigureEndpoints(ctx));
});

// OpenTelemetry
builder.Services.AddOpenTelemetry().WithTracing(t => t.AddAspNetCoreInstrumentation().AddNpgsql().AddOtlpExporter())
                                   .WithMetrics(m => m.AddAspNetCoreInstrumentation().AddRuntimeInstrumentation().AddOtlpExporter());

Behind a proxy, configure forwarded headers (UseForwardedHeaders) so the app sees the client's IP and scheme, and set Kestrel limits and timeouts deliberately. Banks and enterprises often run .NET on Windows with IIS and SQL Server; new services increasingly run on Linux containers with Postgres.

IN PRODUCTION: WHAT .NET IS PAIRED WITH
typical deployments
reverse proxyNginx / YARP / Azure Front Door, or IIS on WindowsKestrelthe ASP.NET Core app in a containerMassTransit / NServiceBusover RabbitMQ, Azure Service Bus, KafkaPostgres or SQL ServerEF Core, Npgsql, connection poolingAzure (or any cloud)App Service, AKS, Key VaultOpenTelemetry.NET has first-class OTel support
swipe the figure sideways, or tap expand for full screen
1/4
hosting
On Linux, Kestrel runs in a container behind a reverse proxy or load balancer (Nginx, YARP, cloud load balancers); on Windows, IIS hosts ASP.NET Core in-process via the ASP.NET Core Module.
Kestrel behind a proxyor IIS on Windows