NB: Be sure to install a cekit version >= to 3.1.0. + * `pip3 install cekit` + * `pip3 install docker` + * `pip3 install docker_squash` + +You are ready to build OpenLiberty images using cekit! + +Known issues +============ + +On Mac, if you are using cekit 3.0.1, you will be impacted by this [issue]( +To workaround this problem, you need to do the build in 2 steps. +run cekit first, it will fail but the target/image/Dockerfile is properly generated so you can then use docker to build the image. +For example, to build the builder image: + +``` +$ cekit build docker +$ cd target/image +$ docker build -t openliberty/ol-javaee8-ubi-openshift:latest . +``` \ No newline at end of file diff --git a/image.yaml b/image.yaml new file mode 100644 index 0000000..dcd7a94 --- /dev/null +++ b/image.yaml @@ -0,0 +1,52 @@ +schema_version: 1 + +name: openliberty/ol-javaee8-ubi-openshift +version: 1.0 +from: openliberty/open-liberty:javaee8-ubi-min +description: "Open Libety UBI image with javaee-8" +labels: + - name: io.k8s.description + value: "Open Liberty S2I Image" + - name: io.k8s.display-name + value: "Open Liberty S2I Builder" + - name: io.openshift.tags + value: "runner,builder,openliberty,javaee" + - name: io.openshift.s2i.scripts-url + value: image:///usr/local/s2i + - name: io.s2i.scripts-url + value: image:///usr/local/s2i + - name: io.openshift.expose-services + value: "9080/tcp:http, 9443/tcp:https" + - name: io.openshift.s2i.destination + value: "/tmp" + +envs: + - name: STI_SCRIPTS_PATH + value: "/usr/local/s2i" + - name: WORKDIR + value: "/usr/local/workdir" + - name: S2I_DESTINATION + value: "/tmp" + - name: JAVA_HOME + value: /opt/ibm/java + - name: PATH + value: /opt/ibm/java/bin:$PATH + +packages: + manager: microdnf + +modules: + repositories: + - path: modules + + # Install selected modules (in order) + install: + - name: ibmjdk8 + - name: maven + - name: ol-s2i + +run: + user: 1001 + cmd: + - "/opt/ol/wlp/bin/server run defaultServer" + diff --git a/imagestreams/openliberty-ubi-min.json b/imagestreams/openliberty-ubi-min.json new file mode 100644 index 0000000..56c05bd --- /dev/null +++ b/imagestreams/openliberty-ubi-min.json @@ -0,0 +1,33 @@ +{ + "apiVersion": "v1", + "kind": "ImageStream", + "metadata": { + "annotations": { + "": "Open Liberty" + }, + "name": "openliberty" + }, + "spec": { + "tags": [ + { + "annotations": { + "description": "Build and run Open Liberty applications on Red Hat Universal Base Image 7. For more information about using this builder image, including OpenShift considerations, see TODO.\n\nWARNING: By selecting this tag, your application will automatically update to use the latest version of Open Liberty available on OpenShift, including major versions updates.", + "iconClass": "icon-openliberty", + "": "Open Liberty (Latest)", + "": "IBM", + "sampleRepo": "", + "supports": "jee,java", + "tags": "builder,openliberty,java" + }, + "from": { + "kind": "DockerImage", + "name": "" + }, + "referencePolicy": { + "type": "Local" + }, + "name": "latest" + } + ] + } +} diff --git a/make/ b/make/ new file mode 100755 index 0000000..29503ee --- /dev/null +++ b/make/ @@ -0,0 +1,9 @@ +#!/bin/bash -e +SCRIPT_DIR=$(dirname $0) +pushd ${SCRIPT_DIR}/.. +cekit build docker +popd + +if [[ ! -z "${TEST_MODE:-}" ]]; then + ${SCRIPT_DIR}/../test/run +fi diff --git a/make/ b/make/ new file mode 100644 index 0000000..a97ff46 --- /dev/null +++ b/make/ @@ -0,0 +1,14 @@ +build = make/ + +script_env = \ + IMAGE_NAME=$(IMAGE_NAME) \ + IMAGE_VERSION=$(IMAGE_VERSION) \ + RUNTIME_IMAGE_NAME=$(RUNTIME_IMAGE_NAME) + +.PHONY: build +build: + $(script_env) $(build) + +.PHONY: test +test: + $(script_env) TEST_MODE=true $(build) diff --git a/modules/ibmjdk8/ b/modules/ibmjdk8/ new file mode 100755 index 0000000..02c8e69 --- /dev/null +++ b/modules/ibmjdk8/ @@ -0,0 +1,18 @@ +#!/bin/sh + +set -e + +microdnf install gzip + +echo "INSTALLER_UI=silent" > /tmp/ \ + && echo "USER_INSTALL_DIR=/opt/ibm/java" >> /tmp/ \ + && echo "LICENSE_ACCEPTED=TRUE" >> /tmp/ \ + && mkdir -p /opt/ibm \ + && chmod +x /tmp/artifacts/ibm-java.bin \ + && /tmp/artifacts/ibm-java.bin -i silent -f /tmp/ \ + && rm -f /tmp/ \ + && rm -f /tmp/artifacts/ibm-java.bin + +# Subsequent installation of maven needs gzip +# microdnf remove gzip + diff --git a/modules/ibmjdk8/module.yaml b/modules/ibmjdk8/module.yaml new file mode 100644 index 0000000..caa6e23 --- /dev/null +++ b/modules/ibmjdk8/module.yaml @@ -0,0 +1,15 @@ +schema_version: 1 + +name: ibmjdk8 +version: 1.0 +description: "Module used to install IBM JDK 8" + +# Defined artifacts that are used to build the image +artifacts: + - name: ibm-java.bin + url: + sha256: bc53faf476655e565f965dab3db37f9258bfc16bb8c5352c93d43d53860b79d3 + +execute: + - script: + diff --git a/modules/maven/ b/modules/maven/ new file mode 100755 index 0000000..d50465e --- /dev/null +++ b/modules/maven/ @@ -0,0 +1,14 @@ +#!/bin/sh + +set -e + +microdnf install gzip + + tar -C /usr/local -zxf /tmp/artifacts/maven.tar.gz \ + && ln -sf /usr/local/apache-maven-3.5.4/bin/mvn /usr/local/bin/mvn + +microdnf remove gzip + +mkdir -p /home/default/.m2/repository +chown -R 1001 /home/default/.m2 +chmod -R ug+rwX /home/default/.m2 diff --git a/modules/maven/module.yaml b/modules/maven/module.yaml new file mode 100644 index 0000000..2f77bcd --- /dev/null +++ b/modules/maven/module.yaml @@ -0,0 +1,15 @@ +schema_version: 1 + +name: maven +version: 1.0 +description: "Module used to install Maven 3.5.4" + +# Defined artifacts that are used to build the image +artifacts: + - name: maven.tar.gz + url: + sha512: 2a803f578f341e164f6753e410413d16ab60fabe31dc491d1fe35c984a5cce696bc71f57757d4538fe7738be04065a216f3ebad4ef7e0ce1bb4c51bc36d6be86 + +execute: + - script: + diff --git a/modules/ol-s2i/artifacts/usr/local/s2i/assemble b/modules/ol-s2i/artifacts/usr/local/s2i/assemble new file mode 100755 index 0000000..1dbdce8 --- /dev/null +++ b/modules/ol-s2i/artifacts/usr/local/s2i/assemble @@ -0,0 +1,100 @@ +#!/bin/bash -e +# +# (C) Copyright IBM Corporation 2016. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +# S2I assemble script for the 'open-liberty-javaee8' image. + +echo "Running s2i assemble with user $USER home $HOME" + +if [ -f $S2I_DESTINATION/src/wlp/config/server.xml ]; then + cp $S2I_DESTINATION/src/wlp/config/server.xml /config +else + echo "No server.xml found, using default" +fi + +# Source code provided to S2I is at /tmp/src +LOCAL_SOURCE_DIR=/tmp/src + +# Resulting WAR files will be deployed to /opt/ol/wlp/usr/servers/defaultServer/dropins/ +DEPLOY_DIR=/opt/ol/wlp/usr/servers/defaultServer/dropins/ + +# If a pom.xml is present, this is a normal build scenario +# so run maven. +if [ -f "$LOCAL_SOURCE_DIR/pom.xml" ]; then + + pushd $LOCAL_SOURCE_DIR &> /dev/null + + if [ -z "$MAVEN_ARGS" ]; then + export MAVEN_ARGS="package -Popenshift -DskipTests" + fi + + # Append arguments to MAVEN_ARGS if necessary + if [ -n "$MAVEN_ARGS_APPEND" ]; then + echo "Maven additional arguments: $MAVEN_ARGS_APPEND" + export MAVEN_ARGS="$MAVEN_ARGS $MAVEN_ARGS_APPEND" + fi + echo "Found pom.xml... attempting to build with 'mvn ${MAVEN_ARGS}'" + + mvn --version + mvn $MAVEN_ARGS + + ERR=$? + if [ $ERR -ne 0 ]; then + echo "Aborting due to error code $ERR from mvn package" + exit $ERR + fi + + + #Copy .war file from the source directory + echo "Copying built war files into $DEPLOY_DIR for later deployment..." + popd &> /dev/null +else + echo "Copying binaries in source directory into $DEPLOY_DIR for later deployment..." +fi + +ls -l /tmp/src + +if [ -d $LOCAL_SOURCE_DIR/target ]; then + cp $LOCAL_SOURCE_DIR/target/*.war $DEPLOY_DIR 2>/dev/null || : + cp $LOCAL_SOURCE_DIR/target/*.ear $DEPLOY_DIR 2>/dev/null || : + cp $LOCAL_SOURCE_DIR/target/*.jar $DEPLOY_DIR 2>/dev/null || : + cp $LOCAL_SOURCE_DIR/target/*.rar $DEPLOY_DIR 2>/dev/null || : +fi + +if [ -d $LOCAL_SOURCE_DIR/deployments ]; then + cp $LOCAL_SOURCE_DIR/deployments/*.war $DEPLOY_DIR >& /dev/null + cp $LOCAL_SOURCE_DIR/deployments/*.ear $DEPLOY_DIR >& /dev/null + cp $LOCAL_SOURCE_DIR/deployments/*.jar $DEPLOY_DIR >& /dev/null + cp $LOCAL_SOURCE_DIR/deployments/*.rar $DEPLOY_DIR >& /dev/null +fi + +# Copy supporting files from OL directory +if [ -d $S2I_DESTINATION/src/wlp/usr ]; then + cp -R $S2I_DESTINATION/src/wlp/usr /opt/ol/wlp +fi + +# Run configure again to pick up configuration from the environmentf +echo "whoami: " +whoami + +echo "perms:" +ls -l /opt/ol/wlp/output + +echo "Configuring Server" +echo "MP: $MP_MONITORING" +/opt/ol/helpers/build/ + +echo "Application deployment finished! Please start up the Open Liberty container using the following command: docker run -P " +exit $rc diff --git a/modules/ol-s2i/artifacts/usr/local/s2i/run b/modules/ol-s2i/artifacts/usr/local/s2i/run new file mode 100755 index 0000000..a9827fc --- /dev/null +++ b/modules/ol-s2i/artifacts/usr/local/s2i/run @@ -0,0 +1,10 @@ +#!/bin/bash -e +# +# S2I run script for the 'open-liberty-javaee8' image. +# The run script executes the server that runs your application. +# +# For more information see the documentation: +# +# + +/opt/ol/wlp/bin/server run defaultServer diff --git a/modules/ol-s2i/artifacts/usr/local/s2i/save-artifacts b/modules/ol-s2i/artifacts/usr/local/s2i/save-artifacts new file mode 100755 index 0000000..fdccb70 --- /dev/null +++ b/modules/ol-s2i/artifacts/usr/local/s2i/save-artifacts @@ -0,0 +1,10 @@ +#!/bin/sh -e +# +# S2I save-artifacts script for the 'liberty-javaee7' image. +# The save-artifacts script streams a tar archive to standard output. +# The archive contains the files and folders you want to re-use in the next build. +# +# For more information see the documentation: +# +# +# tar cf - diff --git a/modules/ol-s2i/artifacts/usr/local/s2i/usage b/modules/ol-s2i/artifacts/usr/local/s2i/usage new file mode 100755 index 0000000..94da56f --- /dev/null +++ b/modules/ol-s2i/artifacts/usr/local/s2i/usage @@ -0,0 +1,32 @@ +#! /bin/bash -e +# +# (C) Copyright IBM Corporation 2016. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +# inform the user how to use the image +cat <&"/dev/null" || READLINK_EXEC="greadlink" + ! type -a "gmktemp" >&"/dev/null" || MKTEMP_EXEC="gmktemp" +fi + +SCRIPT_DIR=$(dirname $0) +_dir="$(dirname "${BASH_SOURCE[0]}")" +test_dir="$($READLINK_EXEC ${_dir} || echo ${_dir})" +log_file=$test_dir/test.log +s2i_log_file=$test_dir/s2i.log +cid_file=$test_dir/test.cid + +SNIPPETS_TARGET=/config/configDropins/overrides + +# Environment variables used to modify the Open Liberty configuration +ENABLE_SSL_VAR="-e SSL=true" +ENABLE_TLS_VAR="-e TLS=true" +HTTP_ENDPOINT_VAR="-e HTTP_ENDPOINT=true" +MP_HEALTH_CHECK_VAR="-e MP_HEALTH_CHECK=true" +MP_MONITORING_VAR="-e MP_MONITORING=true" +HZ_SESSION_CACHE_CLIENT_VAR="-e HZ_SESSION_CACHE=client" +HZ_SESSION_CACHE_EMBEDDED_VAR="-e HZ_SESSION_CACHE=embedded" +IIOP_ENDPOINT_VAR="-e IIOP_ENDPOINT=true" +JMS_ENDPOINT_VAR="-e JMS_ENDPOINT=true" + +# Since we built the image locally, we don't want S2I attempt to pull +# it from Docker hub +s2i_args="--pull-policy=never" + +test_port=9080 + +image_exists() { + echo "Checking image $1" + docker inspect $1 &>/dev/null +} + + +container_exists() { + echo "Checking container $(cat $cid_file)" + image_exists $(cat $cid_file) +} + +container_ip() { + docker inspect --format='{{(index (index .NetworkSettings.Ports "9080/tcp") 0).HostIp}}' $(cat $cid_file) | sed 's/' +} + +container_port() { + docker inspect --format="{{"{{"}}(index .NetworkSettings.Ports \"$test_port/tcp\" 0).HostPort {{"}}"}}" "$(cat "${cid_file}")" +} + + +prepare() { + app=$1 + shift + if ! image_exists ${IMAGE_NAME}:${IMAGE_VERSION}; then + echo "ERROR: The image ${IMAGE_NAME}:${IMAGE_VERSION} must exist before this script is executed." + exit 1 + fi + s2i build ${s2i_args} ${test_dir}/$app ${IMAGE_NAME}:${IMAGE_VERSION} ${IMAGE_NAME}-testapp $@ >& $s2i_log_file +} + +run_test_application() { + docker run $@ --rm -p ${test_port}:${test_port} --cidfile=${cid_file} ${IMAGE_NAME}-testapp >& $log_file +} + +run_test_mp_monitoring() { + docker exec $(cat $cid_file) cat $SNIPPETS_TARGET/mp-monitoring.xml + check_result $? +} + +run_test_mp_health_check() { + docker exec $(cat $cid_file) cat $SNIPPETS_TARGET/mp-health-check.xml + check_result $? +} + +run_test_jms_endpoint() { + docker exec $(cat $cid_file) cat $SNIPPETS_TARGET/jms-endpoint.xml + check_result $? +} + +run_test_jms_endpoint_ssl() { + docker exec $(cat $cid_file) cat $SNIPPETS_TARGET/jms-ssl-endpoint.xml + check_result $? +} + +cleanup() { + echo "Cleanup for test, cid $(cat $cid_file)" + if container_exists; then + if [[ $1 != "0" ]]; then + echo "Viewing docker logs" + docker logs $(cat $cid_file) + fi + echo "Stopping container $(cat $cid_file)" + docker stop $(cat $cid_file) || true + fi + if image_exists ${IMAGE_NAME}-testapp; then + docker rmi -f ${IMAGE_NAME}-testapp + fi + if image_exists ${RUNTIME_IMAGE_NAME}-testapp; then + docker rmi -f ${RUNTIME_IMAGE_NAME}-testapp + fi + rm -rf ${test_dir}/test-app/.git + rm -f $cid_file +} + +cleanupFinal() { + rm -f $log_file + rm -f $s2i_log_file +} + +check_result() { + local result="$1" + if [[ "$result" != "0" ]]; then + cleanup 1 + echo "S2I image '${IMAGE_NAME}' test FAILED (exit code: ${result}), last container execution log file in $log_file" + exit $result + fi +} + +wait_for_cid() { + local max_attempts=30 + local sleep_time=1 + local attempt=1 + local result=1 + while [ $attempt -le $max_attempts ]; do + [ -f $cid_file ] && [ -s $cid_file ] && break + echo "Waiting for container start..." + attempt=$(( $attempt + 1 )) + sleep $sleep_time + done +} + +run_test_usage() { + s2i usage ${s2i_args} ${IMAGE_NAME}:${IMAGE_VERSION} &>/dev/null +} + +test_connection() { + local max_attempts=30 + local sleep_time=1 + local attempt=1 + local result=1 + while [ $attempt -le $max_attempts ]; do + echo "Sending GET request to http://$(container_ip):${test_port}/" + set +e + response_code=$(curl -s -w %{http_code} -o /dev/null http://$(container_ip):${test_port}/) + status=$? + set -e + if [ $status -eq 0 ]; then + if [ $response_code -eq 200 ]; then + result=0 + fi + break + fi + attempt=$(( $attempt + 1 )) + sleep $sleep_time + done + return $result +} + + + +echo "Testing image $IMAGE_NAME" +echo "Last s2i execution is logged in $s2i_log_file" +echo "Last container execution is logged in $log_file" + +echo "### Test deployment in default server." + +prepare test-app + +# Verify the 'usage' script is working properly +run_test_usage +check_result $? + +# Verify that the HTTP connection can be established to test application container +run_test_application & + +# Wait for the container to write it's CID file +# +wait_for_cid + +test_connection +check_result $? + +cleanup 0 + +# CONFIGURATION TESTS +# These are simple tests that make sure that environment variables passed to s2i result +# in configuration files being copied to configDropins + +echo "MicroProfile Monitoring Configuration Test" +prepare test-app $MP_MONITORING_VAR +run_test_application & +wait_for_cid +test_connection +check_result $? +run_test_mp_monitoring +cleanup 0 + +echo "MicroProfile Health Configuration Test" +prepare test-app $MP_HEALTH_CHECK_VAR +run_test_application & +wait_for_cid +test_connection +check_result $? +run_test_mp_health_check +cleanup 0 + +echo "JMS Endpoint, No SSL Configuration Test" +prepare test-app $JMS_ENDPOINT_VAR +run_test_application & +wait_for_cid +test_connection +check_result $? +run_test_jms_endpoint +cleanup 0 + +echo "JMS Endpoint, SSL Configuration Test" +prepare test-app $JMS_ENDPOINT_VAR $ENABLE_SSL_VAR +run_test_application & +wait_for_cid +test_connection +check_result $? +run_test_jms_endpoint_ssl + +cleanupFinal + +# END CONFIGURATION TESTS +echo "Test SUCCESSFUL" diff --git a/test/test-app/ b/test/test-app/ new file mode 100644 index 0000000..66289b1 --- /dev/null +++ b/test/test-app/ @@ -0,0 +1,5 @@ +openshift-jee-sample +==================== + +A sample app to be deployed on OpenShift environments + diff --git a/test/test-app/pom.xml b/test/test-app/pom.xml new file mode 100644 index 0000000..840c2b8 --- /dev/null +++ b/test/test-app/pom.xml @@ -0,0 +1,50 @@ + + + 4.0.0 + + SampleApp + SampleApp + war + 1.0 + SampleApp + + + UTF-8 + 1.8 + 1.8 + + + + + javax + javaee-api + 8.0 + provided + + + + + + + + + + openshift + + SampleApp + + + org.apache.maven.plugins + maven-war-plugin + 2.3 + + false + target + ROOT + + + + + + + diff --git a/test/test-app/src/main/java/test/simple/war/ b/test/test-app/src/main/java/test/simple/war/ new file mode 100644 index 0000000..2d0a825 --- /dev/null +++ b/test/test-app/src/main/java/test/simple/war/ @@ -0,0 +1,30 @@ +/******************************************************************************* + * Copyright (c) 2018 IBM Corporation and others. + * All rights reserved. This program and the accompanying materials + * are made available under the terms of the Eclipse Public License v1.0 + * which accompanies this distribution, and is available at + * + * + * Contributors: + * IBM Corporation - initial API and implementation + *******************************************************************************/ +package test.simple.war; + +import; + +import javax.servlet.ServletException; +import javax.servlet.http.HttpServlet; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +public class TestServlet extends HttpServlet { + private static final long serialVersionUID = 1L; + + @Override + protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { + response.getWriter().println("test servlet is running."); + } + + @Override + protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {} +} diff --git a/test/test-app/src/main/java/test/simple/war/ b/test/test-app/src/main/java/test/simple/war/ new file mode 100644 index 0000000..63e0121 --- /dev/null +++ b/test/test-app/src/main/java/test/simple/war/ @@ -0,0 +1,30 @@ +/******************************************************************************* + * Copyright (c) 2018 IBM Corporation and others. + * All rights reserved. This program and the accompanying materials + * are made available under the terms of the Eclipse Public License v1.0 + * which accompanies this distribution, and is available at + * + * + * Contributors: + * IBM Corporation - initial API and implementation + *******************************************************************************/ +package test.simple.war; + +import; + +import javax.servlet.ServletException; +import javax.servlet.http.HttpServlet; +import javax.servlet.http.HttpServletRequest; +import javax.servlet.http.HttpServletResponse; + +public class UpdatedTestServlet extends HttpServlet { + private static final long serialVersionUID = 1L; + + @Override + protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { + response.getWriter().println("this is an updated test servlet."); + } + + @Override + protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {} +} diff --git a/test/test-app/src/main/resources/WEB-INF/web.xml b/test/test-app/src/main/resources/WEB-INF/web.xml new file mode 100644 index 0000000..4b36b80 --- /dev/null +++ b/test/test-app/src/main/resources/WEB-INF/web.xml @@ -0,0 +1,26 @@ + + + + testWarApplication + + + + + TestServlet + TestServlet + test.simple.war.TestServlet + + + TestServlet + + /TestServlet + + + index.html + index.htm + index.jsp + default.html + default.htm + default.jsp + + diff --git a/test/test-app/src/main/webapp/index.html b/test/test-app/src/main/webapp/index.html new file mode 100644 index 0000000..83b94fa --- /dev/null +++ b/test/test-app/src/main/webapp/index.html @@ -0,0 +1,9 @@ + + + + Hello World! + + +

Hello World!

+ + diff --git a/test/test.cid b/test/test.cid new file mode 100644 index 0000000..84d450a --- /dev/null +++ b/test/test.cid @@ -0,0 +1 @@ +034773a2c4a3f92d2f16101b2c355ebb5813196badbb5fac308bbffc97e3fc22 \ No newline at end of file