├── .gitignore ├── Dockerfile ├── Dockerfiles ├── .dockerignore ├── 0-Dockerfile-original ├── 1-Dockerfile-specific-image ├── 2-Dockerfile-do-not-run-as-root ├── 3-Dockerfile-use-workdir ├── 4-Dockerfile-use-entrypoint ├── 5-Dockerfile-use-copy-instead-of-add ├── 6-Dockerfile-healthcheck ├── 7-Dockerfile-multi-stage-build └── 8-Dockerfile-spring-boot-docker-layers ├── README.md ├── compose.yml ├── dcs ├── 0-Dockerfile-original ├── 1-Dockerfile-specific-image ├── 10-Dockerfile-spring-boot-docker-layers ├── 2-Dockerfile-do-not-run-as-root ├── 3-Dockerfile-use-workdir ├── 4-Dockerfile-use-entrypoint ├── 5-Dockerfile-use-copy-instead-of-add ├── 6-use-dockerignore-file ├── 7-Dockerfile-healthcheck ├── 8-compose-healthcheck.yml ├── 9-Dockerfile-multistage-build └── solutions │ ├── 1-Dockerfile-specific-image │ ├── 10-Dockerfile-spring-boot-docker-layers │ ├── 2-Dockerfile-do-not-run-as-root │ ├── 3-Dockerfile-use-workdir │ ├── 4-Dockerfile-use-entrypoint │ ├── 5-Dockerfile-use-copy-instead-of-add │ ├── 7-Dockerfile-healthcheck │ ├── 8-compose-healthcheck.yml │ └── 9-Dockerfile-multistage-build ├── mvnw ├── mvnw.cmd ├── pom.xml └── src ├── main ├── java │ └── com │ │ └── mydeveloperplanet │ │ └── mydockerbestpracticesplanet │ │ ├── DownHealthIndicator.java │ │ ├── HelloController.java │ │ └── MyDockerBestPracticesPlanetApplication.java └── resources │ └── application.properties └── test └── java └── com └── mydeveloperplanet └── mydockerbestpracticesplanet └── MyDockerBestPracticesPlanetApplicationTests.java /.gitignore: -------------------------------------------------------------------------------- 1 | HELP.md 2 | target/ 3 | !.mvn/wrapper/maven-wrapper.jar 4 | !**/src/main/**/target/ 5 | !**/src/test/**/target/ 6 | 7 | ### STS ### 8 | .apt_generated 9 | .classpath 10 | .factorypath 11 | .project 12 | .settings 13 | .springBeans 14 | .sts4-cache 15 | 16 | ### IntelliJ IDEA ### 17 | .idea 18 | *.iws 19 | *.iml 20 | *.ipr 21 | 22 | ### NetBeans ### 23 | /nbproject/private/ 24 | /nbbuild/ 25 | /dist/ 26 | /nbdist/ 27 | /.nb-gradle/ 28 | build/ 29 | !**/src/main/**/build/ 30 | !**/src/test/**/build/ 31 | 32 | ### VS Code ### 33 | .vscode/ 34 | -------------------------------------------------------------------------------- /Dockerfile: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17 2 | RUN mkdir /opt/app 3 | ARG JAR_FILE 4 | ADD target/${JAR_FILE} /opt/app/app.jar 5 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/.dockerignore: -------------------------------------------------------------------------------- 1 | **/** 2 | !target/*.jar -------------------------------------------------------------------------------- /Dockerfiles/0-Dockerfile-original: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17 2 | RUN mkdir /opt/app 3 | ARG JAR_FILE 4 | ADD target/${JAR_FILE} /opt/app/app.jar 5 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/1-Dockerfile-specific-image: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 2 | RUN mkdir /opt/app 3 | ARG JAR_FILE 4 | ADD target/${JAR_FILE} /opt/app/app.jar 5 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/2-Dockerfile-do-not-run-as-root: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 2 | RUN mkdir /opt/app 3 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 4 | ARG JAR_FILE 5 | ADD target/${JAR_FILE} /opt/app/app.jar 6 | RUN chown -R javauser:javauser /opt/app 7 | USER javauser 8 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/3-Dockerfile-use-workdir: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 2 | WORKDIR /opt/app 3 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 4 | ARG JAR_FILE 5 | ADD target/${JAR_FILE} app.jar 6 | RUN chown -R javauser:javauser . 7 | USER javauser 8 | CMD ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/4-Dockerfile-use-entrypoint: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 2 | WORKDIR /opt/app 3 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 4 | ARG JAR_FILE 5 | ADD target/${JAR_FILE} app.jar 6 | RUN chown -R javauser:javauser . 7 | USER javauser 8 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/5-Dockerfile-use-copy-instead-of-add: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 2 | WORKDIR /opt/app 3 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 4 | ARG JAR_FILE 5 | COPY target/${JAR_FILE} app.jar 6 | RUN chown -R javauser:javauser . 7 | USER javauser 8 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/6-Dockerfile-healthcheck: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 2 | WORKDIR /opt/app 3 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 4 | ARG JAR_FILE 5 | COPY target/${JAR_FILE} app.jar 6 | RUN chown -R javauser:javauser . 7 | USER javauser 8 | HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 9 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/7-Dockerfile-multi-stage-build: -------------------------------------------------------------------------------- 1 | FROM maven:3.8.6-eclipse-temurin-17-alpine@sha256:e88c1a981319789d0c00cd508af67a9c46524f177ecc66ca37c107d4c371d23b AS builder 2 | WORKDIR /build 3 | COPY . . 4 | RUN mvn clean package -DskipTests 5 | 6 | FROM eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 7 | WORKDIR /opt/app 8 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 9 | COPY --from=builder /build/target/mydockerbestpracticesplanet-0.0.1-SNAPSHOT.jar app.jar 10 | RUN chown -R javauser:javauser . 11 | USER javauser 12 | HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 13 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /Dockerfiles/8-Dockerfile-spring-boot-docker-layers: -------------------------------------------------------------------------------- 1 | FROM eclipse-temurin:17.0.4.1_1-jre-alpine@sha256:e1506ba20f0cb2af6f23e24c7f8855b417f0b085708acd9b85344a884ba77767 AS builder 2 | WORKDIR application 3 | ARG JAR_FILE 4 | COPY target/${JAR_FILE} app.jar 5 | RUN java -Djarmode=layertools -jar app.jar extract 6 | 7 | FROM eclipse-temurin:17.0.4.1_1-jre-alpine@sha256:e1506ba20f0cb2af6f23e24c7f8855b417f0b085708acd9b85344a884ba77767 8 | WORKDIR /opt/app 9 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 10 | COPY --from=builder application/dependencies/ ./ 11 | COPY --from=builder application/spring-boot-loader/ ./ 12 | COPY --from=builder application/snapshot-dependencies/ ./ 13 | COPY --from=builder application/application/ ./ 14 | RUN chown -R javauser:javauser . 15 | USER javauser 16 | HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 17 | ENTRYPOINT ["java", "org.springframework.boot.loader.JarLauncher"] -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # mydockerbestpracticesplanet 2 | 3 | The corresponding blog posts for this repository is: 4 | 5 | https://mydeveloperplanet.com/2022/11/30/docker-best-practices/ 6 | 7 | https://mydeveloperplanet.com/2022/12/14/spring-boot-docker-best-practices/ 8 | 9 | Exercises based on the blogs can be found in the [dcs directory](dcs). 10 | The solutions can be found in the [solutions directory](dcs/solutions). -------------------------------------------------------------------------------- /compose.yml: -------------------------------------------------------------------------------- 1 | services: 2 | dockerbestpractices: 3 | image: mydeveloperplanet/dockerbestpractices:0.0.1-SNAPSHOT 4 | 5 | autoheal: 6 | image: willfarrell/autoheal:1.2.0 7 | restart: always 8 | environment: 9 | AUTOHEAL_CONTAINER_LABEL: all 10 | volumes: 11 | - type: bind 12 | source: /var/run/docker.sock 13 | target: /var/run/docker.sock -------------------------------------------------------------------------------- /dcs/0-Dockerfile-original: -------------------------------------------------------------------------------- 1 | # Build the jar-file: mvn clean verify 2 | # or 3 | # download the jar-file and copy it in the target directory: https://github.com/mydeveloperplanet/mydockerbestpracticesplanet/releases/tag/V0.0.1-SNAPSHOT 4 | # 5 | # Try to build the docker image, execute the following command from the root from the repository 6 | # docker build . --tag mydeveloperplanet/dockerbestpractices:0.0.1-SNAPSHOT -f dcs/0-Dockerfile-original --build-arg JAR_FILE=mydockerbestpracticesplanet-0.0.1-SNAPSHOT.jar 7 | # 8 | # Run the container 9 | # docker run --rm -p 8080:8080 --name dockerbestpractices -d mydeveloperplanet/dockerbestpractices:0.0.1-SNAPSHOT 10 | # 11 | # Verify the container is running: docker ps 12 | # 13 | # Invoke the endpoint: curl http://localhost:8080/hello 14 | # Or just use the browser 15 | # 16 | # Stop the container: docker stop dockerbestpractices 17 | FROM eclipse-temurin:17 18 | RUN mkdir /opt/app 19 | ARG JAR_FILE 20 | ADD target/${JAR_FILE} /opt/app/app.jar 21 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /dcs/1-Dockerfile-specific-image: -------------------------------------------------------------------------------- 1 | # Search the latest eclipse-temurin java 17 jre alpine image on Docker Hub: https://hub.docker.com/ 2 | # Change the base image and add the SHA256 tag 3 | # It should be like the following but this is an old version: 4 | # eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 5 | # 6 | # Build the image 7 | # Run the container 8 | # Verify it builds and starts successfully 9 | # View the logs and verify that the container is using the latest Java version and verify that the applicatoin is started by root using the command: 10 | # docker logs dockerbestpractices 11 | FROM eclipse-temurin:17 12 | RUN mkdir /opt/app 13 | ARG JAR_FILE 14 | ADD target/${JAR_FILE} /opt/app/app.jar 15 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /dcs/10-Dockerfile-spring-boot-docker-layers: -------------------------------------------------------------------------------- 1 | # Create a multistage build using Spring Boot Layers: 2 | # https://springframework.guru/why-you-should-be-using-spring-boot-docker-layers/ 3 | # 4 | # Build the image 5 | # Run the container 6 | # Verify whether the application still runs 7 | -------------------------------------------------------------------------------- /dcs/2-Dockerfile-do-not-run-as-root: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Add a service account to the Docker image: 3 | # RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 4 | # 5 | # Change the ownership of the application directory: 6 | # RUN chown -R javauser:javauser /opt/app 7 | # 8 | # Use the service account: 9 | # USER javauser 10 | # 11 | # Build the image 12 | # Run the container 13 | # Verify it builds and starts successfully 14 | # View the logs and verify that the container is started by the service account using the command: 15 | # docker logs dockerbestpractices 16 | -------------------------------------------------------------------------------- /dcs/3-Dockerfile-use-workdir: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Set the /opt/app directory as WORKDIR and remove the mkdir instruction: 3 | # WORKDIR /opt/app 4 | # 5 | # Remove unnecessary /opt/app references 6 | # 7 | # Build the image 8 | # Run the container 9 | # Verify it builds and starts successfully 10 | # You will not notice any difference, only the Dockerfile is more readable 11 | -------------------------------------------------------------------------------- /dcs/4-Dockerfile-use-entrypoint: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Use ENTRYPOINT instead of CMD 3 | # 4 | # Build the image 5 | # Run the container 6 | # Verify it builds and starts successfully 7 | # You will not notice any difference 8 | -------------------------------------------------------------------------------- /dcs/5-Dockerfile-use-copy-instead-of-add: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Use COPY instead of ADD 3 | # 4 | # Build the image 5 | # Run the container 6 | # Verify it builds and starts successfully 7 | # You will not notice any difference, only the Docker image will be a bit more secure 8 | -------------------------------------------------------------------------------- /dcs/6-use-dockerignore-file: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Add a .dockerignore file to the root of the repository excluding all files: 3 | # **/** 4 | # 5 | # Build the Docker image, it will fail, because it will not find the jar-file 6 | # 7 | # Include the jar-file: 8 | # !target/*.jar 9 | # 10 | # Build the image 11 | # You will not notice any difference, creating the Docker image will be slightly faster and you are certain that only intended information can be copied into the Docker image 12 | -------------------------------------------------------------------------------- /dcs/7-Dockerfile-healthcheck: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Add a health check: 3 | # HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 4 | # 5 | # Build the image 6 | # Run the container 7 | # Invoke the actuator health endpoint until the status of the container is unhealthy (should do so after 5 consecutive calls) 8 | # Invoking the endpoint can be done with the command: curl http://localhost:8080/actuator/health 9 | # Checking the status can be seen with: docker ps 10 | # Also note, that the container is not restarted 11 | -------------------------------------------------------------------------------- /dcs/8-compose-healthcheck.yml: -------------------------------------------------------------------------------- 1 | # Create a Docker Compose file with 2 services: https://docs.docker.com/compose/ 2 | # the container for dockerbestpractices 3 | # the container which will perform the restart: https://github.com/willfarrell/docker-autoheal 4 | # run the compose file: 5 | # docker compose -f dcs/8-compose-healthcheck.yml up -d 6 | # 7 | # Invoke the actuator health endpoint until the status of the container is unhealthy (should do so after 5 consecutive calls) 8 | # Invoking the endpoint can be done with the command: curl http://localhost:8080/actuator/health 9 | # Checking the status can be seen with: docker ps 10 | # Note that the container is restarted (you will notice this because the uptime of the container changes) 11 | # 12 | # Stop the containers: 13 | # docker compose -f dcs/8-compose-healthcheck.yml down 14 | -------------------------------------------------------------------------------- /dcs/9-Dockerfile-multistage-build: -------------------------------------------------------------------------------- 1 | # Build the application in a first build stage using the eclipse-temurin-17-alpine docker image 2 | # Copy the contents of the repository into the docker image (beware that the source directory must be in the context of 'docker build' 3 | # This means that you cannot use '../.' but you need to move the Dockerfile one directory level up. 4 | # Build the application with command: mvn clean package -DskipTests 5 | # 6 | # In the second build stage, use the Dockerfile as previously created, but use the jar-file from the first stage 7 | # 8 | # Build the image (No need to add the build argument. Why?) 9 | # docker build . --tag mydeveloperplanet/dockerbestpractices:0.0.1-SNAPSHOT -f 9-Dockerfile-multistage-build 10 | # Run the container 11 | -------------------------------------------------------------------------------- /dcs/solutions/1-Dockerfile-specific-image: -------------------------------------------------------------------------------- 1 | # Search the latest eclipse-temurin java 17 jre alpine image on Docker Hub: https://hub.docker.com/ 2 | # Change the base image and add the SHA256 tag 3 | # It should be like the following but this is an old version: 4 | # eclipse-temurin:17.0.5_8-jre-alpine@sha256:02c04793fa49ad5cd193c961403223755f9209a67894622e05438598b32f210e 5 | # 6 | # Build the image 7 | # Run the container 8 | # Verify it builds and starts successfully 9 | # View the logs and verify that the container is using the latest Java version and verify that the applicatoin is started by root using the command: 10 | # docker logs dockerbestpractices 11 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 12 | RUN mkdir /opt/app 13 | ARG JAR_FILE 14 | ADD target/${JAR_FILE} /opt/app/app.jar 15 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /dcs/solutions/10-Dockerfile-spring-boot-docker-layers: -------------------------------------------------------------------------------- 1 | # Create a multistage build using Spring Boot Layers: 2 | # https://springframework.guru/why-you-should-be-using-spring-boot-docker-layers/ 3 | # 4 | # Build the image 5 | # Run the container 6 | # Verify whether the application still runs 7 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed AS builder 8 | WORKDIR application 9 | ARG JAR_FILE 10 | COPY target/${JAR_FILE} app.jar 11 | RUN java -Djarmode=layertools -jar app.jar extract 12 | 13 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 14 | WORKDIR /opt/app 15 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 16 | COPY --from=builder application/dependencies/ ./ 17 | COPY --from=builder application/spring-boot-loader/ ./ 18 | COPY --from=builder application/snapshot-dependencies/ ./ 19 | COPY --from=builder application/application/ ./ 20 | RUN chown -R javauser:javauser . 21 | USER javauser 22 | HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 23 | ENTRYPOINT ["java", "org.springframework.boot.loader.JarLauncher"] -------------------------------------------------------------------------------- /dcs/solutions/2-Dockerfile-do-not-run-as-root: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Add a service account to the Docker image: 3 | # RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 4 | # 5 | # Change the ownership of the application directory: 6 | # RUN chown -R javauser:javauser /opt/app 7 | # 8 | # Use the service account: 9 | # USER javauser 10 | # 11 | # Build the image 12 | # Run the container 13 | # Verify it builds and starts successfully 14 | # View the logs and verify that the container is started by the service account using the command: 15 | # docker logs dockerbestpractices 16 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 17 | RUN mkdir /opt/app 18 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 19 | ARG JAR_FILE 20 | ADD target/${JAR_FILE} /opt/app/app.jar 21 | RUN chown -R javauser:javauser /opt/app 22 | USER javauser 23 | CMD ["java", "-jar", "/opt/app/app.jar"] -------------------------------------------------------------------------------- /dcs/solutions/3-Dockerfile-use-workdir: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Set the /opt/app directory as WORKDIR and remove the mkdir instruction: 3 | # WORKDIR /opt/app 4 | # 5 | # Remove unnecessary /opt/app references 6 | # 7 | # Build the image 8 | # Run the container 9 | # Verify it builds and starts successfully 10 | # You will not notice any difference, only the Dockerfile is more readable 11 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 12 | WORKDIR /opt/app 13 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 14 | ARG JAR_FILE 15 | ADD target/${JAR_FILE} app.jar 16 | RUN chown -R javauser:javauser . 17 | USER javauser 18 | CMD ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /dcs/solutions/4-Dockerfile-use-entrypoint: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Use ENTRYPOINT instead of CMD 3 | # 4 | # Build the image 5 | # Run the container 6 | # Verify it builds and starts successfully 7 | # You will not notice any difference 8 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 9 | WORKDIR /opt/app 10 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 11 | ARG JAR_FILE 12 | ADD target/${JAR_FILE} app.jar 13 | RUN chown -R javauser:javauser . 14 | USER javauser 15 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /dcs/solutions/5-Dockerfile-use-copy-instead-of-add: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Use COPY instead of ADD 3 | # 4 | # Build the image 5 | # Run the container 6 | # Verify it builds and starts successfully 7 | # You will not notice any difference, only the Docker image will be a bit more secure 8 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 9 | WORKDIR /opt/app 10 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 11 | ARG JAR_FILE 12 | COPY target/${JAR_FILE} app.jar 13 | RUN chown -R javauser:javauser . 14 | USER javauser 15 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /dcs/solutions/7-Dockerfile-healthcheck: -------------------------------------------------------------------------------- 1 | # Continue with the previous dockerfile 2 | # Add a health check: 3 | # HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 4 | # 5 | # Build the image 6 | # Run the container 7 | # Invoke the actuator health endpoint until the status of the container is unhealthy (should do so after 5 consecutive calls) 8 | # Invoking the endpoint can be done with the command: curl http://localhost:8080/actuator/health 9 | # Checking the status can be seen with: docker ps 10 | # Also note, that the container is not restarted 11 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 12 | WORKDIR /opt/app 13 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 14 | ARG JAR_FILE 15 | COPY target/${JAR_FILE} app.jar 16 | RUN chown -R javauser:javauser . 17 | USER javauser 18 | HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 19 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /dcs/solutions/8-compose-healthcheck.yml: -------------------------------------------------------------------------------- 1 | # Create a Docker Compose file with 2 services: https://docs.docker.com/compose/ 2 | # the container for dockerbestpractices 3 | # the container which will perform the restart: https://github.com/willfarrell/docker-autoheal 4 | # run the compose file: 5 | # docker compose -f dcs/8-compose-healthcheck.yml up -d 6 | # 7 | # Invoke the actuator health endpoint until the status of the container is unhealthy (should do so after 5 consecutive calls) 8 | # Invoking the endpoint can be done with the command: curl http://localhost:8080/actuator/health 9 | # Checking the status can be seen with: docker ps 10 | # Note that the container is restarted (you will notice this because the uptime of the container changes) 11 | # 12 | # Stop the containers: 13 | # docker compose -f dcs/8-compose-healthcheck.yml down 14 | services: 15 | dockerbestpractices: 16 | image: mydeveloperplanet/dockerbestpractices:0.0.1-SNAPSHOT 17 | ports: 18 | - "127.0.0.1:8080:8080" 19 | 20 | autoheal: 21 | image: willfarrell/autoheal:1.2.0 22 | restart: always 23 | environment: 24 | AUTOHEAL_CONTAINER_LABEL: all 25 | volumes: 26 | - type: bind 27 | source: /var/run/docker.sock 28 | target: /var/run/docker.sock -------------------------------------------------------------------------------- /dcs/solutions/9-Dockerfile-multistage-build: -------------------------------------------------------------------------------- 1 | # Build the application in a first build stage using the eclipse-temurin-17-alpine docker image 2 | # Copy the contents of the repository into the docker image (beware that the source directory must be in the context of 'docker build' 3 | # This means that you cannot use '../.' but you need to move the Dockerfile one directory level up. 4 | # Build the application with command: mvn clean package -DskipTests 5 | # 6 | # In the second build stage, use the Dockerfile as previously created, but use the jar-file from the first stage 7 | # 8 | # Build the image (No need to add the build argument. Why?) 9 | # docker build . --tag mydeveloperplanet/dockerbestpractices:0.0.1-SNAPSHOT -f 9-Dockerfile-multistage-build 10 | # Run the container 11 | FROM maven:3.9.3-eclipse-temurin-17-alpine@sha256:38e7fe344f85a25e88fb15c5588360e439dab00cd4abdb72c11670543075965b AS builder 12 | WORKDIR /build 13 | COPY . . 14 | RUN mvn clean package -DskipTests 15 | 16 | FROM eclipse-temurin:17.0.7_7-jre-alpine@sha256:dd8238c151293ae6a7c22898ef2f0df2af8a05786aef73ccd3248e73765969ed 17 | WORKDIR /opt/app 18 | RUN addgroup --system javauser && adduser -S -s /usr/sbin/nologin -G javauser javauser 19 | COPY --from=builder /build/target/mydockerbestpracticesplanet-0.0.1-SNAPSHOT.jar app.jar 20 | RUN chown -R javauser:javauser . 21 | USER javauser 22 | HEALTHCHECK --interval=30s --timeout=3s --retries=1 CMD wget -qO- http://localhost:8080/actuator/health/ | grep UP || exit 1 23 | ENTRYPOINT ["java", "-jar", "app.jar"] -------------------------------------------------------------------------------- /mvnw: -------------------------------------------------------------------------------- 1 | #!/bin/sh 2 | # ---------------------------------------------------------------------------- 3 | # Licensed to the Apache Software Foundation (ASF) under one 4 | # or more contributor license agreements. See the NOTICE file 5 | # distributed with this work for additional information 6 | # regarding copyright ownership. The ASF licenses this file 7 | # to you under the Apache License, Version 2.0 (the 8 | # "License"); you may not use this file except in compliance 9 | # with the License. You may obtain a copy of the License at 10 | # 11 | # https://www.apache.org/licenses/LICENSE-2.0 12 | # 13 | # Unless required by applicable law or agreed to in writing, 14 | # software distributed under the License is distributed on an 15 | # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 16 | # KIND, either express or implied. See the License for the 17 | # specific language governing permissions and limitations 18 | # under the License. 19 | # ---------------------------------------------------------------------------- 20 | 21 | # ---------------------------------------------------------------------------- 22 | # Maven Start Up Batch script 23 | # 24 | # Required ENV vars: 25 | # ------------------ 26 | # JAVA_HOME - location of a JDK home dir 27 | # 28 | # Optional ENV vars 29 | # ----------------- 30 | # M2_HOME - location of maven2's installed home dir 31 | # MAVEN_OPTS - parameters passed to the Java VM when running Maven 32 | # e.g. to debug Maven itself, use 33 | # set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 34 | # MAVEN_SKIP_RC - flag to disable loading of mavenrc files 35 | # ---------------------------------------------------------------------------- 36 | 37 | if [ -z "$MAVEN_SKIP_RC" ] ; then 38 | 39 | if [ -f /usr/local/etc/mavenrc ] ; then 40 | . /usr/local/etc/mavenrc 41 | fi 42 | 43 | if [ -f /etc/mavenrc ] ; then 44 | . /etc/mavenrc 45 | fi 46 | 47 | if [ -f "$HOME/.mavenrc" ] ; then 48 | . "$HOME/.mavenrc" 49 | fi 50 | 51 | fi 52 | 53 | # OS specific support. $var _must_ be set to either true or false. 54 | cygwin=false; 55 | darwin=false; 56 | mingw=false 57 | case "`uname`" in 58 | CYGWIN*) cygwin=true ;; 59 | MINGW*) mingw=true;; 60 | Darwin*) darwin=true 61 | # Use /usr/libexec/java_home if available, otherwise fall back to /Library/Java/Home 62 | # See https://developer.apple.com/library/mac/qa/qa1170/_index.html 63 | if [ -z "$JAVA_HOME" ]; then 64 | if [ -x "/usr/libexec/java_home" ]; then 65 | export JAVA_HOME="`/usr/libexec/java_home`" 66 | else 67 | export JAVA_HOME="/Library/Java/Home" 68 | fi 69 | fi 70 | ;; 71 | esac 72 | 73 | if [ -z "$JAVA_HOME" ] ; then 74 | if [ -r /etc/gentoo-release ] ; then 75 | JAVA_HOME=`java-config --jre-home` 76 | fi 77 | fi 78 | 79 | if [ -z "$M2_HOME" ] ; then 80 | ## resolve links - $0 may be a link to maven's home 81 | PRG="$0" 82 | 83 | # need this for relative symlinks 84 | while [ -h "$PRG" ] ; do 85 | ls=`ls -ld "$PRG"` 86 | link=`expr "$ls" : '.*-> \(.*\)$'` 87 | if expr "$link" : '/.*' > /dev/null; then 88 | PRG="$link" 89 | else 90 | PRG="`dirname "$PRG"`/$link" 91 | fi 92 | done 93 | 94 | saveddir=`pwd` 95 | 96 | M2_HOME=`dirname "$PRG"`/.. 97 | 98 | # make it fully qualified 99 | M2_HOME=`cd "$M2_HOME" && pwd` 100 | 101 | cd "$saveddir" 102 | # echo Using m2 at $M2_HOME 103 | fi 104 | 105 | # For Cygwin, ensure paths are in UNIX format before anything is touched 106 | if $cygwin ; then 107 | [ -n "$M2_HOME" ] && 108 | M2_HOME=`cygpath --unix "$M2_HOME"` 109 | [ -n "$JAVA_HOME" ] && 110 | JAVA_HOME=`cygpath --unix "$JAVA_HOME"` 111 | [ -n "$CLASSPATH" ] && 112 | CLASSPATH=`cygpath --path --unix "$CLASSPATH"` 113 | fi 114 | 115 | # For Mingw, ensure paths are in UNIX format before anything is touched 116 | if $mingw ; then 117 | [ -n "$M2_HOME" ] && 118 | M2_HOME="`(cd "$M2_HOME"; pwd)`" 119 | [ -n "$JAVA_HOME" ] && 120 | JAVA_HOME="`(cd "$JAVA_HOME"; pwd)`" 121 | fi 122 | 123 | if [ -z "$JAVA_HOME" ]; then 124 | javaExecutable="`which javac`" 125 | if [ -n "$javaExecutable" ] && ! [ "`expr \"$javaExecutable\" : '\([^ ]*\)'`" = "no" ]; then 126 | # readlink(1) is not available as standard on Solaris 10. 127 | readLink=`which readlink` 128 | if [ ! `expr "$readLink" : '\([^ ]*\)'` = "no" ]; then 129 | if $darwin ; then 130 | javaHome="`dirname \"$javaExecutable\"`" 131 | javaExecutable="`cd \"$javaHome\" && pwd -P`/javac" 132 | else 133 | javaExecutable="`readlink -f \"$javaExecutable\"`" 134 | fi 135 | javaHome="`dirname \"$javaExecutable\"`" 136 | javaHome=`expr "$javaHome" : '\(.*\)/bin'` 137 | JAVA_HOME="$javaHome" 138 | export JAVA_HOME 139 | fi 140 | fi 141 | fi 142 | 143 | if [ -z "$JAVACMD" ] ; then 144 | if [ -n "$JAVA_HOME" ] ; then 145 | if [ -x "$JAVA_HOME/jre/sh/java" ] ; then 146 | # IBM's JDK on AIX uses strange locations for the executables 147 | JAVACMD="$JAVA_HOME/jre/sh/java" 148 | else 149 | JAVACMD="$JAVA_HOME/bin/java" 150 | fi 151 | else 152 | JAVACMD="`\\unset -f command; \\command -v java`" 153 | fi 154 | fi 155 | 156 | if [ ! -x "$JAVACMD" ] ; then 157 | echo "Error: JAVA_HOME is not defined correctly." >&2 158 | echo " We cannot execute $JAVACMD" >&2 159 | exit 1 160 | fi 161 | 162 | if [ -z "$JAVA_HOME" ] ; then 163 | echo "Warning: JAVA_HOME environment variable is not set." 164 | fi 165 | 166 | CLASSWORLDS_LAUNCHER=org.codehaus.plexus.classworlds.launcher.Launcher 167 | 168 | # traverses directory structure from process work directory to filesystem root 169 | # first directory with .mvn subdirectory is considered project base directory 170 | find_maven_basedir() { 171 | 172 | if [ -z "$1" ] 173 | then 174 | echo "Path not specified to find_maven_basedir" 175 | return 1 176 | fi 177 | 178 | basedir="$1" 179 | wdir="$1" 180 | while [ "$wdir" != '/' ] ; do 181 | if [ -d "$wdir"/.mvn ] ; then 182 | basedir=$wdir 183 | break 184 | fi 185 | # workaround for JBEAP-8937 (on Solaris 10/Sparc) 186 | if [ -d "${wdir}" ]; then 187 | wdir=`cd "$wdir/.."; pwd` 188 | fi 189 | # end of workaround 190 | done 191 | echo "${basedir}" 192 | } 193 | 194 | # concatenates all lines of a file 195 | concat_lines() { 196 | if [ -f "$1" ]; then 197 | echo "$(tr -s '\n' ' ' < "$1")" 198 | fi 199 | } 200 | 201 | BASE_DIR=`find_maven_basedir "$(pwd)"` 202 | if [ -z "$BASE_DIR" ]; then 203 | exit 1; 204 | fi 205 | 206 | ########################################################################################## 207 | # Extension to allow automatically downloading the maven-wrapper.jar from Maven-central 208 | # This allows using the maven wrapper in projects that prohibit checking in binary data. 209 | ########################################################################################## 210 | if [ -r "$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" ]; then 211 | if [ "$MVNW_VERBOSE" = true ]; then 212 | echo "Found .mvn/wrapper/maven-wrapper.jar" 213 | fi 214 | else 215 | if [ "$MVNW_VERBOSE" = true ]; then 216 | echo "Couldn't find .mvn/wrapper/maven-wrapper.jar, downloading it ..." 217 | fi 218 | if [ -n "$MVNW_REPOURL" ]; then 219 | jarUrl="$MVNW_REPOURL/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" 220 | else 221 | jarUrl="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" 222 | fi 223 | while IFS="=" read key value; do 224 | case "$key" in (wrapperUrl) jarUrl="$value"; break ;; 225 | esac 226 | done < "$BASE_DIR/.mvn/wrapper/maven-wrapper.properties" 227 | if [ "$MVNW_VERBOSE" = true ]; then 228 | echo "Downloading from: $jarUrl" 229 | fi 230 | wrapperJarPath="$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" 231 | if $cygwin; then 232 | wrapperJarPath=`cygpath --path --windows "$wrapperJarPath"` 233 | fi 234 | 235 | if command -v wget > /dev/null; then 236 | if [ "$MVNW_VERBOSE" = true ]; then 237 | echo "Found wget ... using wget" 238 | fi 239 | if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then 240 | wget "$jarUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath" 241 | else 242 | wget --http-user=$MVNW_USERNAME --http-password=$MVNW_PASSWORD "$jarUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath" 243 | fi 244 | elif command -v curl > /dev/null; then 245 | if [ "$MVNW_VERBOSE" = true ]; then 246 | echo "Found curl ... using curl" 247 | fi 248 | if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then 249 | curl -o "$wrapperJarPath" "$jarUrl" -f 250 | else 251 | curl --user $MVNW_USERNAME:$MVNW_PASSWORD -o "$wrapperJarPath" "$jarUrl" -f 252 | fi 253 | 254 | else 255 | if [ "$MVNW_VERBOSE" = true ]; then 256 | echo "Falling back to using Java to download" 257 | fi 258 | javaClass="$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.java" 259 | # For Cygwin, switch paths to Windows format before running javac 260 | if $cygwin; then 261 | javaClass=`cygpath --path --windows "$javaClass"` 262 | fi 263 | if [ -e "$javaClass" ]; then 264 | if [ ! -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then 265 | if [ "$MVNW_VERBOSE" = true ]; then 266 | echo " - Compiling MavenWrapperDownloader.java ..." 267 | fi 268 | # Compiling the Java class 269 | ("$JAVA_HOME/bin/javac" "$javaClass") 270 | fi 271 | if [ -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then 272 | # Running the downloader 273 | if [ "$MVNW_VERBOSE" = true ]; then 274 | echo " - Running MavenWrapperDownloader.java ..." 275 | fi 276 | ("$JAVA_HOME/bin/java" -cp .mvn/wrapper MavenWrapperDownloader "$MAVEN_PROJECTBASEDIR") 277 | fi 278 | fi 279 | fi 280 | fi 281 | ########################################################################################## 282 | # End of extension 283 | ########################################################################################## 284 | 285 | export MAVEN_PROJECTBASEDIR=${MAVEN_BASEDIR:-"$BASE_DIR"} 286 | if [ "$MVNW_VERBOSE" = true ]; then 287 | echo $MAVEN_PROJECTBASEDIR 288 | fi 289 | MAVEN_OPTS="$(concat_lines "$MAVEN_PROJECTBASEDIR/.mvn/jvm.config") $MAVEN_OPTS" 290 | 291 | # For Cygwin, switch paths to Windows format before running java 292 | if $cygwin; then 293 | [ -n "$M2_HOME" ] && 294 | M2_HOME=`cygpath --path --windows "$M2_HOME"` 295 | [ -n "$JAVA_HOME" ] && 296 | JAVA_HOME=`cygpath --path --windows "$JAVA_HOME"` 297 | [ -n "$CLASSPATH" ] && 298 | CLASSPATH=`cygpath --path --windows "$CLASSPATH"` 299 | [ -n "$MAVEN_PROJECTBASEDIR" ] && 300 | MAVEN_PROJECTBASEDIR=`cygpath --path --windows "$MAVEN_PROJECTBASEDIR"` 301 | fi 302 | 303 | # Provide a "standardized" way to retrieve the CLI args that will 304 | # work with both Windows and non-Windows executions. 305 | MAVEN_CMD_LINE_ARGS="$MAVEN_CONFIG $@" 306 | export MAVEN_CMD_LINE_ARGS 307 | 308 | WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain 309 | 310 | exec "$JAVACMD" \ 311 | $MAVEN_OPTS \ 312 | $MAVEN_DEBUG_OPTS \ 313 | -classpath "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" \ 314 | "-Dmaven.home=${M2_HOME}" \ 315 | "-Dmaven.multiModuleProjectDirectory=${MAVEN_PROJECTBASEDIR}" \ 316 | ${WRAPPER_LAUNCHER} $MAVEN_CONFIG "$@" 317 | -------------------------------------------------------------------------------- /mvnw.cmd: -------------------------------------------------------------------------------- 1 | @REM ---------------------------------------------------------------------------- 2 | @REM Licensed to the Apache Software Foundation (ASF) under one 3 | @REM or more contributor license agreements. See the NOTICE file 4 | @REM distributed with this work for additional information 5 | @REM regarding copyright ownership. The ASF licenses this file 6 | @REM to you under the Apache License, Version 2.0 (the 7 | @REM "License"); you may not use this file except in compliance 8 | @REM with the License. You may obtain a copy of the License at 9 | @REM 10 | @REM https://www.apache.org/licenses/LICENSE-2.0 11 | @REM 12 | @REM Unless required by applicable law or agreed to in writing, 13 | @REM software distributed under the License is distributed on an 14 | @REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY 15 | @REM KIND, either express or implied. See the License for the 16 | @REM specific language governing permissions and limitations 17 | @REM under the License. 18 | @REM ---------------------------------------------------------------------------- 19 | 20 | @REM ---------------------------------------------------------------------------- 21 | @REM Maven Start Up Batch script 22 | @REM 23 | @REM Required ENV vars: 24 | @REM JAVA_HOME - location of a JDK home dir 25 | @REM 26 | @REM Optional ENV vars 27 | @REM M2_HOME - location of maven2's installed home dir 28 | @REM MAVEN_BATCH_ECHO - set to 'on' to enable the echoing of the batch commands 29 | @REM MAVEN_BATCH_PAUSE - set to 'on' to wait for a keystroke before ending 30 | @REM MAVEN_OPTS - parameters passed to the Java VM when running Maven 31 | @REM e.g. to debug Maven itself, use 32 | @REM set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000 33 | @REM MAVEN_SKIP_RC - flag to disable loading of mavenrc files 34 | @REM ---------------------------------------------------------------------------- 35 | 36 | @REM Begin all REM lines with '@' in case MAVEN_BATCH_ECHO is 'on' 37 | @echo off 38 | @REM set title of command window 39 | title %0 40 | @REM enable echoing by setting MAVEN_BATCH_ECHO to 'on' 41 | @if "%MAVEN_BATCH_ECHO%" == "on" echo %MAVEN_BATCH_ECHO% 42 | 43 | @REM set %HOME% to equivalent of $HOME 44 | if "%HOME%" == "" (set "HOME=%HOMEDRIVE%%HOMEPATH%") 45 | 46 | @REM Execute a user defined script before this one 47 | if not "%MAVEN_SKIP_RC%" == "" goto skipRcPre 48 | @REM check for pre script, once with legacy .bat ending and once with .cmd ending 49 | if exist "%USERPROFILE%\mavenrc_pre.bat" call "%USERPROFILE%\mavenrc_pre.bat" %* 50 | if exist "%USERPROFILE%\mavenrc_pre.cmd" call "%USERPROFILE%\mavenrc_pre.cmd" %* 51 | :skipRcPre 52 | 53 | @setlocal 54 | 55 | set ERROR_CODE=0 56 | 57 | @REM To isolate internal variables from possible post scripts, we use another setlocal 58 | @setlocal 59 | 60 | @REM ==== START VALIDATION ==== 61 | if not "%JAVA_HOME%" == "" goto OkJHome 62 | 63 | echo. 64 | echo Error: JAVA_HOME not found in your environment. >&2 65 | echo Please set the JAVA_HOME variable in your environment to match the >&2 66 | echo location of your Java installation. >&2 67 | echo. 68 | goto error 69 | 70 | :OkJHome 71 | if exist "%JAVA_HOME%\bin\java.exe" goto init 72 | 73 | echo. 74 | echo Error: JAVA_HOME is set to an invalid directory. >&2 75 | echo JAVA_HOME = "%JAVA_HOME%" >&2 76 | echo Please set the JAVA_HOME variable in your environment to match the >&2 77 | echo location of your Java installation. >&2 78 | echo. 79 | goto error 80 | 81 | @REM ==== END VALIDATION ==== 82 | 83 | :init 84 | 85 | @REM Find the project base dir, i.e. the directory that contains the folder ".mvn". 86 | @REM Fallback to current working directory if not found. 87 | 88 | set MAVEN_PROJECTBASEDIR=%MAVEN_BASEDIR% 89 | IF NOT "%MAVEN_PROJECTBASEDIR%"=="" goto endDetectBaseDir 90 | 91 | set EXEC_DIR=%CD% 92 | set WDIR=%EXEC_DIR% 93 | :findBaseDir 94 | IF EXIST "%WDIR%"\.mvn goto baseDirFound 95 | cd .. 96 | IF "%WDIR%"=="%CD%" goto baseDirNotFound 97 | set WDIR=%CD% 98 | goto findBaseDir 99 | 100 | :baseDirFound 101 | set MAVEN_PROJECTBASEDIR=%WDIR% 102 | cd "%EXEC_DIR%" 103 | goto endDetectBaseDir 104 | 105 | :baseDirNotFound 106 | set MAVEN_PROJECTBASEDIR=%EXEC_DIR% 107 | cd "%EXEC_DIR%" 108 | 109 | :endDetectBaseDir 110 | 111 | IF NOT EXIST "%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config" goto endReadAdditionalConfig 112 | 113 | @setlocal EnableExtensions EnableDelayedExpansion 114 | for /F "usebackq delims=" %%a in ("%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config") do set JVM_CONFIG_MAVEN_PROPS=!JVM_CONFIG_MAVEN_PROPS! %%a 115 | @endlocal & set JVM_CONFIG_MAVEN_PROPS=%JVM_CONFIG_MAVEN_PROPS% 116 | 117 | :endReadAdditionalConfig 118 | 119 | SET MAVEN_JAVA_EXE="%JAVA_HOME%\bin\java.exe" 120 | set WRAPPER_JAR="%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.jar" 121 | set WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain 122 | 123 | set DOWNLOAD_URL="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" 124 | 125 | FOR /F "usebackq tokens=1,2 delims==" %%A IN ("%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.properties") DO ( 126 | IF "%%A"=="wrapperUrl" SET DOWNLOAD_URL=%%B 127 | ) 128 | 129 | @REM Extension to allow automatically downloading the maven-wrapper.jar from Maven-central 130 | @REM This allows using the maven wrapper in projects that prohibit checking in binary data. 131 | if exist %WRAPPER_JAR% ( 132 | if "%MVNW_VERBOSE%" == "true" ( 133 | echo Found %WRAPPER_JAR% 134 | ) 135 | ) else ( 136 | if not "%MVNW_REPOURL%" == "" ( 137 | SET DOWNLOAD_URL="%MVNW_REPOURL%/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar" 138 | ) 139 | if "%MVNW_VERBOSE%" == "true" ( 140 | echo Couldn't find %WRAPPER_JAR%, downloading it ... 141 | echo Downloading from: %DOWNLOAD_URL% 142 | ) 143 | 144 | powershell -Command "&{"^ 145 | "$webclient = new-object System.Net.WebClient;"^ 146 | "if (-not ([string]::IsNullOrEmpty('%MVNW_USERNAME%') -and [string]::IsNullOrEmpty('%MVNW_PASSWORD%'))) {"^ 147 | "$webclient.Credentials = new-object System.Net.NetworkCredential('%MVNW_USERNAME%', '%MVNW_PASSWORD%');"^ 148 | "}"^ 149 | "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $webclient.DownloadFile('%DOWNLOAD_URL%', '%WRAPPER_JAR%')"^ 150 | "}" 151 | if "%MVNW_VERBOSE%" == "true" ( 152 | echo Finished downloading %WRAPPER_JAR% 153 | ) 154 | ) 155 | @REM End of extension 156 | 157 | @REM Provide a "standardized" way to retrieve the CLI args that will 158 | @REM work with both Windows and non-Windows executions. 159 | set MAVEN_CMD_LINE_ARGS=%* 160 | 161 | %MAVEN_JAVA_EXE% ^ 162 | %JVM_CONFIG_MAVEN_PROPS% ^ 163 | %MAVEN_OPTS% ^ 164 | %MAVEN_DEBUG_OPTS% ^ 165 | -classpath %WRAPPER_JAR% ^ 166 | "-Dmaven.multiModuleProjectDirectory=%MAVEN_PROJECTBASEDIR%" ^ 167 | %WRAPPER_LAUNCHER% %MAVEN_CONFIG% %* 168 | if ERRORLEVEL 1 goto error 169 | goto end 170 | 171 | :error 172 | set ERROR_CODE=1 173 | 174 | :end 175 | @endlocal & set ERROR_CODE=%ERROR_CODE% 176 | 177 | if not "%MAVEN_SKIP_RC%"=="" goto skipRcPost 178 | @REM check for post script, once with legacy .bat ending and once with .cmd ending 179 | if exist "%USERPROFILE%\mavenrc_post.bat" call "%USERPROFILE%\mavenrc_post.bat" 180 | if exist "%USERPROFILE%\mavenrc_post.cmd" call "%USERPROFILE%\mavenrc_post.cmd" 181 | :skipRcPost 182 | 183 | @REM pause the script if MAVEN_BATCH_PAUSE is set to 'on' 184 | if "%MAVEN_BATCH_PAUSE%"=="on" pause 185 | 186 | if "%MAVEN_TERMINATE_CMD%"=="on" exit %ERROR_CODE% 187 | 188 | cmd /C exit /B %ERROR_CODE% 189 | -------------------------------------------------------------------------------- /pom.xml: -------------------------------------------------------------------------------- 1 | 2 | 4 | 4.0.0 5 | 6 | org.springframework.boot 7 | spring-boot-starter-parent 8 | 2.7.4 9 | 10 | 11 | com.mydeveloperplanet 12 | mydockerbestpracticesplanet 13 | 0.0.1-SNAPSHOT 14 | mydockerbestpracticesplanet 15 | Project describing Docker best practices 16 | 17 | 17 18 | 19 | 20 | 21 | org.springframework.boot 22 | spring-boot-starter-actuator 23 | 24 | 25 | org.springframework.boot 26 | spring-boot-starter-web 27 | 28 | 29 | 30 | org.springframework.boot 31 | spring-boot-starter-test 32 | test 33 | 34 | 35 | 36 | 37 | 38 | 39 | org.springframework.boot 40 | spring-boot-maven-plugin 41 | 42 | 43 | com.xenoamess.docker 44 | dockerfile-maven-plugin 45 | 1.4.25 46 | 47 | mydeveloperplanet/dockerbestpractices 48 | ${project.version} 49 | 50 | ${project.build.finalName}.jar 51 | 52 | 53 | 54 | 55 | 56 | 57 | 58 | -------------------------------------------------------------------------------- /src/main/java/com/mydeveloperplanet/mydockerbestpracticesplanet/DownHealthIndicator.java: -------------------------------------------------------------------------------- 1 | package com.mydeveloperplanet.mydockerbestpracticesplanet; 2 | 3 | import org.springframework.boot.actuate.health.Health; 4 | import org.springframework.boot.actuate.health.HealthIndicator; 5 | import org.springframework.stereotype.Component; 6 | 7 | @Component 8 | public class DownHealthIndicator implements HealthIndicator { 9 | 10 | private int counter; 11 | 12 | @Override 13 | public Health health() { 14 | counter++; 15 | Health.Builder status = Health.up(); 16 | if (counter == 5) { 17 | status = Health.down(); 18 | counter = 0; 19 | } 20 | return status.build(); 21 | } 22 | } 23 | -------------------------------------------------------------------------------- /src/main/java/com/mydeveloperplanet/mydockerbestpracticesplanet/HelloController.java: -------------------------------------------------------------------------------- 1 | package com.mydeveloperplanet.mydockerbestpracticesplanet; 2 | 3 | import org.springframework.web.bind.annotation.RequestMapping; 4 | import org.springframework.web.bind.annotation.RestController; 5 | 6 | @RestController 7 | public class HelloController { 8 | 9 | @RequestMapping("/hello") 10 | public String hello() { 11 | return "Hello Docker!"; 12 | } 13 | } 14 | -------------------------------------------------------------------------------- /src/main/java/com/mydeveloperplanet/mydockerbestpracticesplanet/MyDockerBestPracticesPlanetApplication.java: -------------------------------------------------------------------------------- 1 | package com.mydeveloperplanet.mydockerbestpracticesplanet; 2 | 3 | import org.springframework.boot.SpringApplication; 4 | import org.springframework.boot.autoconfigure.SpringBootApplication; 5 | 6 | @SpringBootApplication 7 | public class MyDockerBestPracticesPlanetApplication { 8 | 9 | public static void main(String[] args) { 10 | SpringApplication.run(MyDockerBestPracticesPlanetApplication.class, args); 11 | } 12 | 13 | } 14 | -------------------------------------------------------------------------------- /src/main/resources/application.properties: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/mydeveloperplanet/mydockerbestpracticesplanet/62d62d481c94809b3b7d0703b69eb155acadeac0/src/main/resources/application.properties -------------------------------------------------------------------------------- /src/test/java/com/mydeveloperplanet/mydockerbestpracticesplanet/MyDockerBestPracticesPlanetApplicationTests.java: -------------------------------------------------------------------------------- 1 | package com.mydeveloperplanet.mydockerbestpracticesplanet; 2 | 3 | import org.junit.jupiter.api.Test; 4 | import org.springframework.boot.test.context.SpringBootTest; 5 | 6 | @SpringBootTest 7 | class MyDockerBestPracticesPlanetApplicationTests { 8 | 9 | @Test 10 | void contextLoads() { 11 | } 12 | 13 | } 14 | --------------------------------------------------------------------------------