# Build stage # # Context is the repository root. # # The command stays named vantagectl even though the repository is vantage-ctl: # it is what an operator types, and it is in every runbook. Only the paths moved. # # vantage-shared is a private module, so both steps below need a credential. It # arrives as a BuildKit secret rather than a build arg, which would be baked # into this stage's layer history. FROM golang:1.26 AS builder WORKDIR /src ENV GOPRIVATE=gitea.hostxtra.co.uk/* # Manifests first so the dependency layer caches independently of source edits. COPY go.mod go.sum ./ RUN --mount=type=secret,id=netrc,target=/root/.netrc \ go mod download COPY . . ARG VERSION=dev RUN --mount=type=secret,id=netrc,target=/root/.netrc \ CGO_ENABLED=0 GOOS=linux go build \ -ldflags="-s -w -X main.Version=${VERSION}" -o /vantagectl . # Staged so the scratch image below can have a /tmp. It cannot mkdir one # itself - scratch has no shell. RUN mkdir -p /staging/tmp && chmod 1777 /staging/tmp # Runtime stage FROM scratch COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ # restore extracts an archive here before verifying its checksums, and backup # stages nothing but still inherits os.MkdirTemp's requirements. Without this # every restore stops at "temp dir: stat /tmp: no such file or directory". COPY --from=builder /staging/tmp /tmp COPY --from=builder /vantagectl /vantagectl ENTRYPOINT ["/vantagectl"]