Sign inSign up

zinthose/d387-app

By zinthose

•Updated 10 months ago

WGU D387 - Spring Boot hotel app with internationalization & timezone features

Image
0

1.9K

zinthose/d387-app repository overview

⁠D387 Advanced Java – Landon Hotel (Spring Boot, Java 17)

A Java 17 Spring Boot application bundling the Landon Hotel UI and REST API for searching rooms and managing reservations. Uses an in-memory H2 database by default.

⁠⚠️ Security Notice

Known Vulnerabilities: This image contains known security vulnerabilities in its dependencies:

  • Spring Boot 2.7.18 (end-of-life, no further updates)
  • Tomcat 9.0.83 with 2 Critical and 26 High severity CVEs

Mitigation Options:

  1. For Production: Upgrade to Spring Boot 3.x (requires javax.* → jakarta.* migration)
  2. For Development/School Projects: Current configuration is acceptable with reduced attack surface
  3. Network Isolation: Deploy behind ALB/API Gateway with strict security groups

Vulnerability Scan:

docker scout cves local://d387-advanced-java:latest
# Shows: 2C 26H 29M 9L vulnerabilities

To Upgrade:

  • Spring Boot 3.3.x uses Tomcat 10.1.x (significantly fewer vulnerabilities)
  • Requires Java 17+ (already satisfied)
  • Breaking changes: package renames, deprecated API removal

⁠Quickstart

docker pull <your-username>/d387-app:latest
docker run --rm -p 8080:8080 <your-username>/d387-app:latest
# Open: http://localhost:8080

⁠Ports

  • 8080/tcp: HTTP server (UI + API)

⁠Health

  • Endpoint: GET /actuator/health
  • Returns HTTP 200 when healthy (use for probes/ALB target health)

⁠Features

  • UI served at / (LandonHotelApp)
  • REST endpoints for rooms and reservations
  • H2 in-memory DB auto-initialized on startup

⁠Configuration

  • No required env vars for local run
  • JVM options: -e JAVA_TOOL_OPTIONS="-Xms256m -Xmx512m"
  • Server port override: -e SERVER_PORT=8080 -p 8080:8080
  • Spring profiles: -e SPRING_PROFILES_ACTIVE=prod

⁠Tags

  • latest: current stable build
  • <git-sha>: immutable build tag (e.g., 1a2b3c4)

Examples:

docker run --rm -p 8080:8080 <your-username>/d387-app:latest
docker run --rm -p 8080:8080 <your-username>/d387-app:1a2b3c4

⁠Kubernetes / Cloud

  • Container port: 8080
  • Probes: httpGet path /actuator/health, port 8080
  • ALB target health path: /actuator/health

⁠Image Details

  • Base: eclipse-temurin:17-jre-alpine
  • Workdir: /app
  • Entrypoint: java -jar /app/app.jar
  • Exposed: 8080
  • Dependencies: Spring Boot 2.7.18, Tomcat 9.0.83

⁠Security Hardening

Default container user is root (from base image)

Hardened run example:

docker run --rm -p 8080:8080 --user 10001:10001 --read-only \
  -v /tmp:/tmp <your-username>/d387-app:latest

Additional Security Measures:

  • Deploy behind WAF (Web Application Firewall)
  • Use network policies to restrict inbound/outbound traffic
  • Enable container runtime security monitoring
  • Regular vulnerability scanning in CI/CD pipeline
  • Consider using distroless base images for production

⁠Troubleshooting

  • Logs: docker logs <container-id>
  • Health: curl -sSf http://localhost:8080/actuator/health
  • Port conflicts: map a different host port, e.g., -p 8081:8080

⁠Version Information

ComponentVersionStatus
Spring Boot2.7.18End-of-life (last 2.7.x release)
Tomcat9.0.83Known vulnerabilities (2C, 26H)
Java17Supported
Base Imageeclipse-temurin:17-jre-alpineUp-to-date

Recommended for Production: Upgrade to Spring Boot 3.3.x for active security support.

Tag summary

Content type

Image

Digest

sha256:7c22b8d9c…

Size

101.7 MB

Last updated

10 months ago

docker pull zinthose/d387-app