# Lint stage — fast feedback on formatting and lint issues # golangci/golangci-lint:v2.12.2 (Debian-based), 2026-08-07 FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint WORKDIR /src COPY go.mod go.sum ./ RUN go mod download # script/cibuild sets CHECK_EPOCH to the current time, so every step below # runs again on each build, an unchanged tree included, while the steps # above stay cached. ARG is per stage: the build stage declares it too. ARG CHECK_EPOCH COPY . . RUN make fmt-check # Not make lint: script/lint is a docker build, which cannot run in here. RUN golangci-lint run --config .golangci.yml ./... # Build stage — tests and compilation # golang 1.24.13-alpine (2026-03-10) FROM golang@sha256:8bee1901f1e530bfb4a7850aa7a479d17ae3a18beb6e09064ed54cfd245b7191 AS builder # Force BuildKit to run the lint stage COPY --from=lint /src/go.sum /dev/null RUN apk add --no-cache gcc musl-dev make git gnupg WORKDIR /build COPY go.mod go.sum ./ RUN go mod download # As in the lint stage: the steps below run again on each script/cibuild. ARG CHECK_EPOCH COPY . . RUN make test # The version stamped into the binary: the VERSION build argument when one # is given, otherwise `git describe --tags --always` of the .git the build # context carries: the tag on a tagged commit, tag-N-gHASH on a commit after # one, the short commit when no tag is reachable. A context that carries .git # and still yields no version fails the build. ARG VERSION RUN version="${VERSION:-$(git describe --tags --always)}"; \ if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \ [ "$version" = unknown ]; }; then \ echo "no version could be derived although the build context carries .git" >&2; \ exit 1; \ fi; \ make build VERSION="${version:-dev}" # Runtime stage # alpine 3.23 (2026-03-10) FROM alpine@sha256:25109184c71bdad752c8312a8623239686a9a2071e8825f20acb8f2198c3f659 RUN apk add --no-cache ca-certificates gnupg RUN adduser -D -s /bin/sh secret COPY --from=builder /build/secret /usr/local/bin/secret RUN chmod +x /usr/local/bin/secret USER secret WORKDIR /home/secret ENTRYPOINT ["secret"]