0af35d44f4
Provide the production foundation for Apple identity, immutable credits, referrals, integrity checks, managed providers, and hardened Docker deployment.
26 lines
763 B
Docker
26 lines
763 B
Docker
FROM gradle:9.6.1-jdk21-alpine AS build
|
|
WORKDIR /workspace
|
|
|
|
COPY --chown=gradle:gradle . .
|
|
USER gradle
|
|
RUN ./gradlew --no-daemon --stacktrace installDist
|
|
|
|
FROM eclipse-temurin:21-jre-alpine
|
|
RUN addgroup -S -g 10001 app \
|
|
&& adduser -S -D -H -u 10001 -G app -h /app app
|
|
WORKDIR /app
|
|
|
|
COPY --from=build --chown=app:app /workspace/build/install/OSGAccountServer/ /app/
|
|
|
|
ENV HOME=/tmp \
|
|
JAVA_TOOL_OPTIONS="-Djava.io.tmpdir=/tmp -XX:+UseG1GC -XX:MaxGCPauseMillis=100 -XX:MaxRAMPercentage=75.0 -XX:+ExitOnOutOfMemoryError"
|
|
|
|
USER 10001:10001
|
|
EXPOSE 8080
|
|
STOPSIGNAL SIGTERM
|
|
|
|
HEALTHCHECK --interval=30s --timeout=3s --start-period=30s --retries=3 \
|
|
CMD wget -q -O /dev/null http://127.0.0.1:8080/health/live || exit 1
|
|
|
|
ENTRYPOINT ["/app/bin/OSGAccountServer"]
|