Images and layerseasy0-2 years

A service's production image is built `FROM eclipse-temurin:21-jdk`, includes Maven's full dependency cache, and is 850 MB. What's wrong with shipping that image, and what does a multi-stage build actually change?

A JDK image carries the compiler, the full toolchain and whatever build-time dependency cache accumulated during mvnw package — none of which the running service ever touches once the jar exists. Shipping it means every pull is slower, every host stores more, and the attack surface is bigger: a compiler and a build tool are extra tools an attacker who gets a shell in the container can use. A multi-stage build uses one image (the JDK) to compile and package the jar, then starts a second, separate image (the JRE) and copies in only the finished jar — the build stage, with everything in it, is discarded entirely once the copy is done. The final image has the JRE and one jar file, nothing else, typically a third the size or smaller.

The lesson behind it →
More on Images and layers