-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.61.graalvm-static
More file actions
55 lines (45 loc) · 2.29 KB
/
Copy pathDockerfile.61.graalvm-static
File metadata and controls
55 lines (45 loc) · 2.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
# ============================================================
# Stage 1: Build Environment (GraalVM + Musl Toolchain)
# Purpose: Compile Java source into a 100% statically linked
# native Linux binary using the musl libc.
# ============================================================
FROM ghcr.io/graalvm/native-image-community:25-muslib AS builder
WORKDIR /workspace
# ------------------------------------------------------------
# Layer 1: Build Infrastructure
# ------------------------------------------------------------
COPY .mvn/ .mvn/
COPY mvnw pom.xml ./
RUN chmod +x mvnw
# ------------------------------------------------------------
# Layer 2: Dependency Caching (BuildKit)
# ------------------------------------------------------------
RUN --mount=type=cache,target=/root/.m2 \
./mvnw -q -Pnative-static dependency:go-offline
# ------------------------------------------------------------
# Layer 3: Static Native Compilation
# ------------------------------------------------------------
# We trigger the 'native' and 'native-static' profiles. The latter
# forces GraalVM to compile against 'musl' instead of 'glibc',
# resulting in a binary that requires no external system libraries.
COPY src ./src
RUN --mount=type=cache,target=/root/.m2 \
./mvnw -Pnative,native-static -DskipTests package
# ============================================================
# Stage 2: Runtime Environment (Distroless Static)
# Purpose: The pinnacle of production security.
# ============================================================
# Distroless 'static' contains no shell, no package manager, and
# no standard Linux utilities. It is the minimal runtime possible
# for a statically linked binary.
FROM gcr.io/distroless/static-debian12:nonroot
LABEL maintainer="Emmanuel Bruno <emmanuel.bruno@univ-tln.fr>"
LABEL description="Java Hello World Application with GraalVM Native Image statically linked against musl"
# Copy the self-contained native binary. Since it is statically linked,
# no system libraries (like glibc or libz) are required at runtime.
COPY --from=builder --chown=65532:65532 /workspace/target/app /app
# Distroless 'nonroot' user ID is predefined as 65532.
USER 65532:65532
# Execution: The binary is completely self-contained.
# It manages its own memory and execution context.
ENTRYPOINT ["/app"]