forked from mosip/commons
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
82 lines (57 loc) · 3.2 KB
/
Copy pathDockerfile
File metadata and controls
82 lines (57 loc) · 3.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
FROM eclipse-temurin:21-jre
# can be passed during Docker build as build time environment for keystore location for encryption
ARG encrypt_keyStore_location
# can be passed during Docker build as build time environment for keystore password for encryption
ARG encrypt_keyStore_password
# can be passed during Docker build as build time environment for keystore alias for encryption
ARG encrypt_keyStore_alias
# can be passed during Docker build as build time environment for keystore secret for encryption
ARG encrypt_keyStore_secret
# can be passed during Docker build as build time environment for github branch to pickup configuration from.
ARG container_user=mosip
# can be passed during Docker build as build time environment for github branch to pickup configuration from.
ARG container_user_group=mosip
# can be passed during Docker build as build time environment for github branch to pickup configuration from.
ARG container_user_uid=1002
# can be passed during Docker build as build time environment for github branch to pickup configuration from.
ARG container_user_gid=1001
ARG SOURCE
ARG COMMIT_HASH
ARG COMMIT_ID
ARG BUILD_TIME
# set working directory for the user
WORKDIR /home/${container_user}
ENV work_dir=/home/${container_user}
# environment variable to pass GIT URL at docker runtime
ENV git_url_env=${git_url}
# environment variable to pass github configuration folder to pickup configuration from, at docker runtime
ENV git_config_folder_env=${git_config_folder}
# environment variable to pass encryption keystore location at docker runtime
ENV encrypt_keyStore_location_env=${encrypt_keyStore_location}
# environment variable to pass encryption keystore password at docker runtime
ENV encrypt_keyStore_password_env=${encrypt_keyStore_password}
# environment variable to pass encryption keystore alias at docker runtime
ENV encrypt_keyStore_alias_env=${encrypt_keyStore_alias}
# environment variable to pass encryption keystore secret at docker runtime
ENV encrypt_keyStore_secret_env=${encrypt_keyStore_secret}
LABEL source=${SOURCE}
LABEL commit_hash=${COMMIT_HASH}
LABEL commit_id=${COMMIT_ID}
LABEL build_time=${BUILD_TIME}
# install packages and create user
RUN apt-get -y update \
&& apt-get install -y unzip sudo\
&& groupadd -g ${container_user_gid} ${container_user_group} \
&& useradd -u ${container_user_uid} -g ${container_user_group} -s /bin/sh -m ${container_user} \
&& usermod -aG sudo ${container_user} \
&& echo "%sudo ALL=(ALL) NOPASSWD:/home/${container_user}/${hsm_local_dir}/install.sh" >> /etc/sudoers \
# change permissions of file inside working dir
&& chown -R ${container_user}:${container_user} /home/${container_user}
#ADD execute-jar.sh execute-jar.sh
#RUN chmod 777 execute-jar.sh
# select container user for all tasks
USER ${container_user_uid}:${container_user_gid}
COPY ./target/kernel-config-server-*.jar kernel-config-server.jar
EXPOSE 51000
#CMD ./execute-jar.sh
CMD java -XX:-UseG1GC -XX:+ExplicitGCInvokesConcurrent -XX:-UseParallelGC -XX:+UseZGC -XX:+ZGenerational -XX:-UseShenandoahGC -XX:MaxGCPauseMillis=200 -XX:+UnlockExperimentalVMOptions -XX:+UseStringDeduplication -XX:+HeapDumpOnOutOfMemoryError -Dfile.encoding=UTF-8 -XX:+UseCompressedOops -jar kernel-config-server.jar