From d757d089ccb7f6af7f42e57f897e772c56f86df0 Mon Sep 17 00:00:00 2001 From: mrhid6 Date: Mon, 7 Sep 2026 14:09:00 +0000 Subject: [PATCH] feat: Build and publish vantagectl The scratch runtime stage copies an explicit /tmp: restore extracts an archive there before verifying it, and a scratch image has none. shared/ now fans out to four Go images rather than three. --- Dockerfile | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 Dockerfile diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..437c1ad --- /dev/null +++ b/Dockerfile @@ -0,0 +1,36 @@ +# Build stage +# +# Context is the repository root, not vantagectl/, because vantagectl depends on +# the shared module through a replace directive. +FROM golang:1.26 AS builder + +WORKDIR /src + +# Manifests first so the dependency layer caches independently of source edits. +COPY shared/go.mod shared/go.sum ./shared/ +COPY vantagectl/go.mod vantagectl/go.sum ./vantagectl/ +RUN cd vantagectl && go mod download + +COPY shared/ ./shared/ +COPY vantagectl/ ./vantagectl/ + +ARG VERSION=dev +RUN cd vantagectl && CGO_ENABLED=0 GOOS=linux go build \ + -ldflags="-s -w -X main.Version=${VERSION}" -o /vantagectl . + +# Staged so the scratch image below can have a /tmp. It cannot mkdir one +# itself — scratch has no shell. +RUN mkdir -p /staging/tmp && chmod 1777 /staging/tmp + +# Runtime stage +FROM scratch + +COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ + +# restore extracts an archive here before verifying its checksums, and backup +# stages nothing but still inherits os.MkdirTemp's requirements. Without this +# every restore stops at "temp dir: stat /tmp: no such file or directory". +COPY --from=builder /staging/tmp /tmp +COPY --from=builder /vantagectl /vantagectl + +ENTRYPOINT ["/vantagectl"]