Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Comparing Native Java REST API Frameworks - Chi...

Comparing Native Java REST API Frameworks - Chicago JUG 2023

Use Spring Boot! No, use Micronaut!! Nooooo, Quarkus is the best!!! What about Helidon?

Many developers praise the hottest and fastest Java REST frameworks: Micronaut, Quarkus, Spring Boot, and Helidon. In this session, you'll learn how to do the following with each framework:

✅ Build a REST API
✅ Secure your API with OAuth 2.0
✅ Optimize for production with Docker and GraalVM

I'll also share some performance numbers and pretty graphs to compare community metrics.

YouTube recording: https://www.youtube.com/watch?v=TNZAbHR59RI
GitHub repo: https://github.com/oktadev/auth0-java-rest-api-examples
Demo script: @oktadev/auth0-java-rest-api-examples/blob/main/demo.adoc

Matt Raible

August 24, 2023
Tweet

More Decks by Matt Raible

Other Decks in Programming

Transcript

  1. Matt Raible | @mraible August 24, 2023 Native Java REST

    API Comparison Micronaut, Quarkus, Spring Boot, and Helidon Photo by Max Bender https://unsplash.com/photos/8FdEwlxP3oU
  2. @mraible Who is Matt Raible? Father, Husband, Skier, Mountain Biker,

    Whitewater Rafter Bus Lover Web Developer and Java Champion Okta Developer Advocate Blogger on raibledesigns.com and developer.okta.com/blog @mraible
  3. @mraible Today’s Agenda Why Java? Build { REST, GraphQL }

    APIs with Java Secure your APIs with OAuth 2.1 Build with Docker Go Native with GraalVM https://unsplash.com/photos/JsTmUnHdVYQ
  4. @mraible Why Java? 25+ Years of use, abuse, and improvements

    Open Source code is available; many popular open source frameworks and tools Hugely Popular and widely used by many enterprises and web-scale companies
  5. @mraible Download the Oracle builds of OpenJDK https://jdk.java.net/20 Or Eclipse

    builds from Adoptium https://adoptium.net Get Started with Java 20
  6. @mraible Get Started with Java 20 Better yet, use SDKMAN!

    curl -s https://get.sdkman.io | bash 
 sdk install java 20-open
  7. package com.okta.rest.controller; import io.micronaut.http.MediaType; import io.micronaut.http.annotation.Controller; import io.micronaut.http.annotation.Get; import io.micronaut.http.annotation.Produces;

    import io.micronaut.security.annotation.Secured; import io.micronaut.security.rules.SecurityRule; import java.security.Principal; @Controller("/hello") public class HelloController { @Get @Secured(SecurityRule.IS_AUTHENTICATED) @Produces(MediaType.TEXT_PLAIN) public String hello(Principal principal) { return "Hello, " + principal.getName() + "!"; } }
  8. @mraible Get Started with Quarkus sdk install quarkus quarkus create

    app com.okta.rest:quarkus \ --extension="smallrye-jwt,resteasy-reactive"
  9. package com.okta.rest; import io.quarkus.security.Authenticated; import jakarta.ws.rs.GET; import jakarta.ws.rs.Path; import jakarta.ws.rs.Produces;

    import jakarta.ws.rs.core.Context; import jakarta.ws.rs.core.MediaType; import jakarta.ws.rs.core.SecurityContext; import java.security.Principal; @Path("/hello") public class HelloResource { @GET @Authenticated @Produces(MediaType.TEXT_PLAIN) public String hello(@Context SecurityContext context) { Principal userPrincipal = context.getUserPrincipal(); return "Hello, " + userPrincipal.getName() + "!"; } }
  10. Test Quarkus with HTTPie https://httpie.org gradle --console=plain quarkusDev http :8080/hello

    TOKEN=eyJraWQiOiJxOE1QMjFNNHZCVmxOSkxGbFFWNlN... http :8080/hello Authorization:"Bearer $TOKEN"
  11. @mraible Get Started with Spring Boot https start.spring.io/starter.zip \ dependencies==web,oauth2-resource-server,native

    \ packageName==com.okta.rest \ name==spring-boot \ baseDir==spring-boot | tar -xzvf -
  12. @mraible Use the Spring Boot CLI sdk install springboot spring

    init -d=web,oauth2-resource-server,native \ --group-id=com.okta.rest \ --package-name=com.okta.rest spring-boot
  13. package com.okta.rest.controller; import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.RestController; import java.security.Principal; @RestController public

    class HelloController { @GetMapping("/hello") public String hello(Principal principal) { return "Hello, " + principal.getName() + "!"; } }
  14. Test Spring Boot with HTTPie https://httpie.org gradle bootRun http :8080/hello

    TOKEN=eyJraWQiOiJxOE1QMjFNNHZCVmxOSkxGbFFWNlN... http :8080/hello Authorization:"Bearer $TOKEN"
  15. @mraible Get Started with Helidon mvn -U archetype:generate -DinteractiveMode=false \

    -DarchetypeGroupId=io.helidon.archetypes \ -DarchetypeArtifactId=helidon-quickstart-mp \ -DarchetypeVersion=3.2.2 \ -DgroupId=com.okta.rest \ -DartifactId=helidon \ -Dpackage=com.okta.rest
  16. Use the Helidon CLI helidon init --flavor MP \ --groupid

    com.okta.rest \ --artifactid helidon --package com.okta.rest
  17. package com.okta.rest.controller; import io.helidon.security.Principal; import io.helidon.security.annotations.Authenticated; import jakarta.ws.rs.GET; import jakarta.ws.rs.Path;

    import jakarta.ws.rs.core.Context; @Path("/hello") public class HelloResource { @Authenticated @GET public String hello(@Context SecurityContext context) { return "Hello, " + context.userName() + "!"; } }
  18. package com.okta.rest; import com.okta.rest.controller.HelloResource; import org.eclipse.microprofile.auth.LoginConfig; import jakarta.enterprise.context.ApplicationScoped; import jakarta.ws.rs.core.Application;

    import java.util.Set; @LoginConfig(authMethod = "MP-JWT") @ApplicationScoped public class HelloApplication extends Application { @Override public Set<Class<?>> getClasses() { return Set.of(HelloResource.class); } }
  19. Test Helidon with HTTPie https://httpie.org mvn package && java -jar

    target/helidon.jar http :8080/hello TOKEN=eyJraWQiOiJxOE1QMjFNNHZCVmxOSkxGbFFWNlN... http :8080/hello Authorization:"Bearer $TOKEN"
  20. @mraible Startup Performance Milliseconds 0 500 1000 1500 2000 Micronaut

    Quarkus Spring Boot Helidon 1,002 948 413 430 854 739 1,463 401 Dev Startup (gradle or mvn) Packaged Startup (java -jar)
  21. @mraible What about GraphQL APIs? Why GraphQL? Does your favorite

    framework support GraphQL? Micronaut https://micronaut-projects.github.io/micronaut-graphql/latest/guide Quarkus https://quarkus.io/guides/smallrye-graphql Spring Boot https://spring.io/projects/spring-graphql Helidon https://helidon.io/docs/v3/#/mp/graphql
  22. @mraible Secure your API with OAuth 2.1 https://oauth.net/2.1 PKCE is

    required for all clients using the authorization code flow Redirect URIs must be compared using exact string matching The Implicit grant is omitted from this specification The Resource Owner Password Credentials grant is omitted from this specification Bearer token usage omits the use of bearer tokens in the query string of URIs Refresh tokens for public clients must either be sender-constrained or one-time use
  23. @mraible Authenticate with OpenID Connect (OIDC) What is OpenID Connect?

    Does your favorite framework support OIDC authentication? Micronaut https://guides.micronaut.io/latest/micronaut-oauth2-auth0.html Quarkus https://quarkus.io/guides/security-openid-connect-web-authentication Spring Boot https://docs.spring.io/spring-security/reference/servlet/oauth2/login Helidon https://helidon.io/docs/v3/#/mp/security/providers#OIDC-Provider
  24. @mraible Build with Docker Create a Dockerfile 
 FROM openjdk:20-alpine

    ARG JAR_FILE=target/*.jar COPY ${JAR_FILE} app.jar EXPOSE 8080 ENTRYPOINT ["java","-jar","/app.jar"]
  25. @mraible Build with Docker Build your image docker build -t

    <tag-name> . Run your image docker run -it -p 8080:8080 <tag-name>
  26. @mraible Build with Docker: Jib Get Jibby with it! mvn

    verify jib:build gradle jib Or build directly to your Docker daemon mvn verify jib:dockerBuild gradle jibDockerbuild https://github.com/GoogleContainerTools/jib
  27. @mraible Build with Docker Micronaut uses Jib, but you must

    configure plugins Quarkus generates four Docker-related files Dockerfile.jvm Dockerfile.legacy-jar Dockerfile.native Dockerfile.native-micro Quarkus + Jib mvn quarkus:add-extension -Dextensions="container-image-jib" gradle addExtension --extensions="container-image-jib"
  28. @mraible Build with Docker Spring Boot 2.3+ has built-in support

    mvn -Pnative spring-boot:build-image 
 gradle bootBuildImage 
 Uses layered JARs for faster builds dependencies snapshot-dependencies resources application https://spring.io/blog/2020/01/27/creating-docker-images-with-spring-boot-2-3-0-m1
  29. @mraible Build with Docker Helidon generates three Docker-related files Dockerfile

    Dockerfile.jlink Dockerfile.native Helidon + Jib Not available
  30. @mraible Use Micronaut CLI mn create-app ... mvn package -Dpackaging=native-image

    gradle nativeImage gradle dockerBuildNative Go Native with GraalVM and Micronaut https://docs.micronaut.io/latest/guide/#graal
  31. @mraible Go Native with GraalVM and Quarkus Create an executable

    without GraalVM installed mvn package -Dnative -Dquarkus.native.container-build=true gradle build -Dquarkus.package.type=native \ -Dquarkus.native.container-build=true Then, build the image docker build -f src/main/docker/Dockerfile.native -t \ <tag-name> . And run it docker run -it -p 8080:8080 <tag-name> https://quarkus.io/guides/building-native-image
  32. @mraible Use start.spring.io to get plugins Go Native with GraalVM

    and Spring Boot <plugins> <plugin> <groupId>org.graalvm.buildtools</groupId> <artifactId>native-maven-plugin</artifactId> </plugin> <plugin> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-maven-plugin</artifactId> </plugin> </plugins> plugins { ... id 'org.graalvm.buildtools.native' version '0.9.20' }
  33. @mraible Go Native with GraalVM and Spring Boot Build the

    native application mvn native:compile -Pnative gradle nativeCompile Build an image and Docker container mvn spring-boot:build-image -Pnative gradle bootBuildImage
  34. @mraible Build the image docker build -f Dockerfile.native -t <tag-name>

    . And run it docker run --rm -p 8080:8080 <tag-name> Go Native with GraalVM and Helidon
  35. @mraible Native Startup Performance (GraalVM 22.3) Milliseconds 0 12 24

    36 48 60 August 24, 2023 30.8 48.4 38.2 36.8 14 15.6 Micronaut 4.0.4 Micronaut (optimized) Quarkus 3.3.0 Spring Boot 3.1.3 Helidon 3.2.2 Helidon (optimized)
  36. @mraible Native Startup Performance (GraalVM 22.3) Milliseconds 0 12 24

    36 48 60 August 24, 2023 30.8 48.4 38.2 22.8 14 15.6 Micronaut 4.0.4 Micronaut (optimized) Quarkus 3.2.4.Final Spring Boot 3.1.3 Helidon 3.2.2 Helidon (optimized)
  37. @mraible Native Memory Used after 5 requests (MB) Megabytes 0

    30 60 90 120 150 August 24, 2023 101 110 94 58 56 62 Micronaut Micronaut (optimized) Quarkus Spring Boot Helidon Helidon (optimized)
  38. @mraible Stack Overflow Tags 0 45,000 90,000 135,000 180,000 August

    18, 2023 135 142,805 3,945 1,677 Micronaut Quarkus Spring Boot Helidon
  39. @mraible GitHub Stars 0 18,750 37,500 56,250 75,000 August 18,

    2023 3,100 68,900 12,100 5,800 Micronaut Quarkus Spring Boot Helidon
  40. @mraible Jobs on Indeed (US) 0 2,500 5,000 August 18,

    2023 11 4,172 71 39 Micronaut Quarkus Spring Boot Helidon
  41. @mraible Twitter Followers 0 30,000 60,000 90,000 120,000 August 18,

    2023 4,466 102,500 18,100 13,200 Micronaut Quarkus Spring Boot Helidon
  42. @mraible JHipster Support 🤓 Spring Boot 3 - JHipster 8.0.0-beta.2,

    beta 3 or 8.0.0 coming soon! Micronaut blueprint - github.com/jhipster/generator-jhipster-micronaut - v2.0.0 for Micronaut 3, 19 releases, 20 contributors, 495 commits - v3.0.0 with Micronaut 4 with JHipster 8 is next! Quarkus blueprint - github.com/jhipster/generator-jhipster-quarkus - v2.0.0 for Quarkus 2, 7 releases, 18 contributors, 653 commits - v3.0.0 with Quarkus 3 is on the horizon!
  43. @mraible 🏆 Quarkus provides the best developer joy and memory

    usage 🚀 Micronaut is consistently competitive and 4.0 starts the fastest! 🌱 Spring Boot has the strongest community, ecosystem, and growth 🔮 Helidon has a lot of catching up to do ⚡ Spring Boot 3 not as fast as expected My Thoughts
  44. @mraible Action! New to Java? Try Spring Boot Know Spring?

    Trial migration paths Testing is important, invest early and often Design your apps with security in mind Use OpenID Connect and OAuth 2.1 https://unsplash.com/photos/JsTmUnHdVYQ