check / check (push) Waiting to run
The final stage is scratch, which has no CA certificates, so fetch from an HTTPS URL failed to verify any server. Copy the CA bundle from the pinned builder image into the final stage. Model: opus-5-5
80 lines
2.9 KiB
Docker
80 lines
2.9 KiB
Docker
# Lint stage — fast feedback on formatting and lint issues
|
|
# golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07
|
|
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
|
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
|
|
# Touch .pb.go so make does not try to regenerate via protoc (file is committed)
|
|
RUN touch mfer/mf.pb.go
|
|
|
|
# Go half of fmt-check only: this image has no node, so no prettier. The
|
|
# markdown half runs in the mdfmt stage below.
|
|
RUN make fmt-check-go
|
|
RUN make lint
|
|
|
|
# Markdown/JSON format stage — prettier needs node, which the Go images
|
|
# do not have. node:22.17.0-bookworm-slim (2026-08-09); ships node
|
|
# 22.17.0 and yarn 1.22.22, the versions script/bootstrap pins.
|
|
FROM node@sha256:b04ce4ae4e95b522112c2e5c52f781471a5cbc3b594527bcddedee9bc48c03a0 AS mdfmt
|
|
|
|
WORKDIR /src
|
|
COPY package.json yarn.lock ./
|
|
RUN yarn install --frozen-lockfile
|
|
|
|
COPY . .
|
|
|
|
# No make in this image; call the script entrypoint directly.
|
|
RUN script/prettier --check
|
|
|
|
# Build stage — tests and compilation
|
|
# golang:1.23 (2026-03-14)
|
|
FROM golang@sha256:60deed95d3888cc5e4d9ff8a10c54e5edc008c6ae3fba6187be6fb592e19e8c0 AS builder
|
|
|
|
# Force BuildKit to run the lint and mdfmt stages by creating stage dependencies
|
|
COPY --from=lint /src/go.sum /dev/null
|
|
COPY --from=mdfmt /src/go.sum /dev/null
|
|
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
|
|
# Touch .pb.go so make does not try to regenerate via protoc (file is committed)
|
|
RUN touch mfer/mf.pb.go
|
|
|
|
RUN make test
|
|
|
|
# A build context sent as a tar archive, as upaas sends it, keeps its files'
|
|
# owners, and git refuses to read a checkout owned by another user.
|
|
RUN git config --system --add safe.directory /src
|
|
|
|
# The revision `mfer version` prints, stamped into main.Gitrev: the VERSION
|
|
# build argument when one is given (script/docker passes one), otherwise
|
|
# `git describe --tags --always` of the .git the build context carries: the
|
|
# tag on a tagged commit, tag-N-gHASH on a commit after one, the short commit
|
|
# when no tag is reachable. git ships in this base image. A context that
|
|
# carries .git and still yields no version fails the build.
|
|
ARG VERSION
|
|
RUN version="${VERSION:-$(git describe --tags --always)}"; \
|
|
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
|
[ "$version" = unknown ]; }; then \
|
|
echo "no version could be derived although the build context carries .git" >&2; \
|
|
exit 1; \
|
|
fi; \
|
|
cd cmd/mfer && \
|
|
CGO_ENABLED=0 go build -tags urfave_cli_no_docs -ldflags "-X main.Gitrev=$version" -o /mfer .
|
|
|
|
# Fail unless /mfer is statically linked: scratch has no C library to run it.
|
|
RUN ldd /mfer 2>&1 | grep -q 'not a dynamic executable'
|
|
|
|
FROM scratch
|
|
# scratch has no CA certificates; fetch needs them to verify HTTPS servers.
|
|
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
|
|
COPY --from=builder /mfer /mfer
|
|
ENTRYPOINT ["/mfer"]
|