Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
165 changes: 165 additions & 0 deletions releases/latest/beta/Dockerfile.ubi10-micro.openjdk25
Original file line number Diff line number Diff line change
@@ -0,0 +1,165 @@
FROM registry.access.redhat.com/ubi10/ubi-minimal:latest AS builder

USER root

ARG LIBERTY_VERSION=26.0.0.9-beta
ARG LIBERTY_SHA=52af30086cb86dca8d028182eaf4091e83362fac
ARG LIBERTY_DOWNLOAD_URL=https://repo1.maven.org/maven2/io/openliberty/beta/openliberty-runtime/$LIBERTY_VERSION/openliberty-runtime-$LIBERTY_VERSION.zip

ARG VERBOSE=false

# If there is a local copy of the image use that instead
COPY resources/ /tmp/

# Install Open Liberty
RUN microdnf -y install shadow-utils wget unzip openssl \
&& if [ ! -f /tmp/wlp.zip ]; then wget -q $LIBERTY_DOWNLOAD_URL -U UA-Open-Liberty-Docker -O /tmp/wlp.zip; fi \
&& echo "$LIBERTY_SHA /tmp/wlp.zip" > /tmp/wlp.zip.sha1 \
&& sha1sum -c /tmp/wlp.zip.sha1 \
&& chmod -R u+x /usr/bin \
&& unzip -q /tmp/wlp.zip -d /opt/ol \
&& mkdir -p /licenses \
&& cp /opt/ol/wlp/LICENSE /licenses/ \
&& adduser -u 1001 -r -g root -s /usr/sbin/nologin default \
&& chown -R 1001:0 /opt/ol/wlp \
&& chmod -R g+rw /opt/ol/wlp

# Install dumb-init
RUN set -eux; \
ARCH="$(uname -m)"; \
case "${ARCH}" in \
aarch64|arm64) \
DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_aarch64'; \
DUMB_INIT_SHA256=b7d648f97154a99c539b63c55979cd29f005f88430fb383007fe3458340b795e; \
;; \
amd64|x86_64) \
DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_x86_64'; \
DUMB_INIT_SHA256=e874b55f3279ca41415d290c512a7ba9d08f98041b28ae7c2acb19a545f1c4df; \
;; \
ppc64el|ppc64le) \
DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_ppc64le'; \
DUMB_INIT_SHA256=3d15e80e29f0f4fa1fc686b00613a2220bc37e83a35283d4b4cca1fbd0a5609f; \
;; \
s390x) \
DUMB_INIT_URL='https://github.com/Yelp/dumb-init/releases/download/v1.2.5/dumb-init_1.2.5_s390x'; \
DUMB_INIT_SHA256=47e4601b152fc6dcb1891e66c30ecc62a2939fd7ffd1515a7c30f281cfec53b7; \
;;\
*) \
echo "Unsupported arch: ${ARCH}"; \
exit 1; \
;; \
esac; \
curl -LfsSo /usr/bin/dumb-init ${DUMB_INIT_URL}; \
echo "${DUMB_INIT_SHA256} */usr/bin/dumb-init" | sha256sum -c -; \
chmod +x /usr/bin/dumb-init;

FROM icr.io/appcafe/ibm-semeru-runtimes:open-25-jre-ubi10-micro

USER root

ARG LIBERTY_VERSION=26.0.0.9-beta
ARG LIBERTY_BUILD_LABEL=cl260820260725-1102

ARG OPENJ9_SCC=true
ARG VERBOSE=false

LABEL org.opencontainers.image.authors="Leo Christy Jesuraj, Iain Lewis, Melissa Lee, Kirby Chin" \
org.opencontainers.image.vendor="Open Liberty" \
org.opencontainers.image.url="https://openliberty.io/" \
org.opencontainers.image.source="https://github.com/OpenLiberty/ci.docker" \
org.opencontainers.image.version="$LIBERTY_VERSION" \
org.opencontainers.image.revision="$LIBERTY_BUILD_LABEL" \
liberty.version="$LIBERTY_VERSION" \
io.openliberty.version="$LIBERTY_VERSION" \
vendor="Open Liberty" \
name="Open Liberty Beta" \
version="$LIBERTY_VERSION" \
summary="Image for Open Liberty Beta with IBM Semeru Runtime Open Edition OpenJDK 25 with OpenJ9 and UBI 10 micro" \
description="This image contains the Open Liberty beta runtime with IBM Semeru Runtime Open Edition OpenJDK 25 with OpenJ9 and Red Hat UBI 10 micro as the base OS. For more information on this image please see https://github.com/OpenLiberty/ci.docker#building-an-application-image"

COPY NOTICES /opt/ol/NOTICES
COPY helpers /opt/ol/helpers
COPY fixes/ /opt/ol/fixes/

# Add default user 1001 and create wlp with right user/permissions before copying
RUN echo "1001:x:1001:0::/home/1001:/sbin/nologin" >> /etc/passwd \
&& mkdir -p /home/1001 \
&& chown 1001:0 /home/1001 \
&& mkdir -p /opt/ol/wlp \
&& chown -R 1001:0 /opt/ol/wlp \
&& chmod -R g+rw /opt/ol/wlp

COPY --from=builder /usr/bin/dumb-init /usr/bin/dumb-init
COPY --from=builder /usr/bin/awk /usr/bin/awk
COPY --from=builder /usr/bin/wget /usr/bin/wget

COPY --from=builder /usr/lib64/libpsl.so* /usr/lib64/
COPY --from=builder /usr/lib64/libmpfr.so* /usr/lib64/

# Copy the runtime and licenses
COPY --from=builder --chown=1001:0 /opt/ol/wlp /opt/ol/wlp
COPY --from=builder /licenses /licenses

# Set Path Shortcuts
ENV PATH=$PATH:/opt/ol/wlp/bin:/opt/ol/helpers/build:/opt/ol/helpers/runtime \
LOG_DIR=/liberty/logs \
WLP_OUTPUT_DIR=/opt/ol/wlp/output \
WLP_SKIP_MAXPERMSIZE=true \
OPENJ9_SCC=$OPENJ9_SCC

# Configure Open Liberty
RUN /opt/ol/wlp/bin/server create --template=javaee8 \
&& rm -rf $WLP_OUTPUT_DIR/.classCache /output/workarea \
&& rm -rf /opt/ol/wlp/usr/servers/defaultServer/server.env

# Create symlinks && set permissions for non-root user
RUN mkdir /logs \
&& chown -R 1001:0 /logs \
&& chmod -R g+rw /logs \
&& mkdir -p /opt/ol/wlp/usr/shared/resources/lib.index.cache \
&& ln -s /opt/ol/wlp/usr/shared/resources/lib.index.cache /lib.index.cache \
&& mkdir -p $WLP_OUTPUT_DIR/defaultServer \
&& ln -s $WLP_OUTPUT_DIR/defaultServer /output \
&& ln -s /opt/ol/wlp/usr/servers/defaultServer /config \
&& mkdir -p /config/configDropins/defaults \
&& mkdir -p /config/configDropins/overrides \
&& mkdir -p /config/dropins \
&& mkdir -p /config/apps \
&& ln -s /opt/ol/wlp /liberty \
&& ln -s /opt/ol/fixes /fixes \
&& chown -R 1001:0 /config \
&& chmod -R g+rw /config \
&& chown -R 1001:0 /opt/ol/wlp/usr \
&& chmod -R g+rw /opt/ol/wlp/usr \
&& chown -R 1001:0 /opt/ol/wlp/output \
&& chmod -R g+rw /opt/ol/wlp/output \
&& chown -R 1001:0 /opt/ol/helpers \
&& chmod -R ug+rwx /opt/ol/helpers \
&& chown -R 1001:0 /opt/ol/fixes \
&& chmod -R g+rwx /opt/ol/fixes \
&& mkdir /etc/wlp \
&& chown -R 1001:0 /etc/wlp \
&& chmod -R g+rw /etc/wlp \
&& if [ -e /etc/instanton.ld.so.cache ]; then chmod g+w /etc/ld.so.cache; fi \
&& echo "<server description=\"Default Server\"><httpEndpoint id=\"defaultHttpEndpoint\" host=\"*\" /></server>" > /config/configDropins/defaults/open-default-port.xml \
&& ln -s /logs /liberty/logs \
&& mkdir /serviceability \
&& chown -R 1001:0 /serviceability \
&& chmod -R g+rw /serviceability

# Create a new SCC layer
RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
&& rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
&& chown -R 1001:0 /opt/ol/wlp/output \
&& chmod -R g+rwx /opt/ol/wlp/output

#These settings are needed so that we can run as a different user than 1001 after server warmup
ENV RANDFILE=/tmp/.rnd \
OPENJ9_JAVA_OPTIONS="-XX:+IgnoreUnrecognizedVMOptions -XX:+IdleTuningGcOnIdle -Xshareclasses:name=openj9_system_scc,cacheDir=/opt/java/.scc,readonly,nonFatal -Dosgi.checkConfiguration=false"

USER 1001

EXPOSE 9080 9443

ENTRYPOINT ["/opt/ol/helpers/runtime/docker-server.sh"]
CMD ["/opt/ol/wlp/bin/server", "run", "defaultServer"]
19 changes: 13 additions & 6 deletions releases/latest/beta/helpers/build/populate_scc.sh
Original file line number Diff line number Diff line change
Expand Up @@ -76,10 +76,10 @@ do
-s <size> Size of the SCC in megabytes (m suffix required). (Default: $SCC_SIZE)
-t Trim the SCC to eliminate most of the free space, if any.
-d Don't trim the SCC.
-w Use curl to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
-w Use curl/wget to warm an endpoint during SCC creation. (Default: $WARM_ENDPOINT)
-c Do not warm an endpoint during SCC creation.
-u The URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_URL)
-m Use curl to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
-m Use curl/wget to warm the openapi endpoint during SCC creation. (Default: $WARM_OPENAPI_ENDPOINT)
-l Do not warm the openapi endpoint during SCC creation.
-o The Open API URL endpoint to warm during SCC creation. (Default: $WARM_ENDPOINT_OPENAPI_URL)

Expand All @@ -100,6 +100,13 @@ done
OLD_UMASK=`umask`
umask 002 # 002 is required to provide group rw permission to the cache when `-Xshareclasses:groupAccess` options is used

# Use curl/wget to warm endpoints
if command -v curl > /dev/null 2>&1; then
http_get() { curl --silent --output /dev/null --show-error --fail --max-time 5 "$1"; }
else
http_get() { wget -q -O /dev/null -T 5 "$1"; }
fi

# Explicity create a class cache layer for this image layer here rather than allowing
# `server start` to do it, which will lead to problems because multiple JVMs will be started.
java $CREATE_LAYER -Xscmx$SCC_SIZE -version
Expand All @@ -112,11 +119,11 @@ then

if [ ${WARM_ENDPOINT} == true ]
then
curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi

/opt/ol/wlp/bin/server stop
Expand Down Expand Up @@ -147,11 +154,11 @@ do

if [ ${WARM_ENDPOINT} == true ]
then
curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
http_get ${WARM_ENDPOINT_URL} 2>&1 || echo "${WARM_ENDPOINT_URL} call failed, continuing"
fi
if [ ${WARM_OPENAPI_ENDPOINT} == true ]
then
curl --silent --output /dev/null --show-error --fail --max-time 5 ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
http_get ${WARM_OPENAPI_ENDPOINT_URL} 2>&1 || echo "${WARM_OPENAPI_ENDPOINT_URL} call failed, continuing"
fi

/opt/ol/wlp/bin/server stop
Expand Down
53 changes: 53 additions & 0 deletions releases/latest/full/Dockerfile.ubi10-micro.ibmjava8
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java8-ibmjava-ubi-micro

# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
RUN microdnf -y install unzip && microdnf clean all

FROM $PARENT_IMAGE AS installBundle

ARG VERBOSE=false
ARG LIBERTY_VERSION=26.0.0.8
ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419

# If there is a local copy of the repository use that instead
COPY resources/ /tmp/

# We need unzip when using a local repo; copy it from ubi-minimal builder stage
USER root
COPY --from=builder /usr/bin/unzip /usr/bin/unzip
COPY --from=builder /usr/lib64/libbz2.so* /usr/lib64/
USER 1001

# Install all features
RUN set -eux; \
if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
else \
echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
export FEATURE_VERIFY=skip; \
fi; \
grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
rm -rf /output/workarea /output/logs; \
find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;

ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java8-ibmjava-ubi-micro
FROM $PARENT_IMAGE
ARG VERBOSE=false

# Copy the runtime
COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp

COPY --chown=1001:0 server.xml /config/

# Create a new SCC layer
RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
&& rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
&& find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
52 changes: 52 additions & 0 deletions releases/latest/full/Dockerfile.ubi10-micro.openjdk11
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java11-openj9-ubi-micro

# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
RUN microdnf -y install unzip && microdnf clean all

FROM $PARENT_IMAGE AS installBundle

ARG VERBOSE=false
ARG LIBERTY_VERSION=26.0.0.8
ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419

# If there is a local copy of the repository use that instead
COPY resources/ /tmp/

# We need unzip when using a local repo; copy it from ubi-minimal builder stage
USER root
COPY --from=builder /usr/bin/unzip /usr/bin/unzip
USER 1001

# Install all features
RUN set -eux; \
if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
else \
echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
export FEATURE_VERIFY=skip; \
fi; \
grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
rm -rf /output/workarea /output/logs; \
find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;

ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java11-openj9-ubi-micro
FROM $PARENT_IMAGE
ARG VERBOSE=false

# Copy the runtime
COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp

COPY --chown=1001:0 server.xml /config/

# Create a new SCC layer
RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
&& rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
&& find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
52 changes: 52 additions & 0 deletions releases/latest/full/Dockerfile.ubi10-micro.openjdk17
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java17-openj9-ubi-micro

# ubi-micro has no package manager; install unzip from ubi-minimal and copy it in
FROM registry.access.redhat.com/ubi10/ubi-minimal AS builder
RUN microdnf -y install unzip && microdnf clean all

FROM $PARENT_IMAGE AS installBundle

ARG VERBOSE=false
ARG LIBERTY_VERSION=26.0.0.8
ARG FEATURES_SHA=534d4f1b2b8cf34903b36f6e3780915f82a35419

# If there is a local copy of the repository use that instead
COPY resources/ /tmp/

# We need unzip when using a local repo; copy it from ubi-minimal builder stage
USER root
COPY --from=builder /usr/bin/unzip /usr/bin/unzip
USER 1001

# Install all features
RUN set -eux; \
if [ ! -f /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip ]; then \
wget -q https://repo1.maven.org/maven2/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json -O /tmp/features-$LIBERTY_VERSION.json; \
echo "$FEATURES_SHA /tmp/features-$LIBERTY_VERSION.json" > /tmp/features-$LIBERTY_VERSION.json.sha1; \
sha1sum -c /tmp/features-$LIBERTY_VERSION.json.sha1; \
else \
echo "$FEATURES_SHA /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip" > /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
sha1sum -c /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip.sha1; \
mkdir /tmp/feature-repo-$LIBERTY_VERSION; \
unzip -d /tmp/feature-repo-$LIBERTY_VERSION /tmp/openliberty-MavenArtifact-$LIBERTY_VERSION.zip; \
cp /tmp/feature-repo-$LIBERTY_VERSION/io/openliberty/features/features/$LIBERTY_VERSION/features-$LIBERTY_VERSION.json /tmp; \
export FEATURE_LOCAL_REPO=/tmp/feature-repo-$LIBERTY_VERSION; \
export FEATURE_VERIFY=skip; \
fi; \
grep \"shortName\" /tmp/features-$LIBERTY_VERSION.json | sed -e 's/.* //' -e 's/,//' | xargs featureUtility installFeature --acceptLicense --noCache; \
rm -rf /output/workarea /output/logs; \
find /opt/ol/wlp ! -perm -g=rw -print0 | xargs -r -0 chmod g+rw;

ARG PARENT_IMAGE=icr.io/appcafe/open-liberty:kernel-slim-java17-openj9-ubi-micro
FROM $PARENT_IMAGE
ARG VERBOSE=false

# Copy the runtime
COPY --from=installBundle --chown=1001:0 /opt/ol/wlp /opt/ol/wlp

COPY --chown=1001:0 server.xml /config/

# Create a new SCC layer
RUN if [ "$OPENJ9_SCC" = "true" ]; then populate_scc.sh; fi \
&& rm -rf /output/messaging /output/resources/security /logs/* $WLP_OUTPUT_DIR/.classCache \
&& find /opt/ol/wlp/output ! -perm -g=rwx -print0 | xargs -0 -r chmod g+rwx
Loading