diff --git a/releases/latest/beta/Dockerfile.ubi10-micro.openjdk25 b/releases/latest/beta/Dockerfile.ubi10-micro.openjdk25
new file mode 100644
index 00000000..76f8ed20
--- /dev/null
+++ b/releases/latest/beta/Dockerfile.ubi10-micro.openjdk25
@@ -0,0 +1,165 @@
+FROM registry.access.redhat.com/ubi10/ubi-minimal:latest AS builder
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.9-beta
+ARG LIBERTY_SHA=52af30086cb86dca8d028182eaf4091e83362fac
+ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/beta/openliberty-runtime/$LIBERTY_VERSION/openliberty-runtime-$LIBERTY_VERSION.zip
+
+ARG VERBOSE=false
+
+# If there is a local copy of the image use that instead
+COPY resources/ /tmp/
+
+# Install Open Liberty
+RUN microdnf -y install shadow-utils wget unzip openssl \
+ && if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
+ && echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
+ && sha1sum -c /tmp/wlp.zip.sha1 \
+ && chmod -R u+x /usr/bin \
+ && unzip -q /tmp/wlp.zip -d /opt/ol \
+ && mkdir -p /licenses \
+ && cp /opt/ol/wlp/LICENSE /licenses/ \
+ && adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+# Install dumb-init
+RUN set -eux; \
+ ARCH="$(uname -m)"; \
+ case "${ARCH}" in \
+ aarch64|arm64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
+ DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
+ ;; \
+ amd64|x86_64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
+ DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
+ ;; \
+ ppc64el|ppc64le) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
+ DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
+ ;; \
+ s390x) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
+ DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
+ ;;\
+ *) \
+ echo "Unsupported arch: ${ARCH}"; \
+ exit 1; \
+ ;; \
+ esac; \
+ curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
+ echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
+ chmod +x /usr/bin/dumb-init;
+
+FROM icr.io/appcafe/ibm-semeru-runtimes:open-25-jre-ubi10-micro
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.9-beta
+ARG LIBERTY_BUILD_LABEL=cl260820260725-1102
+
+ARG OPENJ9_SCC=true
+ARG VERBOSE=false
+
+LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
+ org.opencontainers.image.vendor="Open Liberty" \
+ org.opencontainers.image.url="https://openliberty.io/" \
+ org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
+ org.opencontainers.image.version="$LIBERTY_VERSION" \
+ org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
+ liberty.version="$LIBERTY_VERSION" \
+ io.openliberty.version="$LIBERTY_VERSION" \
+ vendor="Open Liberty" \
+ name="Open Liberty Beta" \
+ version="$LIBERTY_VERSION" \
+ summary="Image for Open Liberty Beta with IBM Semeru Runtime Open Edition OpenJDK 25 with OpenJ9 and UBI 10 micro" \
+ description="This image contains the Open Liberty beta runtime with IBM Semeru Runtime Open Edition OpenJDK 25 with OpenJ9 and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"
+
+COPY NOTICES /opt/ol/NOTICES
+COPY helpers /opt/ol/helpers
+COPY fixes/ /opt/ol/fixes/
+
+# Add default user 1001 and create wlp with right user/permissions before copying
+RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
+ && mkdir -p /home/1001 \
+ && chown 1001:0 /home/1001 \
+ && mkdir -p /opt/ol/wlp \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
+COPY --from=builder /usr/bin/awk /usr/bin/awk
+COPY --from=builder /usr/bin/wget /usr/bin/wget
+
+COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/
+
+# Copy the runtime and licenses
+COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+COPY --from=builder /licenses /licenses
+
+# Set Path Shortcuts
+ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
+ LOG_DIR=/liberty/logs \
+ WLP_OUTPUT_DIR=/opt/ol/wlp/output \
+ WLP_SKIP_MAXPERMSIZE=true \
+ OPENJ9_SCC=$OPENJ9_SCC
+
+# Configure Open Liberty
+RUN /opt/ol/wlp/bin/server create --template=javaee8 \
+ && rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env
+
+# Create symlinks && set permissions for non-root user
+RUN mkdir /logs \
+ && chown -R 1001:0 /logs \
+ && chmod -R g+rw /logs \
+ && mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
+ && ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
+ && mkdir -p $WLP_OUTPUT_DIR/defaultServer \
+ && ln -s $WLP_OUTPUT_DIR/defaultServer /output \
+ && ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
+ && mkdir -p /config/configDropins/defaults \
+ && mkdir -p /config/configDropins/overrides \
+ && mkdir -p /config/dropins \
+ && mkdir -p /config/apps \
+ && ln -s /opt/ol/wlp /liberty \
+ && ln -s /opt/ol/fixes /fixes \
+ && chown -R 1001:0 /config \
+ && chmod -R g+rw /config \
+ && chown -R 1001:0 /opt/ol/wlp/usr \
+ && chmod -R g+rw /opt/ol/wlp/usr \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rw /opt/ol/wlp/output \
+ && chown -R 1001:0 /opt/ol/helpers \
+ && chmod -R ug+rwx /opt/ol/helpers \
+ && chown -R 1001:0 /opt/ol/fixes \
+ && chmod -R g+rwx /opt/ol/fixes \
+ && mkdir /etc/wlp \
+ && chown -R 1001:0 /etc/wlp \
+ && chmod -R g+rw /etc/wlp \
+ && if [ -e /etc/instanton.ld.so.cache ]; then chmod g+w /etc/ld.so.cache; fi \
+ && echo "" > /config/configDropins/defaults/open-default-port.xml \
+ && ln -s /logs /liberty/logs \
+ && mkdir /serviceability \
+ && chown -R 1001:0 /serviceability \
+ && chmod -R g+rw /serviceability
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rwx /opt/ol/wlp/output
+
+#These settings are needed so that we can run as a different user than 1001 after server warmup
+ENV RANDFILE=/tmp/.rnd \
+ OPENJ9_JAVA_OPTIONS="-XX:+IgnoreUnrecognizedVMOptions -XX:+IdleTuningGcOnIdle -Xshareclasses:name=openj9_system_scc,cacheDir=/opt/java/.scc,readonly,nonFatal -Dosgi.checkConfiguration=false"
+
+USER 1001
+
+EXPOSE 9080 9443
+
+ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
+CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
diff --git a/releases/latest/beta/helpers/build/populate_scc.sh b/releases/latest/beta/helpers/build/populate_scc.sh
index f0805015..98cd2038 100755
--- a/releases/latest/beta/helpers/build/populate_scc.sh
+++ b/releases/latest/beta/helpers/build/populate_scc.sh
@@ -76,10 +76,10 @@ do
-s Size of the SCC in megabytes (m suffix required). (Default: $SCC_SIZE)
-t Trim the SCC to eliminate most of the free space, if any.
-d Don't trim the SCC.
- -w Use curl to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
+ -w Use curl/wget to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
-c Do not warm an endpoint during SCC creation.
-u The URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_URL)
- -m Use curl to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
+ -m Use curl/wget to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
-l Do not warm the openapi endpoint during SCC creation.
-o The Open API URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_OPENAPI_URL)
@@ -100,6 +100,13 @@ done
OLD_UMASK=`umask`
umask 002 # 002 is required to provide group rw permission to the cache when `-Xshareclasses:groupAccess` options is used
+# Use curl/wget to warm endpoints
+if command -v curl > /dev/null 2>&1; then
+ http_get() { curl --silent --output /dev/null --show-error --fail --max-time 5 "$1"; }
+else
+ http_get() { wget -q -O /dev/null -T 5 "$1"; }
+fi
+
# Explicity create a class cache layer for this image layer here rather than allowing
# `server start` to do it, which will lead to problems because multiple JVMs will be started.
java $CREATE_LAYER -Xscmx$SCC_SIZE -version
@@ -112,11 +119,11 @@ then
if [ ${WARM_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi
/opt/ol/wlp/bin/server stop
@@ -147,11 +154,11 @@ do
if [ ${WARM_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi
/opt/ol/wlp/bin/server stop
diff --git a/releases/latest/full/Dockerfile.ubi10-micro.ibmjava8 b/releases/latest/full/Dockerfile.ubi10-micro.ibmjava8
new file mode 100644
index 00000000..1da744d9
--- /dev/null
+++ b/releases/latest/full/Dockerfile.ubi10-micro.ibmjava8
@@ -0,0 +1,53 @@
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java8-ibmjava-ubi-micro
+
+# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
+FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
+RUN microdnf -y install unzip && microdnf clean all
+
+FROM $PARENT_IMAGE AS installBundle
+
+ARG VERBOSE=false
+ARG LIBERTY_VERSION=26.0.0.8
+ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419
+
+# If there is a local copy of the repository use that instead
+COPY resources/ /tmp/
+
+# We need unzip when using a local repo; copy it from ubi-minimal builder stage
+USER root
+COPY --from=builder /usr/bin/unzip /usr/bin/unzip
+COPY --from=builder /usr/lib64/libbz2.so* /usr/lib64/
+USER 1001
+
+# Install all features
+RUN set -eux; \
+ if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
+ wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
+ echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ else \
+ echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
+ unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
+ cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
+ export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
+ export FEATURE_VERIFY=skip; \
+ fi; \
+ grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
+ rm -rf /output/workarea /output/logs; \
+ find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;
+
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java8-ibmjava-ubi-micro
+FROM $PARENT_IMAGE
+ARG VERBOSE=false
+
+# Copy the runtime
+COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+
+COPY --chown=1001:0 server.xml /config/
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
+ && find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
diff --git a/releases/latest/full/Dockerfile.ubi10-micro.openjdk11 b/releases/latest/full/Dockerfile.ubi10-micro.openjdk11
new file mode 100644
index 00000000..46d2fd5e
--- /dev/null
+++ b/releases/latest/full/Dockerfile.ubi10-micro.openjdk11
@@ -0,0 +1,52 @@
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java11-openj9-ubi-micro
+
+# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
+FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
+RUN microdnf -y install unzip && microdnf clean all
+
+FROM $PARENT_IMAGE AS installBundle
+
+ARG VERBOSE=false
+ARG LIBERTY_VERSION=26.0.0.8
+ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419
+
+# If there is a local copy of the repository use that instead
+COPY resources/ /tmp/
+
+# We need unzip when using a local repo; copy it from ubi-minimal builder stage
+USER root
+COPY --from=builder /usr/bin/unzip /usr/bin/unzip
+USER 1001
+
+# Install all features
+RUN set -eux; \
+ if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
+ wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
+ echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ else \
+ echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
+ unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
+ cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
+ export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
+ export FEATURE_VERIFY=skip; \
+ fi; \
+ grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
+ rm -rf /output/workarea /output/logs; \
+ find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;
+
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java11-openj9-ubi-micro
+FROM $PARENT_IMAGE
+ARG VERBOSE=false
+
+# Copy the runtime
+COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+
+COPY --chown=1001:0 server.xml /config/
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
+ && find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
diff --git a/releases/latest/full/Dockerfile.ubi10-micro.openjdk17 b/releases/latest/full/Dockerfile.ubi10-micro.openjdk17
new file mode 100644
index 00000000..1871ec06
--- /dev/null
+++ b/releases/latest/full/Dockerfile.ubi10-micro.openjdk17
@@ -0,0 +1,52 @@
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java17-openj9-ubi-micro
+
+# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
+FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
+RUN microdnf -y install unzip && microdnf clean all
+
+FROM $PARENT_IMAGE AS installBundle
+
+ARG VERBOSE=false
+ARG LIBERTY_VERSION=26.0.0.8
+ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419
+
+# If there is a local copy of the repository use that instead
+COPY resources/ /tmp/
+
+# We need unzip when using a local repo; copy it from ubi-minimal builder stage
+USER root
+COPY --from=builder /usr/bin/unzip /usr/bin/unzip
+USER 1001
+
+# Install all features
+RUN set -eux; \
+ if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
+ wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
+ echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ else \
+ echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
+ unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
+ cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
+ export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
+ export FEATURE_VERIFY=skip; \
+ fi; \
+ grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
+ rm -rf /output/workarea /output/logs; \
+ find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;
+
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java17-openj9-ubi-micro
+FROM $PARENT_IMAGE
+ARG VERBOSE=false
+
+# Copy the runtime
+COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+
+COPY --chown=1001:0 server.xml /config/
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
+ && find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
diff --git a/releases/latest/full/Dockerfile.ubi10-micro.openjdk21 b/releases/latest/full/Dockerfile.ubi10-micro.openjdk21
new file mode 100644
index 00000000..eac128af
--- /dev/null
+++ b/releases/latest/full/Dockerfile.ubi10-micro.openjdk21
@@ -0,0 +1,52 @@
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java21-openj9-ubi-micro
+
+# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
+FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
+RUN microdnf -y install unzip && microdnf clean all
+
+FROM $PARENT_IMAGE AS installBundle
+
+ARG VERBOSE=false
+ARG LIBERTY_VERSION=26.0.0.8
+ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419
+
+# If there is a local copy of the repository use that instead
+COPY resources/ /tmp/
+
+# We need unzip when using a local repo; copy it from ubi-minimal builder stage
+USER root
+COPY --from=builder /usr/bin/unzip /usr/bin/unzip
+USER 1001
+
+# Install all features
+RUN set -eux; \
+ if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
+ wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
+ echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ else \
+ echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
+ unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
+ cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
+ export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
+ export FEATURE_VERIFY=skip; \
+ fi; \
+ grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
+ rm -rf /output/workarea /output/logs; \
+ find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;
+
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java21-openj9-ubi-micro
+FROM $PARENT_IMAGE
+ARG VERBOSE=false
+
+# Copy the runtime
+COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+
+COPY --chown=1001:0 server.xml /config/
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
+ && find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
diff --git a/releases/latest/full/Dockerfile.ubi10-micro.openjdk25 b/releases/latest/full/Dockerfile.ubi10-micro.openjdk25
new file mode 100644
index 00000000..3f66836e
--- /dev/null
+++ b/releases/latest/full/Dockerfile.ubi10-micro.openjdk25
@@ -0,0 +1,52 @@
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java25-openj9-ubi-micro
+
+# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
+FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
+RUN microdnf -y install unzip && microdnf clean all
+
+FROM $PARENT_IMAGE AS installBundle
+
+ARG VERBOSE=false
+ARG LIBERTY_VERSION=26.0.0.8
+ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419
+
+# If there is a local copy of the repository use that instead
+COPY resources/ /tmp/
+
+# We need unzip when using a local repo; copy it from ubi-minimal builder stage
+USER root
+COPY --from=builder /usr/bin/unzip /usr/bin/unzip
+USER 1001
+
+# Install all features
+RUN set -eux; \
+ if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
+ wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
+ echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ else \
+ echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
+ unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
+ cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
+ export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
+ export FEATURE_VERIFY=skip; \
+ fi; \
+ grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
+ rm -rf /output/workarea /output/logs; \
+ find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;
+
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java25-openj9-ubi-micro
+FROM $PARENT_IMAGE
+ARG VERBOSE=false
+
+# Copy the runtime
+COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+
+COPY --chown=1001:0 server.xml /config/
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
+ && find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
diff --git a/releases/latest/full/Dockerfile.ubi10-micro.openjdk8 b/releases/latest/full/Dockerfile.ubi10-micro.openjdk8
new file mode 100644
index 00000000..7981956a
--- /dev/null
+++ b/releases/latest/full/Dockerfile.ubi10-micro.openjdk8
@@ -0,0 +1,52 @@
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java8-openj9-ubi-micro
+
+# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
+FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
+RUN microdnf -y install unzip && microdnf clean all
+
+FROM $PARENT_IMAGE AS installBundle
+
+ARG VERBOSE=false
+ARG LIBERTY_VERSION=26.0.0.8
+ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419
+
+# If there is a local copy of the repository use that instead
+COPY resources/ /tmp/
+
+# We need unzip when using a local repo; copy it from ubi-minimal builder stage
+USER root
+COPY --from=builder /usr/bin/unzip /usr/bin/unzip
+USER 1001
+
+# Install all features
+RUN set -eux; \
+ if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
+ wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
+ echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
+ else \
+ echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
+ mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
+ unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
+ cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
+ export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
+ export FEATURE_VERIFY=skip; \
+ fi; \
+ grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
+ rm -rf /output/workarea /output/logs; \
+ find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;
+
+ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java8-openj9-ubi-micro
+FROM $PARENT_IMAGE
+ARG VERBOSE=false
+
+# Copy the runtime
+COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+
+COPY --chown=1001:0 server.xml /config/
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
+ && find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
diff --git a/releases/latest/full/helpers/build/populate_scc.sh b/releases/latest/full/helpers/build/populate_scc.sh
index 1012a07a..1c1fc7dd 100755
--- a/releases/latest/full/helpers/build/populate_scc.sh
+++ b/releases/latest/full/helpers/build/populate_scc.sh
@@ -81,10 +81,10 @@ do
-s Size of the SCC in megabytes (m suffix required). (Default: $SCC_SIZE)
-t Trim the SCC to eliminate most of the free space, if any.
-d Don't trim the SCC.
- -w Use curl to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
+ -w Use curl/wget to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
-c Do not warm an endpoint during SCC creation.
-u The URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_URL)
- -m Use curl to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
+ -m Use curl/wget to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
-l Do not warm the openapi endpoint during SCC creation.
-o The Open API URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_OPENAPI_URL)
@@ -105,6 +105,13 @@ done
OLD_UMASK=`umask`
umask 002 # 002 is required to provide group rw permission to the cache when `-Xshareclasses:groupAccess` options is used
+# Use curl/wget to warm endpoints
+if command -v curl > /dev/null 2>&1; then
+ http_get() { curl --silent --output /dev/null --show-error --fail --max-time 5 "$1"; }
+else
+ http_get() { wget -q -O /dev/null -T 5 "$1"; }
+fi
+
# Explicity create a class cache layer for this image layer here rather than allowing
# `server start` to do it, which will lead to problems because multiple JVMs will be started.
java $CREATE_LAYER -Xscmx$SCC_SIZE -version
@@ -117,11 +124,11 @@ then
if [ ${WARM_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi
/opt/ol/wlp/bin/server stop
@@ -152,11 +159,11 @@ do
if [ ${WARM_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi
/opt/ol/wlp/bin/server stop
diff --git a/releases/latest/kernel-slim/Dockerfile.ubi10-micro.ibmjava8 b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.ibmjava8
new file mode 100644
index 00000000..5a7555d5
--- /dev/null
+++ b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.ibmjava8
@@ -0,0 +1,177 @@
+# This relies on a base image which needs to be built seperately
+# curl https://raw.githubusercontent.com/ibmruntimes/ci.docker/main/ibmjava/8/jre/ubi-min/Dockerfile -o java/Dockerfile.ubi10.minimal
+# The above file needs editing before it is built:
+# This changes to a UBI10 base, and corrects the microdnf command to work on UBI10.
+# $> sed -i -e 's/ubi8/ubi10/' -e 's/microdnf install/microdnf -y install/' -e 's/microdnf update/microdnf update -y/' Dockerfile.ubi10-minimal.ibmjava8
+# $> rm ./java/Dockerfile.ubi10.minimal.bak
+# Then build and tag as 'ibmjava:10-ubi'
+# $> docker build -t ibmjava:10-ubi -f ./java/Dockerfile.ubi10.minimal java
+
+FROM ibmjava:10-ubi AS builder
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_SHA=6394fee2c842008e9e36f3474c23330bfe467f48
+ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/openliberty-kernel/$LIBERTY_VERSION/openliberty-kernel-$LIBERTY_VERSION.zip
+
+ARG VERBOSE=false
+
+# If there is a local copy of the image use that instead
+COPY resources/ /tmp/
+
+# Install Open Liberty
+RUN microdnf -y install shadow-utils wget unzip openssl \
+ && if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
+ && echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
+ && sha1sum -c /tmp/wlp.zip.sha1 \
+ && chmod -R u+x /usr/bin \
+ && unzip -q /tmp/wlp.zip -d /opt/ol \
+ && mkdir -p /licenses \
+ && cp /opt/ol/wlp/LICENSE /licenses/ \
+# && adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+# Install dumb-init
+RUN set -eux; \
+ ARCH="$(uname -m)"; \
+ case "${ARCH}" in \
+ aarch64|arm64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
+ DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
+ ;; \
+ amd64|x86_64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
+ DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
+ ;; \
+ ppc64el|ppc64le) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
+ DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
+ ;; \
+ s390x) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
+ DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
+ ;;\
+ *) \
+ echo "Unsupported arch: ${ARCH}"; \
+ exit 1; \
+ ;; \
+ esac; \
+ curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
+ echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
+ chmod +x /usr/bin/dumb-init;
+
+FROM icr.io/appcafe/ibmjava:8-jre-ubi10-micro
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_BUILD_LABEL=cl260820260725-1102
+
+ARG OPENJ9_SCC=true
+ARG VERBOSE=false
+
+LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
+ org.opencontainers.image.vendor="Open Liberty" \
+ org.opencontainers.image.url="https://openliberty.io/" \
+ org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
+ org.opencontainers.image.version="$LIBERTY_VERSION" \
+ org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
+ liberty.version="$LIBERTY_VERSION" \
+ io.openliberty.version="$LIBERTY_VERSION" \
+ vendor="Open Liberty" \
+ name="Open Liberty" \
+ version="$LIBERTY_VERSION" \
+ summary="Image for Open Liberty with IBM's Java and UBI 10 micro" \
+ description="This image contains the Open Liberty runtime with IBM's Java and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"
+
+COPY NOTICES /opt/ol/NOTICES
+COPY helpers /opt/ol/helpers
+COPY fixes/ /opt/ol/fixes/
+
+# Add default user 1001 and create wlp with right user/permissions before copying
+RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
+ && mkdir -p /home/1001 \
+ && chown 1001:0 /home/1001 \
+ && mkdir -p /opt/ol/wlp \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
+COPY --from=builder /usr/bin/awk /usr/bin/awk
+COPY --from=builder /usr/bin/wget /usr/bin/wget
+
+COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libreadline.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libgnutls.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libidn2.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libunistring.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libuuid.so* /usr/lib64/
+
+# Copy the runtime and licenses
+COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+COPY --from=builder /licenses /licenses
+
+# Set Path Shortcuts
+ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
+ LOG_DIR=/liberty/logs \
+ WLP_OUTPUT_DIR=/opt/ol/wlp/output \
+ WLP_SKIP_MAXPERMSIZE=true \
+ OPENJ9_SCC=$OPENJ9_SCC
+
+# Configure Open Liberty
+RUN /opt/ol/wlp/bin/server create \
+ && rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env
+
+# Create symlinks && set permissions for non-root user
+RUN mkdir /logs \
+ && chown -R 1001:0 /logs \
+ && chmod -R g+rw /logs \
+ && mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
+ && ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
+ && mkdir -p $WLP_OUTPUT_DIR/defaultServer \
+ && ln -s $WLP_OUTPUT_DIR/defaultServer /output \
+ && ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
+ && mkdir -p /config/configDropins/defaults \
+ && mkdir -p /config/configDropins/overrides \
+ && ln -s /opt/ol/wlp /liberty \
+ && ln -s /opt/ol/fixes /fixes \
+ && echo "" > /config/configDropins/defaults/open-default-port.xml \
+ && chown -R 1001:0 /config \
+ && chmod -R g+rw /config \
+ && chown -R 1001:0 /opt/ol/wlp/usr \
+ && chmod -R g+rw /opt/ol/wlp/usr \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rw /opt/ol/wlp/output \
+ && chown -R 1001:0 /opt/ol/helpers \
+ && chmod -R ug+rwx /opt/ol/helpers \
+ && chown -R 1001:0 /opt/ol/fixes \
+ && chmod -R g+rwx /opt/ol/fixes \
+ && mkdir /etc/wlp \
+ && chown -R 1001:0 /etc/wlp \
+ && chmod -R g+rw /etc/wlp \
+ && ln -s /logs /liberty/logs \
+ && mkdir /serviceability \
+ && chown -R 1001:0 /serviceability \
+ && chmod -R g+rw /serviceability
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rwx /opt/ol/wlp/output
+
+#These settings are needed so that we can run as a different user than 1001 after server warmup
+ENV RANDFILE=/tmp/.rnd \
+ IBM_JAVA_OPTIONS="-Xshareclasses:name=liberty,readonly,nonfatal,cacheDir=/output/.classCache/ -Dosgi.checkConfiguration=false ${IBM_JAVA_OPTIONS}"
+
+USER 1001
+
+EXPOSE 9080 9443
+
+ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
+CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
+
diff --git a/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk11 b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk11
new file mode 100755
index 00000000..671663ac
--- /dev/null
+++ b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk11
@@ -0,0 +1,164 @@
+FROM registry.access.redhat.com/ubi10/ubi-minimal:latest AS builder
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_SHA=6394fee2c842008e9e36f3474c23330bfe467f48
+ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/openliberty-kernel/$LIBERTY_VERSION/openliberty-kernel-$LIBERTY_VERSION.zip
+
+ARG VERBOSE=false
+
+# If there is a local copy of the image use that instead
+COPY resources/ /tmp/
+
+# Install Open Liberty
+RUN microdnf -y install shadow-utils wget unzip openssl \
+ && if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
+ && echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
+ && sha1sum -c /tmp/wlp.zip.sha1 \
+ && chmod -R u+x /usr/bin \
+ && unzip -q /tmp/wlp.zip -d /opt/ol \
+ && mkdir -p /licenses \
+ && cp /opt/ol/wlp/LICENSE /licenses/ \
+ && adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+# Install dumb-init
+RUN set -eux; \
+ ARCH="$(uname -m)"; \
+ case "${ARCH}" in \
+ aarch64|arm64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
+ DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
+ ;; \
+ amd64|x86_64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
+ DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
+ ;; \
+ ppc64el|ppc64le) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
+ DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
+ ;; \
+ s390x) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
+ DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
+ ;;\
+ *) \
+ echo "Unsupported arch: ${ARCH}"; \
+ exit 1; \
+ ;; \
+ esac; \
+ curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
+ echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
+ chmod +x /usr/bin/dumb-init;
+
+FROM icr.io/appcafe/ibm-semeru-runtimes:open-11-jre-ubi10-micro
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_BUILD_LABEL=cl260820260725-1102
+
+ARG OPENJ9_SCC=true
+ARG VERBOSE=false
+
+LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
+ org.opencontainers.image.vendor="Open Liberty" \
+ org.opencontainers.image.url="https://openliberty.io/" \
+ org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
+ org.opencontainers.image.version="$LIBERTY_VERSION" \
+ org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
+ liberty.version="$LIBERTY_VERSION" \
+ io.openliberty.version="$LIBERTY_VERSION" \
+ vendor="Open Liberty" \
+ name="Open Liberty" \
+ version="$LIBERTY_VERSION" \
+ summary="Image for Open Liberty with IBM Semeru Runtime Open Edition OpenJDK 11 with OpenJ9 and UBI 10 micro" \
+ description="This image contains the Open Liberty runtime with IBM Semeru Runtime Open Edition OpenJDK 11 with OpenJ9 and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"
+
+COPY NOTICES /opt/ol/NOTICES
+COPY helpers /opt/ol/helpers
+COPY fixes/ /opt/ol/fixes/
+
+# Add default user 1001 and create wlp with right user/permissions before copying
+RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
+ && mkdir -p /home/1001 \
+ && chown 1001:0 /home/1001 \
+ && mkdir -p /opt/ol/wlp \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
+COPY --from=builder /usr/bin/awk /usr/bin/awk
+COPY --from=builder /usr/bin/wget /usr/bin/wget
+
+COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/
+
+# Copy the runtime and licenses
+COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+COPY --from=builder /licenses /licenses
+
+# Set Path Shortcuts
+ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
+ LOG_DIR=/liberty/logs \
+ WLP_OUTPUT_DIR=/opt/ol/wlp/output \
+ WLP_SKIP_MAXPERMSIZE=true \
+ OPENJ9_SCC=$OPENJ9_SCC
+
+# Configure Open Liberty
+RUN /opt/ol/wlp/bin/server create \
+ && rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env
+
+# Create symlinks && set permissions for non-root user
+RUN mkdir /logs \
+ && chown -R 1001:0 /logs \
+ && chmod -R g+rw /logs \
+ && mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
+ && ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
+ && mkdir -p $WLP_OUTPUT_DIR/defaultServer \
+ && ln -s $WLP_OUTPUT_DIR/defaultServer /output \
+ && ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
+ && mkdir -p /config/configDropins/defaults \
+ && mkdir -p /config/configDropins/overrides \
+ && ln -s /opt/ol/wlp /liberty \
+ && ln -s /opt/ol/fixes /fixes \
+ && echo "" > /config/configDropins/defaults/open-default-port.xml \
+ && chown -R 1001:0 /config \
+ && chmod -R g+rw /config \
+ && chown -R 1001:0 /opt/ol/wlp/usr \
+ && chmod -R g+rw /opt/ol/wlp/usr \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rw /opt/ol/wlp/output \
+ && chown -R 1001:0 /opt/ol/helpers \
+ && chmod -R ug+rwx /opt/ol/helpers \
+ && chown -R 1001:0 /opt/ol/fixes \
+ && chmod -R g+rwx /opt/ol/fixes \
+ && mkdir /etc/wlp \
+ && chown -R 1001:0 /etc/wlp \
+ && chmod -R g+rw /etc/wlp \
+ && if [ -e /etc/instanton.ld.so.cache ]; then chmod g+w /etc/ld.so.cache; fi \
+ && ln -s /logs /liberty/logs \
+ && mkdir /serviceability \
+ && chown -R 1001:0 /serviceability \
+ && chmod -R g+rw /serviceability
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rwx /opt/ol/wlp/output
+
+#These settings are needed so that we can run as a different user than 1001 after server warmup
+ENV RANDFILE=/tmp/.rnd \
+ OPENJ9_JAVA_OPTIONS="-XX:+IgnoreUnrecognizedVMOptions -XX:+IdleTuningGcOnIdle -Xshareclasses:name=openj9_system_scc,cacheDir=/opt/java/.scc,readonly,nonFatal -Dosgi.checkConfiguration=false"
+
+USER 1001
+
+EXPOSE 9080 9443
+
+ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
+CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
+
diff --git a/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk17 b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk17
new file mode 100755
index 00000000..c15410ac
--- /dev/null
+++ b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk17
@@ -0,0 +1,164 @@
+FROM registry.access.redhat.com/ubi10/ubi-minimal:latest AS builder
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_SHA=6394fee2c842008e9e36f3474c23330bfe467f48
+ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/openliberty-kernel/$LIBERTY_VERSION/openliberty-kernel-$LIBERTY_VERSION.zip
+
+ARG VERBOSE=false
+
+# If there is a local copy of the image use that instead
+COPY resources/ /tmp/
+
+# Install Open Liberty
+RUN microdnf -y install shadow-utils wget unzip openssl \
+ && if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
+ && echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
+ && sha1sum -c /tmp/wlp.zip.sha1 \
+ && chmod -R u+x /usr/bin \
+ && unzip -q /tmp/wlp.zip -d /opt/ol \
+ && mkdir -p /licenses \
+ && cp /opt/ol/wlp/LICENSE /licenses/ \
+ && adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+# Install dumb-init
+RUN set -eux; \
+ ARCH="$(uname -m)"; \
+ case "${ARCH}" in \
+ aarch64|arm64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
+ DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
+ ;; \
+ amd64|x86_64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
+ DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
+ ;; \
+ ppc64el|ppc64le) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
+ DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
+ ;; \
+ s390x) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
+ DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
+ ;;\
+ *) \
+ echo "Unsupported arch: ${ARCH}"; \
+ exit 1; \
+ ;; \
+ esac; \
+ curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
+ echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
+ chmod +x /usr/bin/dumb-init;
+
+FROM icr.io/appcafe/ibm-semeru-runtimes:open-17-jre-ubi10-micro
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_BUILD_LABEL=cl260820260725-1102
+
+ARG OPENJ9_SCC=true
+ARG VERBOSE=false
+
+LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
+ org.opencontainers.image.vendor="Open Liberty" \
+ org.opencontainers.image.url="https://openliberty.io/" \
+ org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
+ org.opencontainers.image.version="$LIBERTY_VERSION" \
+ org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
+ liberty.version="$LIBERTY_VERSION" \
+ io.openliberty.version="$LIBERTY_VERSION" \
+ vendor="Open Liberty" \
+ name="Open Liberty" \
+ version="$LIBERTY_VERSION" \
+ summary="Image for Open Liberty with IBM Semeru Runtime Open Edition OpenJDK 17 with OpenJ9 and UBI 10 micro" \
+ description="This image contains the Open Liberty runtime with IBM Semeru Runtime Open Edition OpenJDK 17 with OpenJ9 and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"
+
+COPY NOTICES /opt/ol/NOTICES
+COPY helpers /opt/ol/helpers
+COPY fixes/ /opt/ol/fixes/
+
+# Add default user 1001 and create wlp with right user/permissions before copying
+RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
+ && mkdir -p /home/1001 \
+ && chown 1001:0 /home/1001 \
+ && mkdir -p /opt/ol/wlp \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
+COPY --from=builder /usr/bin/awk /usr/bin/awk
+COPY --from=builder /usr/bin/wget /usr/bin/wget
+
+COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/
+
+# Copy the runtime and licenses
+COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+COPY --from=builder /licenses /licenses
+
+# Set Path Shortcuts
+ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
+ LOG_DIR=/liberty/logs \
+ WLP_OUTPUT_DIR=/opt/ol/wlp/output \
+ WLP_SKIP_MAXPERMSIZE=true \
+ OPENJ9_SCC=$OPENJ9_SCC
+
+# Configure Open Liberty
+RUN /opt/ol/wlp/bin/server create \
+ && rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env
+
+# Create symlinks && set permissions for non-root user
+RUN mkdir /logs \
+ && chown -R 1001:0 /logs \
+ && chmod -R g+rw /logs \
+ && mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
+ && ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
+ && mkdir -p $WLP_OUTPUT_DIR/defaultServer \
+ && ln -s $WLP_OUTPUT_DIR/defaultServer /output \
+ && ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
+ && mkdir -p /config/configDropins/defaults \
+ && mkdir -p /config/configDropins/overrides \
+ && ln -s /opt/ol/wlp /liberty \
+ && ln -s /opt/ol/fixes /fixes \
+ && echo "" > /config/configDropins/defaults/open-default-port.xml \
+ && chown -R 1001:0 /config \
+ && chmod -R g+rw /config \
+ && chown -R 1001:0 /opt/ol/wlp/usr \
+ && chmod -R g+rw /opt/ol/wlp/usr \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rw /opt/ol/wlp/output \
+ && chown -R 1001:0 /opt/ol/helpers \
+ && chmod -R ug+rwx /opt/ol/helpers \
+ && chown -R 1001:0 /opt/ol/fixes \
+ && chmod -R g+rwx /opt/ol/fixes \
+ && mkdir /etc/wlp \
+ && chown -R 1001:0 /etc/wlp \
+ && chmod -R g+rw /etc/wlp \
+ && if [ -e /etc/instanton.ld.so.cache ]; then chmod g+w /etc/ld.so.cache; fi \
+ && ln -s /logs /liberty/logs \
+ && mkdir /serviceability \
+ && chown -R 1001:0 /serviceability \
+ && chmod -R g+rw /serviceability
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rwx /opt/ol/wlp/output
+
+#These settings are needed so that we can run as a different user than 1001 after server warmup
+ENV RANDFILE=/tmp/.rnd \
+ OPENJ9_JAVA_OPTIONS="-XX:+IgnoreUnrecognizedVMOptions -XX:+IdleTuningGcOnIdle -Xshareclasses:name=openj9_system_scc,cacheDir=/opt/java/.scc,readonly,nonFatal -Dosgi.checkConfiguration=false"
+
+USER 1001
+
+EXPOSE 9080 9443
+
+ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
+CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
+
diff --git a/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk21 b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk21
new file mode 100755
index 00000000..0b69f6f2
--- /dev/null
+++ b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk21
@@ -0,0 +1,164 @@
+FROM registry.access.redhat.com/ubi10/ubi-minimal:latest AS builder
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_SHA=6394fee2c842008e9e36f3474c23330bfe467f48
+ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/openliberty-kernel/$LIBERTY_VERSION/openliberty-kernel-$LIBERTY_VERSION.zip
+
+ARG VERBOSE=false
+
+# If there is a local copy of the image use that instead
+COPY resources/ /tmp/
+
+# Install Open Liberty
+RUN microdnf -y install shadow-utils wget unzip openssl \
+ && if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
+ && echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
+ && sha1sum -c /tmp/wlp.zip.sha1 \
+ && chmod -R u+x /usr/bin \
+ && unzip -q /tmp/wlp.zip -d /opt/ol \
+ && mkdir -p /licenses \
+ && cp /opt/ol/wlp/LICENSE /licenses/ \
+ && adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+# Install dumb-init
+RUN set -eux; \
+ ARCH="$(uname -m)"; \
+ case "${ARCH}" in \
+ aarch64|arm64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
+ DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
+ ;; \
+ amd64|x86_64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
+ DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
+ ;; \
+ ppc64el|ppc64le) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
+ DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
+ ;; \
+ s390x) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
+ DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
+ ;;\
+ *) \
+ echo "Unsupported arch: ${ARCH}"; \
+ exit 1; \
+ ;; \
+ esac; \
+ curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
+ echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
+ chmod +x /usr/bin/dumb-init;
+
+FROM icr.io/appcafe/ibm-semeru-runtimes:open-21-jre-ubi10-micro
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_BUILD_LABEL=cl260820260725-1102
+
+ARG OPENJ9_SCC=true
+ARG VERBOSE=false
+
+LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
+ org.opencontainers.image.vendor="Open Liberty" \
+ org.opencontainers.image.url="https://openliberty.io/" \
+ org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
+ org.opencontainers.image.version="$LIBERTY_VERSION" \
+ org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
+ liberty.version="$LIBERTY_VERSION" \
+ io.openliberty.version="$LIBERTY_VERSION" \
+ vendor="Open Liberty" \
+ name="Open Liberty" \
+ version="$LIBERTY_VERSION" \
+ summary="Image for Open Liberty with IBM Semeru Runtime Open Edition OpenJDK 21 with OpenJ9 and UBI 10 micro" \
+ description="This image contains the Open Liberty runtime with IBM Semeru Runtime Open Edition OpenJDK 21 with OpenJ9 and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"
+
+COPY NOTICES /opt/ol/NOTICES
+COPY helpers /opt/ol/helpers
+COPY fixes/ /opt/ol/fixes/
+
+# Add default user 1001 and create wlp with right user/permissions before copying
+RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
+ && mkdir -p /home/1001 \
+ && chown 1001:0 /home/1001 \
+ && mkdir -p /opt/ol/wlp \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
+COPY --from=builder /usr/bin/awk /usr/bin/awk
+COPY --from=builder /usr/bin/wget /usr/bin/wget
+
+COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/
+
+# Copy the runtime and licenses
+COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+COPY --from=builder /licenses /licenses
+
+# Set Path Shortcuts
+ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
+ LOG_DIR=/liberty/logs \
+ WLP_OUTPUT_DIR=/opt/ol/wlp/output \
+ WLP_SKIP_MAXPERMSIZE=true \
+ OPENJ9_SCC=$OPENJ9_SCC
+
+# Configure Open Liberty
+RUN /opt/ol/wlp/bin/server create \
+ && rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env
+
+# Create symlinks && set permissions for non-root user
+RUN mkdir /logs \
+ && chown -R 1001:0 /logs \
+ && chmod -R g+rw /logs \
+ && mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
+ && ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
+ && mkdir -p $WLP_OUTPUT_DIR/defaultServer \
+ && ln -s $WLP_OUTPUT_DIR/defaultServer /output \
+ && ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
+ && mkdir -p /config/configDropins/defaults \
+ && mkdir -p /config/configDropins/overrides \
+ && ln -s /opt/ol/wlp /liberty \
+ && ln -s /opt/ol/fixes /fixes \
+ && echo "" > /config/configDropins/defaults/open-default-port.xml \
+ && chown -R 1001:0 /config \
+ && chmod -R g+rw /config \
+ && chown -R 1001:0 /opt/ol/wlp/usr \
+ && chmod -R g+rw /opt/ol/wlp/usr \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rw /opt/ol/wlp/output \
+ && chown -R 1001:0 /opt/ol/helpers \
+ && chmod -R ug+rwx /opt/ol/helpers \
+ && chown -R 1001:0 /opt/ol/fixes \
+ && chmod -R g+rwx /opt/ol/fixes \
+ && mkdir /etc/wlp \
+ && chown -R 1001:0 /etc/wlp \
+ && chmod -R g+rw /etc/wlp \
+ && if [ -e /etc/instanton.ld.so.cache ]; then chmod g+w /etc/ld.so.cache; fi \
+ && ln -s /logs /liberty/logs \
+ && mkdir /serviceability \
+ && chown -R 1001:0 /serviceability \
+ && chmod -R g+rw /serviceability
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rwx /opt/ol/wlp/output
+
+#These settings are needed so that we can run as a different user than 1001 after server warmup
+ENV RANDFILE=/tmp/.rnd \
+ OPENJ9_JAVA_OPTIONS="-XX:+IgnoreUnrecognizedVMOptions -XX:+IdleTuningGcOnIdle -Xshareclasses:name=openj9_system_scc,cacheDir=/opt/java/.scc,readonly,nonFatal -Dosgi.checkConfiguration=false"
+
+USER 1001
+
+EXPOSE 9080 9443
+
+ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
+CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
+
diff --git a/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk25 b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk25
new file mode 100755
index 00000000..71bc7950
--- /dev/null
+++ b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk25
@@ -0,0 +1,164 @@
+FROM registry.access.redhat.com/ubi10/ubi-minimal:latest AS builder
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_SHA=6394fee2c842008e9e36f3474c23330bfe467f48
+ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/openliberty-kernel/$LIBERTY_VERSION/openliberty-kernel-$LIBERTY_VERSION.zip
+
+ARG VERBOSE=false
+
+# If there is a local copy of the image use that instead
+COPY resources/ /tmp/
+
+# Install Open Liberty
+RUN microdnf -y install shadow-utils wget unzip openssl \
+ && if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
+ && echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
+ && sha1sum -c /tmp/wlp.zip.sha1 \
+ && chmod -R u+x /usr/bin \
+ && unzip -q /tmp/wlp.zip -d /opt/ol \
+ && mkdir -p /licenses \
+ && cp /opt/ol/wlp/LICENSE /licenses/ \
+ && adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+# Install dumb-init
+RUN set -eux; \
+ ARCH="$(uname -m)"; \
+ case "${ARCH}" in \
+ aarch64|arm64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
+ DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
+ ;; \
+ amd64|x86_64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
+ DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
+ ;; \
+ ppc64el|ppc64le) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
+ DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
+ ;; \
+ s390x) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
+ DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
+ ;;\
+ *) \
+ echo "Unsupported arch: ${ARCH}"; \
+ exit 1; \
+ ;; \
+ esac; \
+ curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
+ echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
+ chmod +x /usr/bin/dumb-init;
+
+FROM icr.io/appcafe/ibm-semeru-runtimes:open-25-jre-ubi10-micro
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_BUILD_LABEL=cl260820260725-1102
+
+ARG OPENJ9_SCC=true
+ARG VERBOSE=false
+
+LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
+ org.opencontainers.image.vendor="Open Liberty" \
+ org.opencontainers.image.url="https://openliberty.io/" \
+ org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
+ org.opencontainers.image.version="$LIBERTY_VERSION" \
+ org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
+ liberty.version="$LIBERTY_VERSION" \
+ io.openliberty.version="$LIBERTY_VERSION" \
+ vendor="Open Liberty" \
+ name="Open Liberty" \
+ version="$LIBERTY_VERSION" \
+ summary="Image for Open Liberty with IBM Semeru Runtime Open Edition OpenJDK 25 with OpenJ9 and UBI 10 micro" \
+ description="This image contains the Open Liberty runtime with IBM Semeru Runtime Open Edition OpenJDK 25 with OpenJ9 and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"
+
+COPY NOTICES /opt/ol/NOTICES
+COPY helpers /opt/ol/helpers
+COPY fixes/ /opt/ol/fixes/
+
+# Add default user 1001 and create wlp with right user/permissions before copying
+RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
+ && mkdir -p /home/1001 \
+ && chown 1001:0 /home/1001 \
+ && mkdir -p /opt/ol/wlp \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
+COPY --from=builder /usr/bin/awk /usr/bin/awk
+COPY --from=builder /usr/bin/wget /usr/bin/wget
+
+COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/
+
+# Copy the runtime and licenses
+COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+COPY --from=builder /licenses /licenses
+
+# Set Path Shortcuts
+ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
+ LOG_DIR=/liberty/logs \
+ WLP_OUTPUT_DIR=/opt/ol/wlp/output \
+ WLP_SKIP_MAXPERMSIZE=true \
+ OPENJ9_SCC=$OPENJ9_SCC
+
+# Configure Open Liberty
+RUN /opt/ol/wlp/bin/server create \
+ && rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env
+
+# Create symlinks && set permissions for non-root user
+RUN mkdir /logs \
+ && chown -R 1001:0 /logs \
+ && chmod -R g+rw /logs \
+ && mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
+ && ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
+ && mkdir -p $WLP_OUTPUT_DIR/defaultServer \
+ && ln -s $WLP_OUTPUT_DIR/defaultServer /output \
+ && ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
+ && mkdir -p /config/configDropins/defaults \
+ && mkdir -p /config/configDropins/overrides \
+ && ln -s /opt/ol/wlp /liberty \
+ && ln -s /opt/ol/fixes /fixes \
+ && echo "" > /config/configDropins/defaults/open-default-port.xml \
+ && chown -R 1001:0 /config \
+ && chmod -R g+rw /config \
+ && chown -R 1001:0 /opt/ol/wlp/usr \
+ && chmod -R g+rw /opt/ol/wlp/usr \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rw /opt/ol/wlp/output \
+ && chown -R 1001:0 /opt/ol/helpers \
+ && chmod -R ug+rwx /opt/ol/helpers \
+ && chown -R 1001:0 /opt/ol/fixes \
+ && chmod -R g+rwx /opt/ol/fixes \
+ && mkdir /etc/wlp \
+ && chown -R 1001:0 /etc/wlp \
+ && chmod -R g+rw /etc/wlp \
+ && if [ -e /etc/instanton.ld.so.cache ]; then chmod g+w /etc/ld.so.cache; fi \
+ && ln -s /logs /liberty/logs \
+ && mkdir /serviceability \
+ && chown -R 1001:0 /serviceability \
+ && chmod -R g+rw /serviceability
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rwx /opt/ol/wlp/output
+
+#These settings are needed so that we can run as a different user than 1001 after server warmup
+ENV RANDFILE=/tmp/.rnd \
+ OPENJ9_JAVA_OPTIONS="-XX:+IgnoreUnrecognizedVMOptions -XX:+IdleTuningGcOnIdle -Xshareclasses:name=openj9_system_scc,cacheDir=/opt/java/.scc,readonly,nonFatal -Dosgi.checkConfiguration=false"
+
+USER 1001
+
+EXPOSE 9080 9443
+
+ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
+CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
+
diff --git a/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk8 b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk8
new file mode 100755
index 00000000..f6fb8586
--- /dev/null
+++ b/releases/latest/kernel-slim/Dockerfile.ubi10-micro.openjdk8
@@ -0,0 +1,164 @@
+FROM registry.access.redhat.com/ubi10/ubi-minimal:latest AS builder
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_SHA=6394fee2c842008e9e36f3474c23330bfe467f48
+ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/openliberty-kernel/$LIBERTY_VERSION/openliberty-kernel-$LIBERTY_VERSION.zip
+
+ARG VERBOSE=false
+
+# If there is a local copy of the image use that instead
+COPY resources/ /tmp/
+
+# Install Open Liberty
+RUN microdnf -y install shadow-utils wget unzip openssl \
+ && if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
+ && echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
+ && sha1sum -c /tmp/wlp.zip.sha1 \
+ && chmod -R u+x /usr/bin \
+ && unzip -q /tmp/wlp.zip -d /opt/ol \
+ && mkdir -p /licenses \
+ && cp /opt/ol/wlp/LICENSE /licenses/ \
+ && adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+# Install dumb-init
+RUN set -eux; \
+ ARCH="$(uname -m)"; \
+ case "${ARCH}" in \
+ aarch64|arm64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
+ DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
+ ;; \
+ amd64|x86_64) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
+ DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
+ ;; \
+ ppc64el|ppc64le) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
+ DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
+ ;; \
+ s390x) \
+ DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
+ DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
+ ;;\
+ *) \
+ echo "Unsupported arch: ${ARCH}"; \
+ exit 1; \
+ ;; \
+ esac; \
+ curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
+ echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
+ chmod +x /usr/bin/dumb-init;
+
+FROM icr.io/appcafe/ibm-semeru-runtimes:open-8-jre-ubi10-micro
+
+USER root
+
+ARG LIBERTY_VERSION=26.0.0.8
+ARG LIBERTY_BUILD_LABEL=cl260820260725-1102
+
+ARG OPENJ9_SCC=true
+ARG VERBOSE=false
+
+LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
+ org.opencontainers.image.vendor="Open Liberty" \
+ org.opencontainers.image.url="https://openliberty.io/" \
+ org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
+ org.opencontainers.image.version="$LIBERTY_VERSION" \
+ org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
+ liberty.version="$LIBERTY_VERSION" \
+ io.openliberty.version="$LIBERTY_VERSION" \
+ vendor="Open Liberty" \
+ name="Open Liberty" \
+ version="$LIBERTY_VERSION" \
+ summary="Image for Open Liberty with IBM Semeru Runtime Open Edition OpenJDK 8 with OpenJ9 and UBI 10 micro" \
+ description="This image contains the Open Liberty runtime with IBM Semeru Runtime Open Edition OpenJDK 8 with OpenJ9 and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"
+
+COPY NOTICES /opt/ol/NOTICES
+COPY helpers /opt/ol/helpers
+COPY fixes/ /opt/ol/fixes/
+
+# Add default user 1001 and create wlp with right user/permissions before copying
+RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
+ && mkdir -p /home/1001 \
+ && chown 1001:0 /home/1001 \
+ && mkdir -p /opt/ol/wlp \
+ && chown -R 1001:0 /opt/ol/wlp \
+ && chmod -R g+rw /opt/ol/wlp
+
+COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
+COPY --from=builder /usr/bin/awk /usr/bin/awk
+COPY --from=builder /usr/bin/wget /usr/bin/wget
+
+COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
+COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/
+
+# Copy the runtime and licenses
+COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
+COPY --from=builder /licenses /licenses
+
+# Set Path Shortcuts
+ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
+ LOG_DIR=/liberty/logs \
+ WLP_OUTPUT_DIR=/opt/ol/wlp/output \
+ WLP_SKIP_MAXPERMSIZE=true \
+ OPENJ9_SCC=$OPENJ9_SCC
+
+# Configure Open Liberty
+RUN /opt/ol/wlp/bin/server create \
+ && rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env
+
+# Create symlinks && set permissions for non-root user
+RUN mkdir /logs \
+ && chown -R 1001:0 /logs \
+ && chmod -R g+rw /logs \
+ && mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
+ && ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
+ && mkdir -p $WLP_OUTPUT_DIR/defaultServer \
+ && ln -s $WLP_OUTPUT_DIR/defaultServer /output \
+ && ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
+ && mkdir -p /config/configDropins/defaults \
+ && mkdir -p /config/configDropins/overrides \
+ && ln -s /opt/ol/wlp /liberty \
+ && ln -s /opt/ol/fixes /fixes \
+ && echo "" > /config/configDropins/defaults/open-default-port.xml \
+ && chown -R 1001:0 /config \
+ && chmod -R g+rw /config \
+ && chown -R 1001:0 /opt/ol/wlp/usr \
+ && chmod -R g+rw /opt/ol/wlp/usr \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rw /opt/ol/wlp/output \
+ && chown -R 1001:0 /opt/ol/helpers \
+ && chmod -R ug+rwx /opt/ol/helpers \
+ && chown -R 1001:0 /opt/ol/fixes \
+ && chmod -R g+rwx /opt/ol/fixes \
+ && mkdir /etc/wlp \
+ && chown -R 1001:0 /etc/wlp \
+ && chmod -R g+rw /etc/wlp \
+ && if [ -e /etc/instanton.ld.so.cache ]; then chmod g+w /etc/ld.so.cache; fi \
+ && ln -s /logs /liberty/logs \
+ && mkdir /serviceability \
+ && chown -R 1001:0 /serviceability \
+ && chmod -R g+rw /serviceability
+
+# Create a new SCC layer
+RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
+ && rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache /output/workarea \
+ && chown -R 1001:0 /opt/ol/wlp/output \
+ && chmod -R g+rwx /opt/ol/wlp/output
+
+#These settings are needed so that we can run as a different user than 1001 after server warmup
+ENV RANDFILE=/tmp/.rnd \
+ OPENJ9_JAVA_OPTIONS="-XX:+IgnoreUnrecognizedVMOptions -XX:+IdleTuningGcOnIdle -Xshareclasses:name=openj9_system_scc,cacheDir=/opt/java/.scc,readonly,nonFatal -Dosgi.checkConfiguration=false"
+
+USER 1001
+
+EXPOSE 9080 9443
+
+ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
+CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
+
diff --git a/releases/latest/kernel-slim/helpers/build/populate_scc.sh b/releases/latest/kernel-slim/helpers/build/populate_scc.sh
index 1012a07a..1c1fc7dd 100755
--- a/releases/latest/kernel-slim/helpers/build/populate_scc.sh
+++ b/releases/latest/kernel-slim/helpers/build/populate_scc.sh
@@ -81,10 +81,10 @@ do
-s Size of the SCC in megabytes (m suffix required). (Default: $SCC_SIZE)
-t Trim the SCC to eliminate most of the free space, if any.
-d Don't trim the SCC.
- -w Use curl to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
+ -w Use curl/wget to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
-c Do not warm an endpoint during SCC creation.
-u The URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_URL)
- -m Use curl to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
+ -m Use curl/wget to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
-l Do not warm the openapi endpoint during SCC creation.
-o The Open API URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_OPENAPI_URL)
@@ -105,6 +105,13 @@ done
OLD_UMASK=`umask`
umask 002 # 002 is required to provide group rw permission to the cache when `-Xshareclasses:groupAccess` options is used
+# Use curl/wget to warm endpoints
+if command -v curl > /dev/null 2>&1; then
+ http_get() { curl --silent --output /dev/null --show-error --fail --max-time 5 "$1"; }
+else
+ http_get() { wget -q -O /dev/null -T 5 "$1"; }
+fi
+
# Explicity create a class cache layer for this image layer here rather than allowing
# `server start` to do it, which will lead to problems because multiple JVMs will be started.
java $CREATE_LAYER -Xscmx$SCC_SIZE -version
@@ -117,11 +124,11 @@ then
if [ ${WARM_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi
/opt/ol/wlp/bin/server stop
@@ -152,11 +159,11 @@ do
if [ ${WARM_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
- curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
+ http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi
/opt/ol/wlp/bin/server stop