# Build stage # # Context is the repository root, not server/, because server depends on the # shared module through a replace directive. FROM golang:1.26 AS builder WORKDIR /src # Manifests first so the dependency layer caches independently of source edits. COPY shared/go.mod shared/go.sum ./shared/ COPY server/go.mod server/go.sum ./server/ RUN cd server && go mod download COPY shared/ ./shared/ COPY server/ ./server/ ARG VERSION=dev RUN cd server && CGO_ENABLED=0 GOOS=linux go build \ -ldflags="-s -w -X main.Version=${VERSION}" -o /vantage-server ./cmd # Staged so the scratch image below can have a /tmp. It cannot mkdir one # itself — scratch has no shell — and os.MkdirTemp fails outright without it. RUN mkdir -p /staging/tmp && chmod 1777 /staging/tmp # Runtime stage FROM scratch COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ # vulndb unpacks the ~50MB trivy-db here. Without it the scheduler stops at # "temp dir: stat /tmp: no such file or directory" and no scanning happens, # while everything else in the process runs perfectly well. COPY --from=builder /staging/tmp /tmp COPY --from=builder /vantage-server /vantage-server COPY default_steps/ /opt/default-steps/ ENV VANTAGE_DEFAULT_STEPS_DIR=/opt/default-steps EXPOSE 8080 9090 ENTRYPOINT ["/vantage-server"]