Build the coordinator image with Jib for every Linux platform the base image publishes - #49
Merged
Merged
Conversation
…e image publishes Signed-off-by: Marvin Froeder <velo.br@gmail.com>
…ers too Signed-off-by: Marvin Froeder <velo.br@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The published coordinator image was amd64-only, so on an arm64 node it dies before the JVM starts with
exec /opt/java/openjdk/bin/java: exec format error.What changes
jib-maven-pluginfromshard4j-coordinator/pom.xmlinstead of a Dockerfile, and published as one multi-arch index covering every Linux platformeclipse-temurin:25-jrepublishes:linux/amd64,linux/arm64,linux/ppc64le,linux/s390x.shard4j-coordinator/Dockerfileis removed so there is a single definition of the image.build.yml'scontainer-imagejob:jib:dockerBuild(Jib picks the runner's platform);registry:2service container and fails if any of the four platforms is missing from the index, so every PR proves the multi-arch path, not only main;jib:build, keeping the existing tags ($VERSION,sha-<12>on main,lateston release tags).Why Jib rather than buildx + QEMU
RUNsteps: it layers the app onto the matching base image per platform, so no emulation, and adding a platform is a pom entry.*-app.jarhappens to sit intarget/.Windows is not built: the base image's
windows/amd64variants are Windows containers, which Jib cannot produce, and the numeric10001:10001user has no meaning there.arm64 CI
build,coordinated-profileandcontainer-imagenow also run onubuntu-24.04-arm(free for public repositories), withfail-fast: false. The arm64 legs are named<job> (arm64); the amd64 legs keep their exact names, so the three required checks onmainstill match.build (arm64)runs the whole reactor including every Testcontainers IT, natively on arm64.coordinated-profile (arm64)runs the failsafe profile against a coordinator container on arm64.container-image (arm64):jib:dockerBuildpicks the runner's platform, so the smoke test boots the arm64 variant natively -- the exact image that failed withexec format error. The platform-index check and the GHCR push run only on the amd64 leg, so the image is pushed once.The arm64 checks are not required checks yet, so Dependabot auto-merge would not wait for them. Adding them is a branch-protection change, left for a separate decision.
Details worth reviewing
/dataownership. Jib cannotchown, so a fresh named volume would be root-owned and the coordinator's exclusive lock on the data directory fails.jib-ownership-extension-mavenchowns/datato10001:10001; the directory comes fromsrc/main/jib/data/, whose.keepplaceholder is excluded from the image.jib.skipistruein the parent andfalsein the coordinator, somvn package jib:…works from the reactor root without the other modules trying to containerize. Jib is not bound to a lifecycle phase: the everyday build stays offline.java -cp @/app/jib-classpath-file …CoordinatorApplicationfrom exploded classes instead ofjava -jar app.jar. Deployments that override the command need updating;JAVA_TOOL_OPTIONSworks either way. Startup to/healthzwas ~3s locally.Verified locally
jib:dockerBuildimage:/healthzanswers with a named volume on/data; with noCOORDINATOR_SECRETSit exits 1 and logs the variable name.jib:buildto a localregistry:2produced an index with all four platforms; the CI platform check passes against it.mvn testpasses.