-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.50.jlink
More file actions
65 lines (52 loc) · 2.6 KB
/
Copy pathDockerfile.50.jlink
File metadata and controls
65 lines (52 loc) · 2.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
# ============================================================
# Stage 1: Build Environment
# Purpose: Leverage Maven to compile code and "slice" a
# custom JRE using the jlink toolchain.
# ============================================================
FROM maven:3.9.16-eclipse-temurin-25-noble AS builder
WORKDIR /workspace
# ------------------------------------------------------------
# Layer 1: Build Infrastructure
# ------------------------------------------------------------
COPY .mvn/ .mvn/
COPY mvnw pom.xml ./
RUN chmod +x mvnw
# ------------------------------------------------------------
# Layer 2: Dependency Caching
# ------------------------------------------------------------
# Warm the Maven cache to speed up subsequent builds
RUN --mount=type=cache,target=/root/.m2 \
./mvnw -q dependency:go-offline
# ------------------------------------------------------------
# Layer 3: Application Build & JRE Slicing
# ------------------------------------------------------------
COPY src ./src
# The 'jlink' profile triggers the maven-jlink-plugin, which
# inspects the module-info and builds a minimal, custom runtime
# image that contains only the required JDK modules.
RUN --mount=type=cache,target=/root/.m2 \
./mvnw clean verify -Pjlink -DskipTests
# ============================================================
# Stage 2: Runtime Environment (Ubuntu Noble)
# Purpose: Deploy the custom, modularized Java runtime.
# ============================================================
FROM ubuntu:noble
LABEL maintainer="Emmanuel Bruno <emmanuel.bruno@univ-tln.fr>"
LABEL description="Java Hello World Application with Custom JRE via jlink"
# Security: Create a non-privileged user to run the application
RUN groupadd -r appgroup && useradd -r -g appgroup appuser && \
mkdir -p /jre && chown -R appuser:appgroup /jre
# ------------------------------------------------------------
# Deployment: Copy the custom runtime
# ------------------------------------------------------------
# The custom JRE includes the application logic, dependencies,
# and the native launcher ('app') generated during the build.
COPY --from=builder --chown=appuser:appgroup /workspace/target/maven-jlink/classifiers/runtime-image/ /jre/
USER appuser
# JVM Container Ergonomics: JAVA_TOOL_OPTIONS is natively parsed by
# the JRE, ensuring resource limits are applied to the custom runtime.
ENV JAVA_TOOL_OPTIONS="-XX:+UseContainerSupport -XX:MaxRAMPercentage=75.0"
# Execution: Invoke the native binary created by jlink.
# No 'java -jar' command is needed, as the application is now a
# self-contained modular executable.
ENTRYPOINT ["/jre/bin/app"]