check / check (push) Waiting to run
rtnetmon had no version. main.Version is now set at link time and logged in the first startup line. `make build` and `make dev` set it from `git describe --tags --always` unless VERSION is given. The Dockerfile takes it from the VERSION build argument when one is given, otherwise from `git describe --tags --always` of the .git the build context now carries, and fails the build if the context carries .git and no version comes out. .dockerignore follows the canonical copy: .git is sent, .git/config, which can hold a credential, is not. Model: opus-5-5
52 lines
2.5 KiB
Docker
52 lines
2.5 KiB
Docker
# Lint phase. golangci-lint runs here, in the pinned linter image, never on
|
|
# the host. script/lint builds this stage by name with --no-cache.
|
|
# golangci/golangci-lint:v2.12.2, 2026-05-06
|
|
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN golangci-lint config verify --config .golangci.yml
|
|
RUN golangci-lint run --config .golangci.yml ./...
|
|
|
|
# Test phase. script/test builds this stage by name with --no-cache.
|
|
# golang:1.26.1-bookworm, 2026-03-17
|
|
FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a3492282a6c820bf4755fd64a4 AS test
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN go test -count=1 -race -cover -timeout 90s ./... || \
|
|
{ echo "--- Rerunning with -v for details ---"; \
|
|
go test -count=1 -race -v -timeout 90s ./...; exit 1; }
|
|
|
|
# Build stage, and the last one. Nothing is wanted from the phases above;
|
|
# the two copies are the ordering edges that make BuildKit build them first,
|
|
# so this stage cannot build unless lint and test passed. For this
|
|
# non-server tool the final stage is the build/development environment
|
|
# carrying the compiled binary; rtnetmon runs on a host with the privileges
|
|
# to open raw ICMP sockets, not as a container service.
|
|
# golang:1.26.1-bookworm, 2026-03-17
|
|
FROM golang:1.26.1-bookworm@sha256:4465644228bc2857a954b092167e12aa59c006a3492282a6c820bf4755fd64a4 AS builder
|
|
COPY --from=lint /src/go.sum /dev/null
|
|
COPY --from=test /src/go.sum /dev/null
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
# The version stamped into the binary: the VERSION build argument when one
|
|
# is given, otherwise `git describe --tags --always` of the .git the build
|
|
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
|
|
# one, the short commit when no tag is reachable. git ships in this base
|
|
# image. A context that carries .git and still yields no version fails the
|
|
# build. With neither, as from a source tarball, the binary reports dev.
|
|
ARG VERSION
|
|
RUN version="${VERSION:-$(git describe --tags --always)}"; \
|
|
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
|
[ "$version" = unknown ]; }; then \
|
|
echo "no version could be derived although the build context carries .git" >&2; \
|
|
exit 1; \
|
|
fi; \
|
|
CGO_ENABLED=0 go build -trimpath -ldflags="-X main.Version=${version:-dev}" \
|
|
-o /rtnetmon ./cmd/rtnetmon/
|