# Lint stage - fast feedback on lint issues, before the build starts. # The linter is invoked directly rather than through `make lint`: that # target shells out to `docker build -f Dockerfile.lint`, and there is # no docker daemon inside a docker build. # golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-10 FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . RUN make fmt-check RUN golangci-lint run --config .golangci.yml ./... # Build stage # golang 1.25-alpine, 2026-02-28 FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder RUN apk add --no-cache git make gcc musl-dev binutils-gold # Force BuildKit to run the lint stage before proceeding COPY --from=lint /src/go.sum /dev/null WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . # Run the tests - build fails if any test fails RUN make test # Build the binary RUN make build # Runtime stage # alpine 3.21, 2026-02-28 FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709 RUN apk add --no-cache ca-certificates tzdata COPY --from=builder /src/bin/dnswatcher /usr/local/bin/dnswatcher # Run as an unprivileged user that owns the data directory. A fresh named # volume inherits this ownership; a bind-mounted host directory must be # owned by uid 10001 (see "Running under upaas" in README.md), or startup # fails. RUN addgroup -S -g 10001 dnswatcher \ && adduser -S -G dnswatcher -u 10001 dnswatcher \ && mkdir -p /var/lib/dnswatcher \ && chown dnswatcher:dnswatcher /var/lib/dnswatcher ENV DNSWATCHER_DATA_DIR=/var/lib/dnswatcher # Config loading also reads a `.env` file and a file named `dnswatcher` # (any config extension, or none) from the working directory. `/` holds # neither, so every setting comes from the environment. Do not make the # data directory, or the binary's directory, the working directory. WORKDIR / USER dnswatcher EXPOSE 8080 # busybox wget (already in alpine) probes the health endpoint every 10 # seconds, so the container is healthy well before upaas reads its health # 60 seconds after a deploy and fails the deploy unless it is healthy. HEALTHCHECK --interval=10s --timeout=5s --start-period=10s --retries=3 \ CMD wget -q -O /dev/null "http://127.0.0.1:${PORT:-8080}/.well-known/healthcheck" || exit 1 ENTRYPOINT ["/usr/local/bin/dnswatcher"]