mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-02 21:03:34 +03:00
## Summary - Add a scheduled GitHub Actions workflow that checks for the latest stable Gradle release. - Update the Gradle wrapper and pinned Gradle Docker build images automatically. - Open an automated pull request when an update is available. - Update the developer prerequisites to Node.js 22+ and Gradle 9.0+. ## Details The workflow runs every Monday at 03:00 UTC and can also be triggered manually. It: 1. Resolves the latest stable Gradle version. 2. Finds the matching `gradle:<version>-jdk25` Docker image digest. 3. Updates the Gradle wrapper and Dockerfiles. 4. Verifies the resolved wrapper version and checks the resulting diff. 5. Creates or updates an automated dependency pull request. The current wrapper and Docker image changes are included as the initial update generated by this workflow. ## Testing - Verified the generated changes with `git diff --check`. - The workflow validates the wrapper version before opening the automated pull request.
137 lines
6.2 KiB
Docker
137 lines
6.2 KiB
Docker
# Stirling-PDF Dockerfile - Ultra-lite version with embedded frontend
|
|
# Single JAR contains both frontend and backend with minimal dependencies
|
|
|
|
# Stage 1: Build application with embedded frontend
|
|
FROM gradle:9.7.0-jdk25@sha256:7d4e63b32991e679b183645680ff81762b6f1ef137850d8c2750b362eb994d08 AS build
|
|
|
|
# Install Node.js and npm for frontend build
|
|
ARG TASK_VERSION=3.52.0
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
curl \
|
|
&& curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \
|
|
&& apt-get install -y --no-install-recommends nodejs \
|
|
&& npm --version \
|
|
&& node --version \
|
|
&& ARCH=$(dpkg --print-architecture) \
|
|
&& curl -fsSL "https://github.com/go-task/task/releases/download/v${TASK_VERSION}/task_${TASK_VERSION}_linux_${ARCH}.deb" -o /tmp/task.deb \
|
|
&& dpkg -i /tmp/task.deb \
|
|
&& rm /tmp/task.deb \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy gradle files for dependency resolution
|
|
COPY build.gradle settings.gradle gradlew ./
|
|
COPY gradle/ gradle/
|
|
COPY buildSrc/build.gradle buildSrc/
|
|
COPY buildSrc/src/main/ buildSrc/src/main/
|
|
COPY app/core/build.gradle app/core/
|
|
COPY app/common/build.gradle app/common/
|
|
COPY app/proprietary/build.gradle app/proprietary/
|
|
|
|
# JDK 25+: --add-exports is no longer accepted via JAVA_TOOL_OPTIONS; use JDK_JAVA_OPTIONS instead
|
|
ENV JDK_JAVA_OPTIONS="--add-exports=jdk.compiler/com.sun.tools.javac.api=ALL-UNNAMED \
|
|
--add-exports=jdk.compiler/com.sun.tools.javac.file=ALL-UNNAMED \
|
|
--add-exports=jdk.compiler/com.sun.tools.javac.parser=ALL-UNNAMED \
|
|
--add-exports=jdk.compiler/com.sun.tools.javac.tree=ALL-UNNAMED \
|
|
--add-exports=jdk.compiler/com.sun.tools.javac.util=ALL-UNNAMED"
|
|
|
|
RUN ./gradlew dependencies --no-daemon || true
|
|
|
|
# Copy entire project
|
|
COPY . .
|
|
|
|
# Build ultra-lite JAR with embedded frontend (minimal features).
|
|
# Embed the admin portal app at /portal when the deploy workflow flags it.
|
|
ARG BUILD_PORTAL=false
|
|
# Bundle only the JPDFium native for this image's target arch.
|
|
ARG TARGETARCH
|
|
RUN JPDFIUM_PLATFORM="$([ "$TARGETARCH" = arm64 ] && echo linux-arm64 || echo linux-x64)" && \
|
|
DISABLE_ADDITIONAL_FEATURES=true \
|
|
./gradlew clean build \
|
|
-PbuildWithFrontend=true \
|
|
-PbuildWithPortal=${BUILD_PORTAL} \
|
|
-PjpdfiumPlatforms="$JPDFIUM_PLATFORM" \
|
|
-x spotlessApply -x spotlessCheck -x test -x sonarqube \
|
|
--no-daemon
|
|
|
|
# Stage 2: Runtime image
|
|
# glibc base (not Alpine/musl): JPDFium's PDFium natives are glibc-linked.
|
|
FROM eclipse-temurin:25-jre-noble@sha256:fbcf915c585659b30eb766ada4d6d7cfc9ec1040bf521e95bf61b10a25af73db
|
|
|
|
ENV DEBIAN_FRONTEND=noninteractive \
|
|
LANG=C.UTF-8 \
|
|
LC_ALL=C.UTF-8
|
|
|
|
ARG VERSION_TAG
|
|
|
|
# Labels
|
|
LABEL org.opencontainers.image.title="Stirling-PDF Ultra-Lite" \
|
|
org.opencontainers.image.description="Stirling-PDF with embedded frontend - Ultra-lite version with minimal dependencies" \
|
|
org.opencontainers.image.source="https://github.com/Stirling-Tools/Stirling-PDF" \
|
|
org.opencontainers.image.licenses="MIT" \
|
|
org.opencontainers.image.vendor="Stirling-Tools" \
|
|
org.opencontainers.image.url="https://www.stirlingpdf.com" \
|
|
org.opencontainers.image.documentation="https://docs.stirlingpdf.com" \
|
|
maintainer="Stirling-Tools" \
|
|
org.opencontainers.image.authors="Stirling-Tools" \
|
|
org.opencontainers.image.version="${VERSION_TAG}" \
|
|
org.opencontainers.image.keywords="PDF, manipulation, ultra-lite, API, Spring Boot, React"
|
|
|
|
# Environment Variables
|
|
# NOTE: Memory flags (InitialRAMPercentage, MaxRAMPercentage, MaxMetaspaceSize)
|
|
# are computed dynamically by init-without-ocr.sh based on container memory limits.
|
|
ENV VERSION_TAG=$VERSION_TAG \
|
|
STIRLING_AOT_ENABLE="false" \
|
|
STIRLING_JVM_PROFILE="balanced" \
|
|
_JVM_OPTS_BALANCED="-XX:+ExitOnOutOfMemoryError -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=/configs/heap_dumps -XX:+UseG1GC -XX:MaxGCPauseMillis=200 -XX:G1HeapRegionSize=4m -XX:G1PeriodicGCInterval=60000 -XX:+UseStringDeduplication -XX:+UseCompactObjectHeaders -XX:+ExplicitGCInvokesConcurrent -Dspring.threads.virtual.enabled=true -Djava.awt.headless=true" \
|
|
_JVM_OPTS_PERFORMANCE="-XX:+ExitOnOutOfMemoryError -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=/configs/heap_dumps -XX:+UseShenandoahGC -XX:ShenandoahGCMode=generational -XX:+UseCompactObjectHeaders -XX:+UseStringDeduplication -XX:+AlwaysPreTouch -XX:+ExplicitGCInvokesConcurrent -Dspring.threads.virtual.enabled=true -Djava.awt.headless=true" \
|
|
JAVA_CUSTOM_OPTS="" \
|
|
HOME=/home/stirlingpdfuser \
|
|
PUID=1000 \
|
|
PGID=1000 \
|
|
UMASK=022 \
|
|
STIRLING_TEMPFILES_DIRECTORY=/tmp/stirling-pdf \
|
|
TMPDIR=/tmp/stirling-pdf \
|
|
TEMP=/tmp/stirling-pdf \
|
|
TMP=/tmp/stirling-pdf \
|
|
ENDPOINTS_GROUPS_TO_REMOVE=CLI
|
|
|
|
# Install minimal dependencies
|
|
RUN mkdir -p $HOME /configs /logs /customFiles /pipeline/watchedFolders /pipeline/finishedFolders /storage /tmp/stirling-pdf /tmp/stirling-pdf/heap_dumps && \
|
|
mkdir -p /usr/share/fonts/opentype/noto && \
|
|
apt-get update && \
|
|
apt-get install -y --no-install-recommends \
|
|
ca-certificates \
|
|
tzdata \
|
|
tini \
|
|
bash \
|
|
curl \
|
|
procps \
|
|
util-linux && \
|
|
rm -rf /var/lib/apt/lists/* && \
|
|
# User permissions
|
|
userdel -r ubuntu 2>/dev/null || true && \
|
|
groupdel ubuntu 2>/dev/null || true && \
|
|
groupadd -g 1000 stirlingpdfgroup && useradd -u 1000 -d $HOME -s /bin/bash -g stirlingpdfgroup stirlingpdfuser && \
|
|
chown -R stirlingpdfuser:stirlingpdfgroup $HOME /configs /customFiles /pipeline /storage /tmp/stirling-pdf
|
|
|
|
# Copy scripts and built artifacts after OS package layer to maximize cache reuse.
|
|
COPY --chown=1000:1000 scripts/init-without-ocr.sh /scripts/init-without-ocr.sh
|
|
COPY --chown=1000:1000 scripts/installFonts.sh /scripts/installFonts.sh
|
|
COPY --chown=1000:1000 scripts/stirling-diagnostics.sh /scripts/stirling-diagnostics.sh
|
|
|
|
# Copy built JARs from build stage
|
|
COPY --from=build --chown=1000:1000 \
|
|
/app/app/core/build/libs/*.jar /app.jar
|
|
COPY --from=build --chown=1000:1000 \
|
|
/app/build/libs/restart-helper.jar /restart-helper.jar
|
|
|
|
RUN chmod +x /scripts/*.sh
|
|
|
|
EXPOSE 8080/tcp
|
|
|
|
# Set user and run command
|
|
ENTRYPOINT ["tini", "--", "/scripts/init-without-ocr.sh"]
|
|
CMD []
|