From a939e673fcf0769d2404878c0f275081961bb521 Mon Sep 17 00:00:00 2001 From: liamfallon Date: Tue, 14 Feb 2023 11:20:40 +0000 Subject: Remove integration base images from PF base images The Docker base image from the integration project is now unmaintained. We replace the Integration base image by updating our own base image to work directly off Alpine. Issue-ID: POLICY-4558 Change-Id: I00097cede2536c88ade3f318479eab309695b41e Signed-off-by: liamfallon --- policy-db-migrator/src/main/docker/Dockerfile | 16 +++-- policy-jdk/alpine/pom.xml | 96 +-------------------------- policy-jdk/alpine/src/main/docker/Dockerfile | 85 +++++++++++++++--------- policy-jre/alpine/pom.xml | 96 +-------------------------- policy-jre/alpine/src/main/docker/Dockerfile | 64 ++++++++++++------ 5 files changed, 110 insertions(+), 247 deletions(-) diff --git a/policy-db-migrator/src/main/docker/Dockerfile b/policy-db-migrator/src/main/docker/Dockerfile index 664649cd..92f45585 100644 --- a/policy-db-migrator/src/main/docker/Dockerfile +++ b/policy-db-migrator/src/main/docker/Dockerfile @@ -1,7 +1,7 @@ #------------------------------------------------------------------------------- # Dockerfile # ============LICENSE_START======================================================= -# Copyright (C) 2021-2022 Nordix Foundation. +# Copyright (C) 2021-2023 Nordix Foundation. # ================================================================================ # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -18,7 +18,7 @@ # SPDX-License-Identifier: Apache-2.0 # ============LICENSE_END========================================================= #------------------------------------------------------------------------------- -FROM onap/policy-jdk-alpine:2.6.1-SNAPSHOT +FROM onap/policy-jre-alpine:2.6.1-SNAPSHOT LABEL maintainer="Policy Team" LABEL org.opencontainers.image.title="Policy db-migrator" @@ -35,10 +35,16 @@ ENV POLICY_ETC /opt/app/policy/etc ENV POLICY_PROFILE /opt/app/policy/etc/profile.d ENV POLICY_BIN /opt/app/policy/bin +USER root RUN apk update && \ - apk add --no-cache mariadb-client && \ - apk add postgresql-client \ - net-tools netcat-openbsd sudo less vim && \ + apk add --no-cache \ + mariadb-client \ + postgresql-client \ + net-tools \ + netcat-openbsd \ + sudo \ + less \ + vim && \ mkdir -p $POLICY_PROFILE $POLICY_BIN && \ chown -R policy:policy $POLICY_ETC $POLICY_BIN diff --git a/policy-jdk/alpine/pom.xml b/policy-jdk/alpine/pom.xml index 69f2c89a..b656b6f8 100644 --- a/policy-jdk/alpine/pom.xml +++ b/policy-jdk/alpine/pom.xml @@ -2,7 +2,7 @@ ============LICENSE_START======================================================= Copyright (C) 2019 Ericsson, Tieto. All rights reserved. Modifications Copyright (C) 2020 AT&T Intellectual Property. All rights reserved. - Modifications Copyright (C) 2022 Nordix Foundation. + Modifications Copyright (C) 2022-2023 Nordix Foundation. ================================================================================ Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. @@ -37,95 +37,8 @@ onap/policy-jdk-alpine - onap/integration-python - 10.1.0 - - - - baseImage - - - aarch64 - - - - - - org.apache.maven.plugins - maven-scm-plugin - 1.13.0 - - - org.codehaus.plexus - plexus-utils - 3.4.2 - - - org.apache.maven.scm - maven-scm-provider-gitexe - 1.13.0 - - - - connection - src/main/resources/meta - - - - checkout-onap-python - validate - - scm:git:https://gerrit.onap.org/r/integration/docker/onap-python - ${project.build.directory}/onap-python - - - checkout - - - - - - io.fabric8 - docker-maven-plugin - - - - generate-python-image - initialize - - true - 1.23 - ${docker.pull.registry} - ${docker.push.registry} - - - ${integration.python.name} - - try - ${project.build.directory}/onap-python - Dockerfile - - ${integration.python.version} - ${integration.python.version}-${maven.build.timestamp} - ${project.docker.latest.minmax.tag.version} - - - - - - - build - - - - - - - - - ${project.artifactId}-${project.version} @@ -169,10 +82,6 @@ ${project.version}-${maven.build.timestamp} ${project.docker.latest.minmax.tag.version} - - ${integration.python.name} - ${integration.python.version} - @@ -205,9 +114,6 @@ build push - - ${docker.jdk.imagename} - diff --git a/policy-jdk/alpine/src/main/docker/Dockerfile b/policy-jdk/alpine/src/main/docker/Dockerfile index a8f84c0c..ab856bf4 100644 --- a/policy-jdk/alpine/src/main/docker/Dockerfile +++ b/policy-jdk/alpine/src/main/docker/Dockerfile @@ -1,7 +1,7 @@ # ============LICENSE_START======================================================= # Copyright (C) 2019 Tieto. All rights reserved. # Modifications Copyright (C) 2020, 2021 AT&T Intellectual Property. All rights reserved. -# Modifications Copyright (C) 2020, 2022 Nordix Foundation. +# Modifications Copyright (C) 2020, 2022-2023 Nordix Foundation. # ================================================================================ # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -18,19 +18,11 @@ # SPDX-License-Identifier: Apache-2.0 # ============LICENSE_END========================================================= -# Docker file to build a base image for all policy components images -# -# $JAVA_HOME is set to /usr/lib/jvm/java-11-openjdk -# more details at https://hub.docker.com/_/openjdk - -ARG INTEGRATION_PYTHON_NAME=${INTEGRATION_PYTHON_NAME} -ARG INTEGRATION_PYTHON_VERSION=${INTEGRATION_PYTHON_VERSION} - -FROM ${INTEGRATION_PYTHON_NAME}:${INTEGRATION_PYTHON_VERSION} +FROM alpine:3.17 LABEL maintainer="Policy Team" -LABEL org.opencontainers.image.title="Policy JDK Alpine" -LABEL org.opencontainers.image.description="Policy Java 11 JDK image based on Alpine" +LABEL org.opencontainers.image.title="Policy JRE Alpine" +LABEL org.opencontainers.image.description="Policy Java 11 JRE image based on Alpine" LABEL org.opencontainers.image.url="https://github.com/onap/policy-docker" LABEL org.opencontainers.image.vendor="ONAP Policy Team" LABEL org.opencontainers.image.licenses="Apache-2.0" @@ -38,32 +30,61 @@ LABEL org.opencontainers.image.created="${git.build.time}" LABEL org.opencontainers.image.version="${git.build.version}" LABEL org.opencontainers.image.revision="${git.commit.id.abbrev}" +ENV JAVA_HOME /usr/lib/jvm/default-jvm +ENV JAVA_OPTS="-Xms256m -Xmx1g" +ENV JAVA_SEC_OPTS="" +ENV PYTHONUNBUFFERED=1 ENV POLICY_HOME=/opt/app/policy +ENV PATH $JAVA_HOME/bin:$PATH + +ARG user=onap +ARG group=onap -USER root +# Default to UTF-8 file.encoding +ENV LANG='en_US.UTF-8' LANGUAGE='en_US:en' LC_ALL='en_US.UTF-8' -RUN rm -rf /opt/java/openjdk \ - && mkdir -p /opt/java/openjdk \ - && mkdir -p /usr/lib/jvm/ \ - && ln -s /opt/java/openjdk /usr/lib/jvm/java-11-openjdk \ - && apk update \ - && apk add --no-cache \ +# Generic additions +RUN apk add --no-cache \ + libretls \ + musl-locales \ + musl-locales-lang \ + openjdk11-jdk \ + openssl \ + ca-certificates && \ + rm -rf /var/cache/apk/* && \ +# ONAP additions + addgroup -S $group && \ + adduser -G $group -D $user && \ + mkdir /var/log/$user && \ + mkdir /app && \ + chown -R $user:$group /var/log/$user && \ + chown -R $user:$group /app && \ +# Policy Framework additions + apk update && \ + apk add --no-cache \ busybox-extras \ curl \ jq \ procps \ unzip \ zip \ - openjdk11 \ - && curl --fail --silent --show-error --retry 3 \ - --output /tmp/apache-maven-3.6.3-bin.tar.gz \ - https://downloads.apache.org/maven/maven-3/3.6.3/binaries/apache-maven-3.6.3-bin.tar.gz \ - && tar zxC /usr/share onap/policy-jre-alpine - onap/integration-java11 - 9.0.0 - - - - baseImage - - - aarch64 - - - - - - org.apache.maven.plugins - maven-scm-plugin - 1.13.0 - - - org.codehaus.plexus - plexus-utils - 3.4.2 - - - org.apache.maven.scm - maven-scm-provider-gitexe - 1.13.0 - - - - connection - src/main/resources/meta - - - - checkout-onap-python - validate - - scm:git:https://gerrit.onap.org/r/integration/docker/onap-java11 - ${project.build.directory}/onap-java11 - - - checkout - - - - - - io.fabric8 - docker-maven-plugin - - - - generate-base-image - initialize - - true - 1.23 - ${docker.pull.registry} - ${docker.push.registry} - - - ${integration.java.name} - - try - ${project.build.directory}/onap-java11 - BareAlpine.Dockerfile - - ${integration.java.version} - ${integration.java.version}-${maven.build.timestamp} - ${project.docker.latest.minmax.tag.version} - - - - - - - build - - - - - - - - - ${project.artifactId}-${project.version} @@ -169,10 +82,6 @@ ${project.version}-${maven.build.timestamp} ${project.docker.latest.minmax.tag.version} - - ${integration.java.name} - ${integration.java.version} - @@ -205,9 +114,6 @@ build push - - ${docker.jre.imagename} - diff --git a/policy-jre/alpine/src/main/docker/Dockerfile b/policy-jre/alpine/src/main/docker/Dockerfile index d4fed90c..f1bf2496 100644 --- a/policy-jre/alpine/src/main/docker/Dockerfile +++ b/policy-jre/alpine/src/main/docker/Dockerfile @@ -1,7 +1,7 @@ # ============LICENSE_START======================================================= # Copyright (C) 2019 Tieto. All rights reserved. # Modifications Copyright (C) 2020, 2021 AT&T Intellectual Property. All rights reserved. -# Modifications Copyright (C) 2020, 2022 Nordix Foundation. +# Modifications Copyright (C) 2020, 2022-2023 Nordix Foundation. # ================================================================================ # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -18,15 +18,7 @@ # SPDX-License-Identifier: Apache-2.0 # ============LICENSE_END========================================================= -# Docker file to build a base image for all policy components images -# -# $JAVA_HOME is set to /usr/lib/jvm/java-11-openjdk -# more details at https://hub.docker.com/_/openjdk - -ARG INTEGRATION_JAVA_NAME=${INTEGRATION_JAVA_NAME} -ARG INTEGRATION_JAVA_VERSION=${INTEGRATION_JAVA_VERSION} - -FROM ${INTEGRATION_JAVA_NAME}:${INTEGRATION_JAVA_VERSION} +FROM alpine:3.17 LABEL maintainer="Policy Team" LABEL org.opencontainers.image.title="Policy JRE Alpine" @@ -38,21 +30,53 @@ LABEL org.opencontainers.image.created="${git.build.time}" LABEL org.opencontainers.image.version="${git.build.version}" LABEL org.opencontainers.image.revision="${git.commit.id.abbrev}" +ENV JAVA_HOME /usr/lib/jvm/default-jvm +ENV JAVA_OPTS="-Xms256m -Xmx1g" +ENV JAVA_SEC_OPTS="" ENV POLICY_HOME=/opt/app/policy +ENV PATH $JAVA_HOME/bin:$PATH -USER root +ARG user=onap +ARG group=onap -RUN apk update \ - && apk add --no-cache \ +# Default to UTF-8 file.encoding +ENV LANG='en_US.UTF-8' LANGUAGE='en_US:en' LC_ALL='en_US.UTF-8' + +# Generic additions +RUN apk add --no-cache \ + libretls \ + musl-locales \ + musl-locales-lang \ + openjdk11-jre \ + openssl \ + ca-certificates && \ + rm -rf /var/cache/apk/* && \ +# ONAP additions + addgroup -S $group && \ + adduser -G $group -D $user && \ + mkdir /var/log/$user && \ + mkdir /app && \ + chown -R $user:$group /var/log/$user && \ + chown -R $user:$group /app && \ +# Policy Framework additions + apk update && \ + apk add --no-cache \ busybox-extras \ curl \ jq \ procps \ unzip \ - zip \ - && addgroup -S policy \ - && adduser -S --shell /bin/sh -G policy policy \ - && mkdir -p ${POLICY_HOME}/ \ - && chown policy:policy ${POLICY_HOME} \ - && mkdir -p /usr/lib/jvm/ \ - && ln -s /opt/java/openjdk /usr/lib/jvm/java-11-openjdk + zip && \ + rm -rf /var/cache/apk/* && \ + addgroup -S policy && \ + adduser -S --shell /bin/sh -G policy policy && \ + mkdir -p ${POLICY_HOME}/ && \ + chown policy:policy ${POLICY_HOME} && \ + mkdir -p /usr/lib/jvm/ && \ + ln -s /opt/java/openjdk /usr/lib/jvm/default-jvm + +# Tell docker that all future commands should be run as the onap user +USER $user +WORKDIR /app + +ENTRYPOINT exec java $JAVA_SEC_OPTS $JAVA_OPTS -jar /app/app.jar -- cgit 1.2.3-korg