build: Dockerfile.backend multistage lint stage (closes #17)
All checks were successful
check / check (push) Successful in 16s

Dockerfile.backend did not follow the Go multistage lint-stage pattern
REPO_POLICIES.md mandates, and dragged the whole git history into the
build context to resolve a version string.

- Add an `AS lint` stage on the hash-pinned golangci/golangci-lint
  image (v2.7.2, the same golangci-lint commit main already pins), which
  ships Go, gofmt, make and the linter, so nothing is installed in it.
  It runs `make fmt-check` then `make lint`.
- Add `COPY --from=lint /src/go.sum /dev/null` to the build stage so
  BuildKit cannot run the two stages in parallel and let a lint failure
  through.
- Stop compiling golangci-lint from source in the build stage.
- Drop `COPY .git /repo/.git`; the version now comes from
  `ARG VERSION=dev`, passed to the build via `make build VERSION=...`.
- Drop gcc and musl-dev, and the corresponding
  `-linkmode external -extldflags -static` in backend/Makefile. The
  build is now `CGO_ENABLED=0 go build -trimpath` with
  `-ldflags "-s -w -X main.Version=... -X main.Buildarch=..."`, which is
  static without a C toolchain.
- backend/Makefile's VERSION is now overridable and degrades to `dev`
  when git or .git is unavailable instead of emitting a git error and
  building an empty version string.
- Every FROM stays pinned by @sha256 with a version and date comment.

Runtime stage, exposed port and entrypoint are unchanged.
This commit is contained in:
2026-08-09 10:09:32 +00:00
parent fbfe1df349
commit bd2bc9f626
3 changed files with 46 additions and 20 deletions

View File

@@ -22,6 +22,10 @@ files, so merging it also closes most compliance gaps.
# Completed Steps
- 2026-08-09: `Dockerfile.backend` reworked to the mandated Go multistage
lint-stage pattern: separate `lint` stage on the hash-pinned
`golangci/golangci-lint` image, `COPY --from=lint` stage dependency,
`CGO_ENABLED=0` static build driven by `ARG VERSION`, and no more `COPY .git`
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints, Makefile
shims, README Entrypoints section
- 2026-02-27: backend with buffered zstd-compressed report storage; CI workflow