Sign inSign up

inspiredag/openjdk-alpine

By inspiredag

•Updated over 8 years ago

Base image for Java and Scala based applications that runs without root privileges.

Image
0

282

inspiredag/openjdk-alpine repository overview

⁠Alpine based Openjdk JRE Image

This image is based on the official openjdk:8-jre-alpine image and runs as a non-root user.

⁠Configuration

PathDescription
/opt/app-root/binPath to place runables.
/persistentPath where persitent data should be stored.
/certificatesPath where certificates are stored.
/certificates/ca.pemFile path to a custom CA certificate.
/certificates/server.p12 File path to a PKCS12 type server certificate/key.
/certificates/server_cert.pem File path to a PEM formatted server certificate.
/certificates/server_key.pem File path to a PEM formatted server key.
/keystores Path were java keystore or other keystores are stored
/keystores/cacerts Java keystore with symlink to ``/etc/ssl/certs/java/cacerts`
envDescription
APP_ROOTPath to place binaries and scripts. Can be used in scripts.
PERSISTENCE_ROOTPath where persistent data should be stored. Can be used in scripts.
CERTIFICATES_ROOTPath where certificates are stored. Can be used in scripts.
KEYSTORES_ROOTPath where keystores are stored.
KEYSTORE_PATHPath of Java keystore. Can be used in scripts.
KEYSTORE_PASSWORDPassword of custom keystore if added. Defaults to changeit.
PKCS12_PASSWORDPassword of server.p12. Defaults to "" (empty string).
PKCS12_ALIASAlias of PrivateKeyEntry in server.p12. Defaults to servercert.
⁠Application Binary

One can use /opt/app-root/bin (env APP_ROOT) to place and run its .jar file.

⁠Persistent Data

For persistent data the folder /persistent (env PERSISTENCE_ROOT) is foreseen.

⁠SSL Certificates

Under /certificates (env CERTIFICATES_ROOT) a set of certificates is stored, that can be used for Development. The certificates are valid for the domain i.test and are signed by an internal Certificate Authority that was created for testing only. By default the certificate for this CA is added to the truststore that is located under /keystores/cacerts. One can either supply its own truststore by replacing /keystores/cacerts or store its custom CA cert as .pem file under /certificates/ca.pem. The entrypoint.sh script will then add it to the truststore. To add a custom server certificate, place a PKCS12 type server certificate/key to /certificates/server.p12. You can specify the password of this PKCS12 archive with the env variable PKCS12_PASSWORD. If no password was specified, an empty string will be used as password. You might also want to specify the alias used to store the private key entry with PKCS12_ALIAS so that an application can access the private key if it was addded to the keystore.

⁠How to use

Add your .jar file from your project

ADD target/scala-2.12/ bin/

specify the command how to start it

CMD java -jar bin/myproject.jar

build your image and run it.

Tag summary

Content type

Image

Digest

Size

54.5 MB

Last updated

over 8 years ago

docker pull inspiredag/openjdk-alpine