refactor: consume vantage-shared as an external private module
shared/ is extracted to gitea.hostxtra.co.uk/vantage/vantage-shared and pinned at v0.1.0 by server, agent, admin, sitesvc and vantagectl. The replace directives and the ./shared entry in go.work are gone. Every Go build now needs a credential for the private module: CI writes a netrc per job from REGISTRY_USER + RELEASE_TOKEN and sets GOPRIVATE, and the four Go Dockerfiles take it as a BuildKit secret rather than a build arg, which would survive in the builder layer's history. RELEASE_TOKEN needs read access to the vantage org. admin, sitesvc and vantagectl now build from their own directory; only server still needs the repository root, for default_steps/. The rebuild triggers in server-deploy.yml lose their shared/ patterns, since a service now moves when its own go.mod pin does.
This commit is contained in:
+14
-8
@@ -1,21 +1,27 @@
|
||||
# Build stage
|
||||
#
|
||||
# Context is the repository root, not server/, because server depends on the
|
||||
# shared module through a replace directive.
|
||||
# Context is still the repository root, not server/, because the runtime stage
|
||||
# copies default_steps/ from it.
|
||||
#
|
||||
# vantage-shared is a private module, so every step that resolves it needs a
|
||||
# credential. It arrives as a BuildKit secret rather than a build arg: an arg
|
||||
# is baked into the builder layer's history, and this one is a Gitea token.
|
||||
FROM golang:1.26 AS builder
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
# Manifests first so the dependency layer caches independently of source edits.
|
||||
COPY shared/go.mod shared/go.sum ./shared/
|
||||
COPY server/go.mod server/go.sum ./server/
|
||||
RUN cd server && go mod download
|
||||
ENV GOPRIVATE=gitea.hostxtra.co.uk/*
|
||||
|
||||
# Manifests first so the dependency layer caches independently of source edits.
|
||||
COPY server/go.mod server/go.sum ./server/
|
||||
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
|
||||
cd server && go mod download
|
||||
|
||||
COPY shared/ ./shared/
|
||||
COPY server/ ./server/
|
||||
|
||||
ARG VERSION=dev
|
||||
RUN cd server && CGO_ENABLED=0 GOOS=linux go build \
|
||||
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
|
||||
cd server && CGO_ENABLED=0 GOOS=linux go build \
|
||||
-ldflags="-s -w -X main.Version=${VERSION}" -o /vantage-server ./cmd
|
||||
|
||||
# Staged so the scratch image below can have a /tmp. It cannot mkdir one
|
||||
|
||||
Reference in New Issue
Block a user