-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.60.graalvm
More file actions
53 lines (46 loc) · 2.1 KB
/
Copy pathDockerfile.60.graalvm
File metadata and controls
53 lines (46 loc) · 2.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
# syntax=docker/dockerfile:1
# Layer 1 — GraalVM Native Image toolchain
# ============================================================================
# GraalVM + native-image (the "native" toolchain, installed on top of the JDK)
ARG GRAALVM_VERSION=25
FROM ghcr.io/graalvm/native-image-community:${GRAALVM_VERSION} AS builder
WORKDIR /workspace
# Maven wrapper + POM first (re-uses the /root/.m2 cache for dependency download)
COPY .mvn/ .mvn/
COPY mvnw pom.xml ./
RUN chmod +x mvnw
RUN --mount=type=cache,target=/root/.m2 \
./mvnw -q -Pnative dependency:go-offline
# Cap the native-image build heap so the CI render stays within the runner
# memory budget (large pool: 24 Gi cgroup limit). JAVA_TOOL_OPTIONS is read by
# every JVM in the build (maven + native-image analysis); -Xmx8G leaves headroom
# for the native compiler + GC + runtime within the limit.
ENV JAVA_TOOL_OPTIONS=-Xmx8G
COPY src ./src
RUN --mount=type=cache,target=/root/.m2 \
./mvnw -Pnative -DskipTests package
# Layer 2 — minimal runtime
FROM gcr.io/distroless/base-debian12:nonroot AS runtime
WORKDIR /workspace
# Copy the compiled native executable from the builder stage
COPY --from=builder /workspace/target/*-runner /app
# The native executable is self-contained (no JVM needed at runtime).
# Run as the nonroot user (uid 65532) provided by the distroless base image.
USER nonroot:nonroot
ENTRYPOINT ["/app"]
EXPOSE 8080
# -----------------------------------------------------------------------------
# Layer 3 — optional: multi-stage variant (for the "advanced" lesson)
# -----------------------------------------------------------------------------
# In a real project you'd split build + runtime more aggressively. Here we show
# the same idea with a single GraalVM image used for both stages, to keep the
# lesson focused on the toolchain rather than image optimisation.
FROM ghcr.io/graalvm/native-image-community:${GRAALVM_VERSION} AS build-and-run
WORKDIR /workspace
COPY .mvn/ .mvn/
COPY mvnw pom.xml ./
RUN chmod +x mvnw
COPY src ./src
RUN --mount=type=cache,target=/root/.m2 \
./mvnw -Pnative -DskipTests package
CMD ["./target/*-runner"]