-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
92 lines (78 loc) · 2.33 KB
/
Dockerfile
File metadata and controls
92 lines (78 loc) · 2.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
## Multi-stage build for optimized production image
##FROM openjdk:17-jdk-slim as builder
#FROM public.ecr.aws/docker/library/eclipse-temurin:17-jdk-jammy AS builder
#
## Set working directory
#WORKDIR /app
#
## Copy Maven wrapper and pom.xml
#COPY mvnw .
#COPY .mvn .mvn
#COPY pom.xml .
#
## Download dependencies (cached layer)
##RUN ./mvnw dependency:go-offline -B
#RUN chmod +x mvnw && ./mvnw -v && ./mvnw dependency:go-offline -B
#
## Copy source code
#COPY src src
#
## Build application
#RUN ./mvnw clean package -DskipTests
#
## Production stage
#FROM public.ecr.aws/docker/library/eclipse-temurin:17-jre-jammy
#
## Create non-root user for security
#RUN groupadd -r banking && useradd -r -g banking banking
#
## Set working directory
#WORKDIR /app
#
## Copy JAR from builder stage
#COPY --from=builder /app/target/banking-system-*.jar app.jar
#
## Change ownership to non-root user
#RUN chown -R banking:banking /app
#
## Switch to non-root user
#USER banking
#
## Expose port
#EXPOSE 8080
#
## Health check
#HEALTHCHECK --interval=30s --timeout=3s --start-period=60s --retries=3 \
# CMD curl -f http://localhost:8080/actuator/health || exit 1
#
## Run application
#ENTRYPOINT ["java", "-jar", "app.jar"]\
# ---- builder: Maven + JDK ----
FROM public.ecr.aws/docker/library/maven:3.9-eclipse-temurin-17 AS builder
WORKDIR /app
# Copy build files
COPY pom.xml .
COPY src/ ./src
# Build and create a stable artifact name: target/app.jar
# (filters out original/plain/sources/javadoc jars)
RUN mvn -v && mvn -B -DskipTests=true clean package && \
JAR="$(ls -1 target/*.jar | grep -vE 'original|plain|sources|javadoc' | head -n1)" && \
cp "$JAR" target/app.jar && \
ls -l target/
# ---- runtime: JRE only ----
FROM public.ecr.aws/docker/library/eclipse-temurin:17-jre-jammy
# Install curl for HEALTHCHECK
RUN apt-get update && apt-get install -y --no-install-recommends curl \
&& rm -rf /var/lib/apt/lists/*
# Create non-root user
RUN groupadd -r banking && useradd -r -g banking banking
WORKDIR /app
# Copy the single, known JAR built above
COPY --from=builder /app/target/app.jar /app/app.jar
# Permissions & user
RUN chown -R banking:banking /app
USER banking
EXPOSE 8080
HEALTHCHECK --interval=30s --timeout=3s --start-period=60s --retries=3 \
CMD curl -f http://localhost:8080/actuator/health || exit 1
ENTRYPOINT ["java","-jar","/app/app.jar"]