# Lint stage — fast feedback on formatting and lint issues # golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07 FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . # Touch .pb.go so make does not try to regenerate via protoc (file is committed) RUN touch mfer/mf.pb.go # Go half of fmt-check only: this image has no node, so no prettier. The # markdown half runs in the mdfmt stage below. RUN make fmt-check-go RUN make lint # Markdown/JSON format stage — prettier needs node, which the Go images # do not have. node:22.17.0-bookworm-slim (2026-08-09); ships node # 22.17.0 and yarn 1.22.22, the versions script/bootstrap pins. FROM node@sha256:b04ce4ae4e95b522112c2e5c52f781471a5cbc3b594527bcddedee9bc48c03a0 AS mdfmt WORKDIR /src COPY package.json yarn.lock ./ RUN yarn install --frozen-lockfile COPY . . # No make in this image; call the script entrypoint directly. RUN script/prettier --check # Build stage — tests and compilation # golang:1.23 (2026-03-14) FROM golang@sha256:60deed95d3888cc5e4d9ff8a10c54e5edc008c6ae3fba6187be6fb592e19e8c0 AS builder # Force BuildKit to run the lint and mdfmt stages by creating stage dependencies COPY --from=lint /src/go.sum /dev/null COPY --from=mdfmt /src/go.sum /dev/null WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . # Touch .pb.go so make does not try to regenerate via protoc (file is committed) RUN touch mfer/mf.pb.go RUN make test # A build context sent as a tar archive, as upaas sends it, keeps its files' # owners, and git refuses to read a checkout owned by another user. RUN git config --system --add safe.directory /src # The revision `mfer version` prints, stamped into main.Gitrev: the VERSION # build argument when one is given (script/docker passes one), otherwise # `git describe --tags --always` of the .git the build context carries: the # tag on a tagged commit, tag-N-gHASH on a commit after one, the short commit # when no tag is reachable. git ships in this base image. A context that # carries .git and still yields no version fails the build. ARG VERSION RUN version="${VERSION:-$(git describe --tags --always)}"; \ if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \ [ "$version" = unknown ]; }; then \ echo "no version could be derived although the build context carries .git" >&2; \ exit 1; \ fi; \ cd cmd/mfer && \ go build -tags urfave_cli_no_docs -ldflags "-X main.Gitrev=$version" -o /mfer . FROM scratch COPY --from=builder /mfer /mfer ENTRYPOINT ["/mfer"]