# Build stage # golang 1.25-alpine, 2026-02-28 FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder RUN apk add --no-cache git make gcc musl-dev binutils-gold # golangci-lint v2.12.2, 2026-08-07 RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5 # goimports v0.42.0 RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0 WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . # Run all checks - build fails if any check fails. # # CHECK_EPOCH is a cache-busting build argument. Without it, an # unchanged tree leaves this layer's cache key identical and Docker # serves the previous verdict instead of re-running the suite, so the # build reports a green it did not earn. A build argument's value # participates in the cache key of later instructions in the stage even # when they do not reference it, so a fresh value busts this layer # either way. It is expanded into the command deliberately: that makes # the invalidation a property of the command string itself rather than # of how a given builder treats unreferenced args, and it surfaces the # epoch in the build log as a diagnostic. # # Placing the ARG here and nowhere earlier keeps everything above it # (toolchain install, go mod download) cached, so only the check and the # steps after it re-run. script/cibuild passes a fresh value per run; a # plain `docker build` without it caches as before. ARG CHECK_EPOCH RUN echo "check epoch: ${CHECK_EPOCH}" && make check # Build the binary RUN make build # Runtime stage # alpine 3.21, 2026-02-28 FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709 RUN apk add --no-cache ca-certificates tzdata WORKDIR /app COPY --from=builder /src/bin/dnswatcher /app/dnswatcher # Create data directory RUN mkdir -p /var/lib/dnswatcher ENV DNSWATCHER_DATA_DIR=/var/lib/dnswatcher EXPOSE 8080 ENTRYPOINT ["/app/dnswatcher"]