From c9471f73ba9bd1d6bbdc4d5a9bcf46d7a2cedb20 Mon Sep 17 00:00:00 2001 From: mrhid6 Date: Tue, 8 Sep 2026 07:42:58 +0000 Subject: [PATCH] refactor: consume vantage-shared as an external private module shared/ is extracted to gitea.hostxtra.co.uk/vantage/vantage-shared and pinned at v0.1.0 by server, agent, admin, sitesvc and vantagectl. The replace directives and the ./shared entry in go.work are gone. Every Go build now needs a credential for the private module: CI writes a netrc per job from REGISTRY_USER + RELEASE_TOKEN and sets GOPRIVATE, and the four Go Dockerfiles take it as a BuildKit secret rather than a build arg, which would survive in the builder layer's history. RELEASE_TOKEN needs read access to the vantage org. admin, sitesvc and vantagectl now build from their own directory; only server still needs the repository root, for default_steps/. The rebuild triggers in server-deploy.yml lose their shared/ patterns, since a service now moves when its own go.mod pin does. --- .dockerignore | 5 +++++ Dockerfile | 23 ++++++++++++++--------- go.mod | 4 +--- go.sum | 2 ++ 4 files changed, 22 insertions(+), 12 deletions(-) create mode 100644 .dockerignore diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..7de6554 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,5 @@ +# The build context is this directory now, so local build output would +# otherwise be shipped into the builder stage on every build. +dist +.env +*.lic diff --git a/Dockerfile b/Dockerfile index 437c1ad..c17e5cb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,21 +1,26 @@ # Build stage # -# Context is the repository root, not vantagectl/, because vantagectl depends on -# the shared module through a replace directive. +# Context is vantagectl/ itself. It used to be the repository root, so that +# shared/ could be copied in beside it; shared is now the private module +# gitea.hostxtra.co.uk/vantage/vantage-shared, fetched like any other +# dependency. The credential for it arrives as a BuildKit secret rather than a +# build arg, which would be baked into this stage's layer history. FROM golang:1.26 AS builder WORKDIR /src -# Manifests first so the dependency layer caches independently of source edits. -COPY shared/go.mod shared/go.sum ./shared/ -COPY vantagectl/go.mod vantagectl/go.sum ./vantagectl/ -RUN cd vantagectl && go mod download +ENV GOPRIVATE=gitea.hostxtra.co.uk/* -COPY shared/ ./shared/ -COPY vantagectl/ ./vantagectl/ +# Manifests first so the dependency layer caches independently of source edits. +COPY go.mod go.sum ./ +RUN --mount=type=secret,id=netrc,target=/root/.netrc \ + go mod download + +COPY . . ARG VERSION=dev -RUN cd vantagectl && CGO_ENABLED=0 GOOS=linux go build \ +RUN --mount=type=secret,id=netrc,target=/root/.netrc \ + CGO_ENABLED=0 GOOS=linux go build \ -ldflags="-s -w -X main.Version=${VERSION}" -o /vantagectl . # Staged so the scratch image below can have a /tmp. It cannot mkdir one diff --git a/go.mod b/go.mod index 3269aa8..52ebce7 100644 --- a/go.mod +++ b/go.mod @@ -2,10 +2,8 @@ module gitea.hostxtra.co.uk/mrhid6/vantage/vantagectl go 1.26 -replace gitea.hostxtra.co.uk/vantage/vantage-shared => ../shared - require ( - gitea.hostxtra.co.uk/vantage/vantage-shared v0.0.0-00010101000000-000000000000 + gitea.hostxtra.co.uk/vantage/vantage-shared v0.1.0 github.com/spf13/cobra v1.10.2 go.mongodb.org/mongo-driver/v2 v2.8.0 golang.org/x/term v0.45.0 diff --git a/go.sum b/go.sum index 258b7c5..880b1a5 100644 --- a/go.sum +++ b/go.sum @@ -1,3 +1,5 @@ +gitea.hostxtra.co.uk/vantage/vantage-shared v0.1.0 h1:H6PCb8JHucrRiqPe9kGOhXUjBD66tKFHCP3qz5TjdZc= +gitea.hostxtra.co.uk/vantage/vantage-shared v0.1.0/go.mod h1:dWjeOFLltQ8sv9Pnn1xRxGfWGgqa2fkG0esuaJLoPXQ= github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g= github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c= github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=