Quarkus Verification

affaan-m/ECC/skills/quarkus-verification

作者 affaan-mef648e01899ba3e8dc6371642deaaf64b4477775無授權條款275K 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫4 天前更新

Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation, health checks, and config validation. Use when verifying a Quarkus service before a PR, after major refactoring or dependency upgrades, or pre-deploy.

AI 產生的概覽

Quarkus 服務的驗證流程:建置、靜態分析、含涵蓋率的測試、安全掃描、原生編譯與健康檢查。

功能
為 Quarkus 專案提供分階段的驗證流程,涵蓋建置、靜態分析(Checkstyle、PMD、SpotBugs、SonarQube)、含 JaCoCo 涵蓋率門檻的測試、OWASP 相依性與容器安全掃描、GraalVM 原生編譯、負載測試、健康檢查、容器映像建置以及設定驗證。文件提供 Maven 與 Gradle 範例指令、範例測試程式碼、檢查清單和 CI/CD 工作流程範例。其產出是一套可重複的 PR 前與部署前驗證流程,而非產生的檔案。
適用情境
適用於為 Quarkus 服務送出拉取請求之前、重大重構或相依性升級之後,以及針對預備或正式環境的部署前驗證。也適合驗證涵蓋率門檻與測試原生映像相容性。
執行需求
僅為說明文件,未附帶指令碼。執行所述指令需要 Quarkus 專案與 Maven 或 Gradle、JDK,以及選用工具如 JaCoCo、Checkstyle、PMD、SpotBugs、SonarQube、OWASP dependency-check、Docker、Trivy 或 Grype、k6,原生建置另需 GraalVM;部分步驟需要網路存取與憑證(例如 SonarQube 權杖)。

Quarkus Verification Loop

Run before PRs, after major changes, and pre-deploy.

When to Activate

  • Before opening a pull request for a Quarkus service
  • After major refactoring or dependency upgrades
  • Pre-deployment verification for staging or production
  • Running full build → lint → test → security scan → native compilation pipeline
  • Validating test coverage meets thresholds (80%+)
  • Testing native image compatibility

Phase 1: Build

bash
# Mavenmvn clean verify -DskipTests
# Gradle./gradlew clean assemble -x test

If build fails, stop and fix compilation errors.

Phase 2: Static Analysis

Checkstyle, PMD, SpotBugs (Maven)

bash
mvn checkstyle:check pmd:check spotbugs:check

SonarQube (if configured)

bash
mvn sonar:sonar \  -Dsonar.projectKey=my-quarkus-project \  -Dsonar.host.url=http://localhost:9000 \  -Dsonar.login=${SONAR_TOKEN}

Common Issues to Address

  • Unused imports or variables
  • Complex methods (high cyclomatic complexity)
  • Potential null pointer dereferences
  • Security issues flagged by SpotBugs

Phase 3: Tests + Coverage

bash
# Run all testsmvn clean test
# Generate coverage reportmvn jacoco:report
# Enforce coverage threshold (80%)mvn jacoco:check
# Or with Gradle./gradlew test jacocoTestReport jacocoTestCoverageVerification

Test Categories

Unit Tests

Test service logic with mocked dependencies:

java
@ExtendWith(MockitoExtension.class)class UserServiceTest {  @Mock UserRepository userRepository;  @InjectMocks UserService userService;
  @Test  void createUser_validInput_returnsUser() {    var dto = new CreateUserDto("Alice", "[email protected]");
    // Panache persist() is void — use doNothing + verify    doNothing().when(userRepository).persist(any(User.class));
    User result = userService.create(dto);
    assertThat(result.name).isEqualTo("Alice");    verify(userRepository).persist(any(User.class));  }}
Integration Tests

Test with real database (Testcontainers):

java
@QuarkusTest@QuarkusTestResource(PostgresTestResource.class)class UserRepositoryIntegrationTest {
  @Inject  UserRepository userRepository;
  @Test  @Transactional  void findByEmail_existingUser_returnsUser() {    User user = new User();    user.name = "Alice";    user.email = "[email protected]";    userRepository.persist(user);
    Optional<User> found = userRepository.findByEmail("[email protected]");
    assertThat(found).isPresent();    assertThat(found.get().name).isEqualTo("Alice");  }}
API Tests

Test REST endpoints with REST Assured:

java
@QuarkusTestclass UserResourceTest {
  @Test  void createUser_validInput_returns201() {    given()        .contentType(ContentType.JSON)        .body("""            {"name": "Alice", "email": "[email protected]"}            """)        .when().post("/api/users")        .then()        .statusCode(201)        .body("name", equalTo("Alice"));  }
  @Test  void createUser_invalidEmail_returns400() {    given()        .contentType(ContentType.JSON)        .body("""            {"name": "Alice", "email": "invalid"}            """)        .when().post("/api/users")        .then()        .statusCode(400);  }}

Coverage Report

Check target/site/jacoco/index.html for detailed coverage:

  • Overall line coverage (target: 80%+)
  • Branch coverage (target: 70%+)
  • Identify uncovered critical paths

Phase 4: Security Scanning

Dependency Vulnerabilities (Maven)

bash
mvn org.owasp:dependency-check-maven:check

Review target/dependency-check-report.html for CVEs.

Quarkus Security Audit

bash
# Check vulnerable extensionsmvn quarkus:audit
# List all extensionsmvn quarkus:list-extensions

OWASP ZAP (API Security Testing)

bash
docker run -t ghcr.io/zaproxy/zaproxy:stable zap-api-scan.py \  -t http://localhost:8080/q/openapi \  -f openapi

Common Security Checks

  • All secrets in environment variables (not in code)
  • Input validation on all endpoints
  • Authentication/authorization configured
  • CORS properly configured
  • Security headers set
  • Passwords hashed with BCrypt
  • SQL injection protection (parameterized queries)
  • Rate limiting on public endpoints

Phase 5: Native Compilation

Test GraalVM native image compatibility:

bash
# Build native executablemvn package -Dnative
# Or with containermvn package -Dnative -Dquarkus.native.container-build=true
# Test native executable./target/*-runner
# Run basic smoke testscurl http://localhost:8080/q/health/livecurl http://localhost:8080/q/health/ready

Native Image Troubleshooting

Common issues:

  • Reflection: Add reflection config for dynamic classes
  • Resources: Include resources with quarkus.native.resources.includes
  • JNI: Register JNI classes if using native libraries

Example reflection config:

java
@RegisterForReflection(targets = {MyDynamicClass.class})public class ReflectionConfiguration {}

Phase 6: Performance Testing

Load Testing with K6

javascript
// load-test.jsimport http from 'k6/http';import { check } from 'k6';
export const options = {  stages: [    { duration: '30s', target: 50 },    { duration: '1m', target: 100 },    { duration: '30s', target: 0 },  ],};
export default function () {  const res = http.get('http://localhost:8080/api/markets');  check(res, {    'status is 200': (r) => r.status === 200,    'response time < 200ms': (r) => r.timings.duration < 200,  });}

Run:

bash
k6 run load-test.js

Metrics to Monitor

  • Response time (p50, p95, p99)
  • Throughput (requests/sec)
  • Error rate
  • Memory usage
  • CPU usage

Phase 7: Health Checks

bash
# Livenesscurl http://localhost:8080/q/health/live
# Readinesscurl http://localhost:8080/q/health/ready
# All health checkscurl http://localhost:8080/q/health
# Metrics (if enabled)curl http://localhost:8080/q/metrics

Expected responses:

json
{  "status": "UP",  "checks": [    {      "name": "Database connection",      "status": "UP"    }  ]}

Phase 8: Container Image Build

bash
# Build container imagemvn package -Dquarkus.container-image.build=true
# Or with specific registrymvn package \  -Dquarkus.container-image.build=true \  -Dquarkus.container-image.registry=docker.io \  -Dquarkus.container-image.group=myorg \  -Dquarkus.container-image.tag=1.0.0
# Test containerdocker run -p 8080:8080 myorg/my-quarkus-app:1.0.0

Container Security Scan

bash
# Trivytrivy image myorg/my-quarkus-app:1.0.0
# Grypegrype myorg/my-quarkus-app:1.0.0

Phase 9: Configuration Validation

bash
# Check all configuration propertiesmvn quarkus:info
# List all config sourcescurl http://localhost:8080/q/dev/io.quarkus.quarkus-vertx-http/config

Environment-Specific Checks

  • Database URLs configured per environment
  • Secrets externalized (Vault, env vars)
  • Logging levels appropriate
  • CORS origins set correctly
  • Rate limiting configured
  • Monitoring/tracing enabled

Phase 10: Documentation Review

  • OpenAPI/Swagger docs up to date (/q/swagger-ui)
  • README has setup instructions
  • API changes documented
  • Migration guide for breaking changes
  • Configuration properties documented

Generate OpenAPI spec:

bash
curl http://localhost:8080/q/openapi -o openapi.json

Verification Checklist

Code Quality

  • Build passes without warnings
  • Static analysis clean (no high/medium issues)
  • Code follows team conventions
  • No commented-out code or TODOs in PR

Testing

  • All tests pass
  • Code coverage ≥ 80%
  • Integration tests with real database
  • Security tests pass
  • Performance within acceptable limits

Security

  • No dependency vulnerabilities
  • Authentication/authorization tested
  • Input validation complete
  • Secrets not in source code
  • Security headers configured

Deployment

  • Native compilation successful
  • Container image builds
  • Health checks respond correctly
  • Configuration valid for target environment

Native Image

  • Native executable builds
  • Native tests pass
  • Startup time < 100ms
  • Memory footprint acceptable

Automated Verification Script

bash
#!/bin/bashset -e
echo "=== Phase 1: Build ==="mvn clean verify -DskipTests
echo "=== Phase 2: Static Analysis ==="mvn checkstyle:check pmd:check spotbugs:check
echo "=== Phase 3: Tests + Coverage ==="mvn test jacoco:report jacoco:check
echo "=== Phase 4: Security Scan ==="mvn org.owasp:dependency-check-maven:check
echo "=== Phase 5: Native Compilation ==="mvn package -Dnative -Dquarkus.native.container-build=true
echo "=== All Phases Complete ==="echo "Review reports:"echo "  - Coverage: target/site/jacoco/index.html"echo "  - Security: target/dependency-check-report.html"echo "  - Native: target/*-runner"

CI/CD Integration

GitHub Actions Example

yaml
name: Verification
on: [push, pull_request]
jobs:  verify:    runs-on: ubuntu-latest    steps:      - uses: actions/checkout@v7
      - name: Set up JDK 21        uses: actions/setup-java@v5        with:          java-version: '21'          distribution: 'temurin'
      - name: Cache Maven packages        uses: actions/cache@v6        with:          path: ~/.m2          key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
      - name: Build        run: mvn clean verify -DskipTests
      - name: Test with Coverage        run: mvn test jacoco:report jacoco:check
      - name: Security Scan        run: mvn org.owasp:dependency-check-maven:check
      - name: Upload Coverage        uses: codecov/codecov-action@v7        with:          token: ${{ secrets.CODECOV_TOKEN }}          files: target/site/jacoco/jacoco.xml

Best Practices

  • Run verification loop before every PR
  • Automate in CI/CD pipeline
  • Fix issues immediately; don't accumulate debt
  • Keep coverage above 80%
  • Update dependencies regularly
  • Test native compilation periodically
  • Monitor performance trends
  • Document breaking changes
  • Review security scan results
  • Validate configuration for each environment

來源與署名

來源:affaan-m/ECC位於skills/quarkus-verification提交ef648e0

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架