CI/CD & Build
GitHub Actions workflows and Docker image publication for the API Gateway.
GitHub Actions Workflows
One workflow is defined under .github/workflows/.
docker-publish.yml — Container Image
Trigger: Push to the default branch.
Key details:
- Builds the JAR with JDK 17 (Temurin) and
mvn build -DskipTests. - Logs in to Docker Hub using the
DOCKERHUB_USERNAMandDOCKERHUB_TOKENsecrets. - Publishes the image as
${DOCKERHUB_USERNAM}/arya-banking-api-gateway:latest.
The published image is consumed by the infrastructure stack (arya-banking-infra/compose/platform.yml) as karthikulkarni/arya-banking-api-gateway:latest.
Dockerfile
The gateway uses a multi-stage Dockerfile: a Maven build stage producing the fat JAR, followed by a slim JRE runtime stage.
> Dockerfile code-highlight
# Stage 1 — Build
FROM maven:3.9.4-eclipse-temurin-17 AS build
WORKDIR /workspace
COPY settings.xml .
COPY pom.xml .
RUN mvn -B dependency:go-offline -s settings.xml
COPY src ./src
RUN mvn -B -DskipTests clean package -s settings.xml
# Stage 2 — Runtime
FROM eclipse-temurin:17-jre-jammy
RUN apt-get update && apt-get install -y --no-install-recommends curl \
&& rm -rf /var/lib/apt/lists/*
COPY /workspace/target/*.jar /app/app.jar
EXPOSE 8085
ENTRYPOINT ["java","-jar","/app/app.jar"]
- Build stage:
maven:3.9.4-eclipse-temurin-17— resolves dependencies viasettings.xmlso the privatearya-banking-commonartifact can be fetched from GitHub Packages. - Runtime stage:
eclipse-temurin:17-jre-jammywithcurlinstalled for container health checks. - Exposed port:
8085(the gateway's HTTP port). - Entrypoint:
java -jar /app/app.jar.
The repository-level settings.xml maps the GitHub Packages registry as server id github:
> Xml code-highlight
<settings>
<servers>
<server>
<id>github</id>
<username>${env.GITHUB_ACTOR}</username>
<password>${env.GH_PAT}</password>
</server>
</servers>
</settings>
Required Secrets
| Secret | Purpose |
|---|---|
DOCKERHUB_USERNAM | Docker Hub username for image pushes |
DOCKERHUB_TOKEN | Docker Hub access token |
GH_PAT | GitHub Packages access for private Maven dependencies |
cicdgithub-actionsmavendocker