Build a static binary so the scratch image runs (closes #126)
check / check (push) Waiting to run

The final stage is scratch, which has no C library, but the builder
compiled mfer with cgo on (the golang image's default). google/uuid
imports net, so the binary came out dynamically linked and the image
could not start. The image's go build now sets CGO_ENABLED=0; nothing
in mfer needs cgo. A new builder step runs ldd on the binary and fails
the build unless it reports a static executable.

Model: opus-5-5
This commit is contained in:
2026-10-04 04:38:13 +00:00
parent a2732cf8da
commit c45310dc9e
+4 -1
View File
@@ -67,7 +67,10 @@ RUN version="${VERSION:-$(git describe --tags --always)}"; \
exit 1; \ exit 1; \
fi; \ fi; \
cd cmd/mfer && \ cd cmd/mfer && \
go build -tags urfave_cli_no_docs -ldflags "-X main.Gitrev=$version" -o /mfer . CGO_ENABLED=0 go build -tags urfave_cli_no_docs -ldflags "-X main.Gitrev=$version" -o /mfer .
# Fail unless /mfer is statically linked: scratch has no C library to run it.
RUN ldd /mfer 2>&1 | grep -q 'not a dynamic executable'
FROM scratch FROM scratch
COPY --from=builder /mfer /mfer COPY --from=builder /mfer /mfer