Adds a golangci-lint lint stage that runs make fmt-check and make lint,
and runs make test in the build stage, so the container build fails when
formatting, lint, or any test fails. The build stage waits for the lint
stage via COPY --from=lint /src/go.sum /dev/null.
Pins the base images by digest (golang:1.24-bookworm, debian:bookworm-slim)
and the new lint image (golangci/golangci-lint:v2.7.2, Go 1.25.5) with
version and date comments; versions are unchanged. The final image content
and entrypoint are unchanged.
Model: opus-4-8
Use runuser to drop privileges and execute the app as the routewatch
user (uid 1000). Fix data directory permissions at runtime since host
mounts may have incorrect ownership.
- Builder stage: vendor dependencies, build binary, create source archive
- Source archive (.tar.zst) includes all code and vendored dependencies
- Runtime stage: minimal Debian image with binary and source archive
- Health check via curl to /.well-known/healthcheck.json
- Runs as non-root user (routewatch:1000)