Images and layerseasy0-2 years
A service's production image is built `FROM eclipse-temurin:21-jdk`, includes Maven's full dependency cache, and is 850 MB. What's wrong with shipping that image, and what does a multi-stage build actually change?
A JDK image carries the compiler, the full toolchain and whatever build-time dependency cache accumulated during mvnw package — none of which the running service ever touches once the jar exists. Shipping it means every pull is slower, every host stores more, and the attack surface is bigger: a compiler and a build tool are extra tools an attacker who gets a shell in the container can use. A multi-stage build uses one image (the JDK) to compile and package the jar, then starts a second, separate image (the JRE) and copies in only the finished jar — the build stage, with everything in it, is discarded entirely once the copy is done. The final image has the JRE and one jar file, nothing else, typically a third the size or smaller.
PreviousA Dockerfile copies the whole repository, then runs `./mvnw package`, and every build re-downloads every dependency even when only a controller class changed. A teammate says "just add more RAM to the build machine." What's actually wrong, and what's the fix?Next A Spring Boot container is configured with `SPRING_DATASOURCE_URL=jdbc:postgresql://localhost:5432/orders`, and the database is a sibling container in the same Compose file. The application can't connect. Why not, and what should the URL say instead?
A Dockerfile copies the whole repository, then runs `./mvnw package`, and every build re-downloads every dependency even when only a controller class changed. A teammate says "just add more RAM to the build machine." What's actually wrong, and what's the fix?A Dockerfile downloads a large tarball, extracts it, and then `rm -rf`s the tarball and the extraction directory in a later `RUN`. The image is still just as large as if the cleanup never happened. Why doesn't the delete shrink the image, and what actually would?