shared/ is extracted to gitea.hostxtra.co.uk/vantage/vantage-shared and pinned at v0.1.0 by server, agent, admin, sitesvc and vantagectl. The replace directives and the ./shared entry in go.work are gone. Every Go build now needs a credential for the private module: CI writes a netrc per job from REGISTRY_USER + RELEASE_TOKEN and sets GOPRIVATE, and the four Go Dockerfiles take it as a BuildKit secret rather than a build arg, which would survive in the builder layer's history. RELEASE_TOKEN needs read access to the vantage org. admin, sitesvc and vantagectl now build from their own directory; only server still needs the repository root, for default_steps/. The rebuild triggers in server-deploy.yml lose their shared/ patterns, since a service now moves when its own go.mod pin does.
48 lines
1.6 KiB
Docker
48 lines
1.6 KiB
Docker
# Build stage
|
|
#
|
|
# Context is still the repository root, not server/, because the runtime stage
|
|
# copies default_steps/ from it.
|
|
#
|
|
# vantage-shared is a private module, so every step that resolves it needs a
|
|
# credential. It arrives as a BuildKit secret rather than a build arg: an arg
|
|
# is baked into the builder layer's history, and this one is a Gitea token.
|
|
FROM golang:1.26 AS builder
|
|
|
|
WORKDIR /src
|
|
|
|
ENV GOPRIVATE=gitea.hostxtra.co.uk/*
|
|
|
|
# Manifests first so the dependency layer caches independently of source edits.
|
|
COPY server/go.mod server/go.sum ./server/
|
|
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
|
|
cd server && go mod download
|
|
|
|
COPY server/ ./server/
|
|
|
|
ARG VERSION=dev
|
|
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
|
|
cd server && CGO_ENABLED=0 GOOS=linux go build \
|
|
-ldflags="-s -w -X main.Version=${VERSION}" -o /vantage-server ./cmd
|
|
|
|
# Staged so the scratch image below can have a /tmp. It cannot mkdir one
|
|
# itself — scratch has no shell — and os.MkdirTemp fails outright without it.
|
|
RUN mkdir -p /staging/tmp && chmod 1777 /staging/tmp
|
|
|
|
# Runtime stage
|
|
FROM scratch
|
|
|
|
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
|
|
|
|
# vulndb unpacks the ~50MB trivy-db here. Without it the scheduler stops at
|
|
# "temp dir: stat /tmp: no such file or directory" and no scanning happens,
|
|
# while everything else in the process runs perfectly well.
|
|
COPY --from=builder /staging/tmp /tmp
|
|
COPY --from=builder /vantage-server /vantage-server
|
|
|
|
COPY default_steps/ /opt/default-steps/
|
|
ENV VANTAGE_DEFAULT_STEPS_DIR=/opt/default-steps
|
|
|
|
EXPOSE 8080 9090
|
|
|
|
ENTRYPOINT ["/vantage-server"]
|