-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.51.jlink-alpine
More file actions
73 lines (58 loc) · 2.89 KB
/
Copy pathDockerfile.51.jlink-alpine
File metadata and controls
73 lines (58 loc) · 2.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
# ============================================================
# Stage 1: Build Environment (Temurin JDK 25 on Alpine/Musl)
# Purpose: Compile the application and slice a custom,
# minimal JRE using jlink.
# ============================================================
FROM eclipse-temurin:25-jdk-alpine AS builder
WORKDIR /workspace
# ------------------------------------------------------------
# Layer 1: Build Infrastructure
# ------------------------------------------------------------
COPY .mvn/ .mvn/
COPY mvnw pom.xml ./
RUN chmod +x mvnw
# ------------------------------------------------------------
# Layer 2: Dependency Caching
# ------------------------------------------------------------
# Warm the local Maven repository to optimize build speed
RUN --mount=type=cache,target=/root/.m2 \
./mvnw -q dependency:go-offline
# ------------------------------------------------------------
# Layer 3: Application Build & JRE Slicing
# ------------------------------------------------------------
COPY src ./src
# The 'jlink' profile generates a custom JRE containing only
# the necessary modules, significantly reducing image footprint.
RUN --mount=type=cache,target=/root/.m2 \
./mvnw clean verify -Pjlink -DskipTests
# Consolidate jlink output into a stable path for the runtime stage
RUN mkdir -p /workspace/jre && \
if [ -d target/maven-jlink/classifiers/runtime-image ]; then \
cp -a target/maven-jlink/classifiers/runtime-image/* /workspace/jre/ ; \
fi
# ============================================================
# Stage 2: Runtime Environment (Minimal Alpine Linux)
# Purpose: Ultra-lightweight secure runtime on musl libc.
# ============================================================
FROM alpine:3.20
LABEL maintainer="Emmanuel Bruno <emmanuel.bruno@univ-tln.fr>"
LABEL description="Java Hello World Application with Custom JRE on Alpine musl"
WORKDIR /app
# Install CA certificates to enable secure HTTPS/TLS communication
RUN apk add --no-cache ca-certificates
# Security: Create a non-privileged user and group to run the app
RUN addgroup -S appgroup && adduser -S appuser -G appgroup && \
mkdir -p /app /jre && chown -R appuser:appgroup /app /jre
# ------------------------------------------------------------
# Deployment: Copy the custom runtime
# ------------------------------------------------------------
# The JRE slice already contains the application modules and
# required dependencies, requiring no further packaging.
COPY --from=builder --chown=appuser:appgroup /workspace/jre /jre
USER appuser
# JVM Container Ergonomics: JAVA_TOOL_OPTIONS is natively parsed
# by the JVM, ensuring resource limits are applied to the runtime.
ENV JAVA_TOOL_OPTIONS="-XX:+UseContainerSupport -XX:MaxRAMPercentage=75.0"
# Execution: Invoke the native launcher ('app') generated by jlink.
# Alpine's 'musl' libc provides a lightweight alternative to 'glibc'.
ENTRYPOINT ["/jre/bin/app"]