-
-
Notifications
You must be signed in to change notification settings - Fork 434
Expand file tree
/
Copy pathDockerfile
More file actions
executable file
·183 lines (147 loc) · 7.55 KB
/
Copy pathDockerfile
File metadata and controls
executable file
·183 lines (147 loc) · 7.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
#--------- Generic stuff all our Dockerfiles should start with so we get caching ------------
ARG IMAGE_VERSION=11.0.23-jdk21-temurin-noble
ARG JAVA_HOME=/opt/java/openjdk
ARG GDAL_VERSION=3.8.4
ARG TARGETARCH
FROM ghcr.io/osgeo/gdal:ubuntu-full-${GDAL_VERSION} AS gdal-builder
##############################################################################
# Plugin downloader #
##############################################################################
# This container pulls in lists of plugins from
# build_data/{required,stable,community}_plugins.txt, and then builds a curl
# configuration file to fetch everything in each list, allowing HTTPS
# connection re-use.
#
# By comparison, calling curl for each URL individually means setting up a new
# HTTPS connection for each URL, which is at least 3 network round-trips
# before we've even sent our HTTP request!
#
# Being a separate stage, docker buildx can run this part in parallel with the
# rest of the build, and it can leverage caches to improve re-build times when
# not changing any plugins (saving ~460 MiB of downloads).
# Use $BUILDPLATFORM because plugin archives are architecture-neutral, and use
# alpine because it's smaller.
FROM --platform=$BUILDPLATFORM python:alpine3.20 AS geoserver-plugin-downloader
ARG GS_VERSION=3.0.1
ARG GS_VERSION_COMMUNITY
ARG STABLE_PLUGIN_BASE_URL=https://sourceforge.net/projects/geoserver/files/GeoServer
ARG COMMUNITY_EXTENSION_PLUGIN_BASE_URL=https://build.geoserver.org/geoserver/${GS_VERSION%.*}x/community-latest
ARG WAR_URL=https://downloads.sourceforge.net/project/geoserver/GeoServer/${GS_VERSION}/geoserver-${GS_VERSION}-war.zip
ARG LIMIT_EXT_DOWNLOAD=false
ENV OTEL_VERSION=v2.17.1
ENV JMX_PROMETHEUS_VERSION=1.0.1
ENV LOG4J_VERSION=2.24.3
RUN apk update && apk add curl py3-pip bash unzip
RUN pip3 install beautifulsoup4 requests
WORKDIR /work
ADD \
build_data/plugins/community_plugins.py \
build_data/plugins/stable_plugins.py \
build_data/plugins/extensions.sh \
build_data/plugins/required_plugins.txt \
build_data/plugins/plugin_download.sh \
/work/
RUN chmod 0755 /work/extensions.sh && /work/extensions.sh
RUN /work/plugin_download.sh
##############################################################################
# Production stage #
##############################################################################
FROM tomcat:$IMAGE_VERSION AS geoserver-prod
LABEL maintainer="Tim Sutton<tim@linfiniti.com>"
ARG IMAGE_VERSION
ARG COMMUNITY_EXTENSION_PLUGIN_BASE_URL
ARG STABLE_PLUGIN_BASE_URL
ARG GS_VERSION
ARG GS_VERSION_COMMUNITY
ARG HTTPS_PORT=8443
ARG TARGETARCH
ARG TOMCAT_IMAGE_SHA=''
ENV DEBIAN_FRONTEND=noninteractive
ENV OTEL_SERVICE_NAME=geoserver
#Install extra fonts to use with sld font markers
RUN set -eux; \
apt-get update; \
apt-get -y --no-install-recommends install \
locales gnupg2 ca-certificates software-properties-common iputils-ping \
apt-transport-https fonts-cantarell fonts-liberation lmodern fonts-aenigma \
ttf-bitstream-vera ttf-sjfonts tv-fonts libapr1-dev libssl-dev git \
zip unzip curl xsltproc certbot cabextract gettext postgresql-client figlet gosu gdal-bin; \
dpkg-divert --local --rename --add /sbin/initctl \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*; \
gosu nobody true
# copy gdal java bindings
COPY --from=gdal-builder /usr/share/java/ /usr/share/java/
RUN --mount=from=gdal-builder,source=/usr/lib,target=/tmp/gdal-builder-lib \
mkdir -p /usr/lib/jni && \
find /tmp/gdal-builder-lib -path "*/jni/*" -exec cp {} /usr/lib/jni/ \;
ENV \
JAVA_HOME=${JAVA_HOME} \
DEBIAN_FRONTEND=noninteractive \
GEOSERVER_DATA_DIR=/opt/geoserver/data_dir \
GDAL_DATA=/usr/share/gdal \
LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/usr/local/tomcat/native-jni-lib:/usr/lib/jni:/usr/local/apr/lib:/opt/libjpeg-turbo/lib64:/usr/lib:/usr/lib/x86_64-linux-gnu:/usr/lib/x86_64-linux-gnu/jni/:/usr/lib/aarch64-linux-gnu:/usr/lib/aarch64-linux-gnu/jni/" \
FOOTPRINTS_DATA_DIR=/opt/footprints_dir \
GEOWEBCACHE_CACHE_DIR=/opt/geoserver/data_dir/gwc \
CERT_DIR=/etc/certs \
RANDFILE=/etc/certs/.rnd \
FONTS_DIR=/opt/fonts \
GEOSERVER_HOME=/geoserver \
EXTRA_CONFIG_DIR=/settings \
COMMUNITY_PLUGINS_DIR=/community_plugins \
STABLE_PLUGINS_DIR=/stable_plugins \
REQUIRED_PLUGINS_DIR=/required_plugins \
OTEL_DIR=/otel \
JMX_DIR=/jmx
WORKDIR /scripts
ADD resources /tmp/resources
ADD build_data /build_data
ADD scripts /scripts
RUN mkdir -p ${OTEL_DIR} \
&& mkdir -p ${JMX_DIR}
# copy plugins
COPY --from=geoserver-plugin-downloader /work/required_plugins/*.zip ${REQUIRED_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/required_plugins/*.jar ${REQUIRED_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/required_plugins/*.deb ${REQUIRED_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/required_plugins.txt ${REQUIRED_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/stable_plugins/*.zip ${STABLE_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/community_plugins/ ${COMMUNITY_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/geoserver_war/geoserver.* ${REQUIRED_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/community_plugins.txt ${COMMUNITY_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/stable_plugins.txt ${STABLE_PLUGINS_DIR}/
COPY --from=geoserver-plugin-downloader /work/community_plugin_download_failures.txt /etc/kartoza/community_plugin_download_failures.txt
# copy telemetry jars
COPY --from=geoserver-plugin-downloader /work/telemetry/opentelemetry-javaagent.jar ${OTEL_DIR}/opentelemetry-javaagent.jar
COPY --from=geoserver-plugin-downloader /work/telemetry/log4j-layout-template-json.jar "${REQUIRED_PLUGINS_DIR}"/log4j-layout-template-json.jar
COPY --from=geoserver-plugin-downloader /work/telemetry/jmx_prometheus_javaagent.jar ${JMX_DIR}/jmx_prometheus_javaagent.jar
COPY --from=geoserver-plugin-downloader /work/telemetry/jmx_config.yaml ${JMX_DIR}/config.yaml
RUN ldconfig
RUN GS_VERSION_COMMUNITY_RESOLVED="${GS_VERSION_COMMUNITY:-${GS_VERSION%.*}.0}" && \
mkdir -p /etc/kartoza && \
printf '%s\n' \
"TOMCAT_VERSION=${IMAGE_VERSION}" \
"GEOSERVER_VERSION=${GS_VERSION}" \
"GS_VERSION_COMMUNITY=${GS_VERSION_COMMUNITY_RESOLVED}" \
"STABLE_PLUGIN_URL=${STABLE_PLUGIN_BASE_URL}" \
"TOMCAT_DIGEST_SHA=${TOMCAT_IMAGE_SHA}" \
"COMMUNITY_EXTENSION_PLUGIN_BASE_URL=${COMMUNITY_EXTENSION_PLUGIN_BASE_URL}" \
> /etc/kartoza/build_info.env
RUN chmod +x /scripts/*.sh;chmod +x /scripts/lib/*.sh;/scripts/lib/setup.sh \
&& apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
EXPOSE ${HTTPS_PORT}
RUN echo 'figlet -t "Kartoza Docker GeoServer"' >> ~/.bashrc
WORKDIR ${GEOSERVER_HOME}
ENTRYPOINT ["/bin/bash", "/scripts/entrypoint.sh"]
##############################################################################
# Testing Stage #
##############################################################################
FROM geoserver-prod AS geoserver-test
COPY ./scenario_tests/utils/requirements.txt /lib/utils/requirements.txt
RUN set -eux \
&& export DEBIAN_FRONTEND=noninteractive \
&& apt-get update \
&& apt-get -y --no-install-recommends install python3-pip procps \
&& apt-get -y --purge autoremove \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*
RUN pip3 install -r /lib/utils/requirements.txt --break-system-packages