Establish secure account and managed AI backend
Provide the production foundation for Apple identity, immutable credits, referrals, integrity checks, managed providers, and hardened Docker deployment.
This commit is contained in:
+25
@@ -0,0 +1,25 @@
|
||||
FROM gradle:9.6.1-jdk21-alpine AS build
|
||||
WORKDIR /workspace
|
||||
|
||||
COPY --chown=gradle:gradle . .
|
||||
USER gradle
|
||||
RUN ./gradlew --no-daemon --stacktrace installDist
|
||||
|
||||
FROM eclipse-temurin:21-jre-alpine
|
||||
RUN addgroup -S -g 10001 app \
|
||||
&& adduser -S -D -H -u 10001 -G app -h /app app
|
||||
WORKDIR /app
|
||||
|
||||
COPY --from=build --chown=app:app /workspace/build/install/OSGAccountServer/ /app/
|
||||
|
||||
ENV HOME=/tmp \
|
||||
JAVA_TOOL_OPTIONS="-Djava.io.tmpdir=/tmp -XX:+UseG1GC -XX:MaxGCPauseMillis=100 -XX:MaxRAMPercentage=75.0 -XX:+ExitOnOutOfMemoryError"
|
||||
|
||||
USER 10001:10001
|
||||
EXPOSE 8080
|
||||
STOPSIGNAL SIGTERM
|
||||
|
||||
HEALTHCHECK --interval=30s --timeout=3s --start-period=30s --retries=3 \
|
||||
CMD wget -q -O /dev/null http://127.0.0.1:8080/health/live || exit 1
|
||||
|
||||
ENTRYPOINT ["/app/bin/OSGAccountServer"]
|
||||
Reference in New Issue
Block a user