All checks were successful
check / check (push) Successful in 16s
Dockerfile.backend did not follow the Go multistage lint-stage pattern REPO_POLICIES.md mandates, and dragged the whole git history into the build context to resolve a version string. - Add an `AS lint` stage on the hash-pinned golangci/golangci-lint image (v2.7.2, the same golangci-lint commit main already pins), which ships Go, gofmt, make and the linter, so nothing is installed in it. It runs `make fmt-check` then `make lint`. - Add `COPY --from=lint /src/go.sum /dev/null` to the build stage so BuildKit cannot run the two stages in parallel and let a lint failure through. - Stop compiling golangci-lint from source in the build stage. - Drop `COPY .git /repo/.git`; the version now comes from `ARG VERSION=dev`, passed to the build via `make build VERSION=...`. - Drop gcc and musl-dev, and the corresponding `-linkmode external -extldflags -static` in backend/Makefile. The build is now `CGO_ENABLED=0 go build -trimpath` with `-ldflags "-s -w -X main.Version=... -X main.Buildarch=..."`, which is static without a C toolchain. - backend/Makefile's VERSION is now overridable and degrades to `dev` when git or .git is unavailable instead of emitting a git error and building an empty version string. - Every FROM stays pinned by @sha256 with a version and date comment. Runtime stage, exposed port and entrypoint are unchanged.
51 lines
1.2 KiB
Makefile
51 lines
1.2 KiB
Makefile
# VERSION is overridable (the Dockerfile passes its ARG VERSION in) and
|
|
# degrades to "dev" when git is unavailable or there is no .git — the
|
|
# build must not depend on the repository history being in the build
|
|
# context.
|
|
VERSION ?= $(shell { git describe --always --dirty; } 2>/dev/null || echo dev)
|
|
BUILDARCH := $(shell uname -m)
|
|
BINARY := netwatch-server
|
|
|
|
GOLDFLAGS += -s -w
|
|
GOLDFLAGS += -X main.Version=$(VERSION)
|
|
GOLDFLAGS += -X main.Buildarch=$(BUILDARCH)
|
|
|
|
.PHONY: all build test lint fmt fmt-check check docker hooks run clean
|
|
|
|
all: build
|
|
|
|
build:
|
|
CGO_ENABLED=0 go build -trimpath -ldflags "$(GOLDFLAGS)" \
|
|
-o ./$(BINARY) ./cmd/netwatch-server/
|
|
|
|
test:
|
|
timeout 30 go test ./...
|
|
|
|
lint:
|
|
golangci-lint run ./...
|
|
|
|
fmt:
|
|
go fmt ./...
|
|
|
|
fmt-check:
|
|
@test -z "$$(gofmt -l .)" || \
|
|
(echo "Files not formatted:"; gofmt -l .; exit 1)
|
|
|
|
check: test lint fmt-check
|
|
|
|
docker:
|
|
timeout 300 docker build -t netwatch-server -f ../Dockerfile.backend ..
|
|
|
|
hooks:
|
|
@printf '#!/bin/sh\ncd backend && make check\n' > \
|
|
$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
|
|
@chmod +x \
|
|
$$(git rev-parse --show-toplevel)/.git/hooks/pre-commit
|
|
@echo "Pre-commit hook installed"
|
|
|
|
run: build
|
|
./$(BINARY)
|
|
|
|
clean:
|
|
rm -f ./$(BINARY)
|