Skip to main content

Building RPMs with Maven for Reliable Software Deployment

Struggling with delivery, architecture alignment, or platform stability?

I help teams fix systemic engineering issues: processes, architecture, and clarity.
→ See how I work with teams.


This article explains how to package applications as revisionable RPM artifacts using Maven, a technique that remains valuable for DevOps and platform engineering teams who operate in controlled, reproducible, or air-gapped environments. It covers prerequisites, rpm-maven-plugin configuration, directory mappings, permissions, and how to integrate RPM creation into CI pipelines to deliver consistent deployment units for Java services.

Modern DevOps Packaging: Building RPMs with Maven for Reliable Software Deployment

In modern DevOps and platform engineering, one of the most underrated tools is still the RPM. Even with the rise of containers, many organizations rely on RPM-based delivery to manage internal services, JVM applications, and deployment flows in secure or air-gapped environments. A revisionable, reproducible, OS-native package is often the cleanest way to promote artifacts through development, staging, and production.

Back in 2015, the motivation was simple: create a dependable deployment mechanism that supports installation, upgrades, and rollbacks. That need has not gone away. Today, with CI/CD pipelines and infrastructure automation everywhere, packaging software as an RPM is still a valid and often required delivery method.

Prerequisites

To build RPMs with Maven, you need the following environment:

  • A Linux system such as Red Hat, AlmaLinux, or CentOS
  • Maven installed and working via mvn
  • Git available on the command line
  • RPM build tools installed:
    sudo yum install rpm-build

The workflow is especially useful for Java web applications where the build produces a .war or other deployable artifact.

Building the Project

Before creating the RPM, ensure the project builds successfully so that the target output is available locally. If local tests fail due to missing dependencies (like MongoDB, Tomcat, etc.), you can bypass them with:

mvn clean install -DskipTests

The rpm-maven-plugin uses several parameters to determine how your files should be installed on the target system:

  • directory — where the files will be installed
  • filemode — file permissions for deployment
  • username and groupname — ownership of installed files
  • location — the build-artifact source location

Configuring the RPM Plugin in Your pom.xml

Add the following plugin configuration to your Maven build:

<project>
  ...
  <build>
    <plugins>
      <plugin>
        <groupId>org.codehaus.mojo</groupId>
        <artifactId>rpm-maven-plugin</artifactId>
        <executions>
          <execution>
            <id>generate-rpm</id>
            <goals>
              <goal>rpm</goal>
            </goals>
          </execution>
        </executions>

        <configuration>
          <license>Apache</license>
          <distribution>Development</distribution>
          <group>Applications/Internet</group>
          <packager>ALO</packager>

          <defineStatements>
            <defineStatement>_unpackaged_files_terminate_build 0</defineStatement>
          </defineStatements>

          <mappings>
            <mapping>
              <directory>/var/lib/tomcat/webapps</directory>
              <filemode>600</filemode>
              <username>tomcat</username>
              <groupname>tomcat</groupname>
              <directoryIncluded>false</directoryIncluded>
              <sources>
                <source>
                  <location>target/test.war</location>
                </source>
              </sources>
            </mapping>
          </mappings>

          <preinstallScriptlet>
            <script>echo "Deploying test-api webapp"</script>
          </preinstallScriptlet>
        </configuration>
      </plugin>
    </plugins>
  </build>
</project>

Building and Inspecting the RPM

Run the RPM build step:

mvn rpm:rpm

After the build completes, you can inspect the RPM contents using:

rpm -q --filesbypkg -p target/rpm/<build-name>/RPMS/noarch/test-api-0.0.1-1.noarch.rpm

This ensures that the packaging layout, permissions, ownership, and file placement match what you expect before deploying the artifact to production environments or CI-based promotion pipelines.

Why This Still Matters in 2025

Even in a world dominated by containers, building RPMs remains a practical approach for teams working with legacy systems, controlled production environments, or hybrid setups where OS-level packaging is still the most reliable delivery path. Maven provides an easy and repeatable way to create these artifacts, making RPM packaging a natural fit in modern CI/CD workflows.

If you need help with distributed systems, backend engineering, or data platforms, check my Services.

Most read articles

Building a Model-Agnostic Multi-Agent System with OpenClaw

Over one week we rebuilt our AI stack around OpenClaw’s multi-agent architecture to avoid provider lock-in and stop wasting premium tokens. By aligning models to tasks, diversifying fallbacks across providers, enforcing minimal tool access, and switching to memory-first workflows with ephemeral sessions, we reduced token usage per task by about 70% and cut our monthly bill by 77% while improving operational resilience. How We Achieved 77% Cost Reduction and Provider Independence Over the past week, we rebuilt our AI infrastructure around OpenClaw’s multi-agent architecture. The result was a 77% cost reduction , provider independence , and a delegation system that routes work to the most cost-effective model for each job. Below is the technical journey of optimizing a 7-agent squad with OpenClaw. The Challenge: Model Provider Lock-In We started with a simple problem: our entire squad defaulted to a single model provider. This created three issues: Cost inefficiency beca...

BacNet => MQTT in Production: The Real Cost of Bridging BACnet to MQTT at Scale

bacnet2mqtt looks simple in a README and expensive in production. Once BACnet polling, reconnection behavior, stale state, and MQTT publishing collide, teams discover they are not deploying a lightweight adapter but operating infrastructure. This article breaks down where bacnet2mqtt works, where it becomes a bottleneck, and which production patterns reduce the operational damage before incidents, backlogs, and silent data loss turn a building integration into a long-running engineering problem. I inherited a building controls integration problem 18 months ago. Three office floors. 217 BACnet sensors covering temperature, occupancy, and HVAC actuators. The data was trapped inside the building automation network while the business wanted analytics, reporting, and compliance visibility in the data platform. The obvious answer looked easy enough: deploy bacnet2mqtt, bridge BACnet into MQTT, and push the stream into the lakehouse stack. The repository made it sound like a w...

Connect BACnet to the Cloud with bacnet-mqtt-gateway

The bacnet-mqtt-gateway project is an open source protocol bridge that translates BACnet building automation traffic into MQTT messages for cloud and IoT systems. It provides discovery, polling, bidirectional writes, APIs, security, and easy deployment via Docker. Many enterprises struggle to unify BACnet with modern data pipelines and cloud platforms because BACnet is local-network only and not cloud ready. This gateway provides a scalable, secure, production-ready adapter for MQTT ecosystems and smart building integrations. The Problem with BACnet Building automation runs on BACnet . HVAC controllers, lighting systems, metering equipment: they all speak ASHRAE 135 . The protocol handles local control loops well. It fails at cloud ingress. BACnet relies on UDP broadcasts. These do not route over the internet or into VPCs. Your chiller controller cannot talk to AWS IoT Core . Your VAV box cannot publish to an MQTT broker. The air gap between operational technology and modern cl...