-
Notifications
You must be signed in to change notification settings - Fork 3
Switch pipeline to build Go inside Dockerfile #27
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
10 commits
Select commit
Hold shift + click to select a range
3e0e48b
Replacing Containerfile with standard kubebuilder Dockerfile
fernando-villalba e46ec3c
rename Containerfile to Dockerfile
rcambrj 46731f2
Removing scan-codeql from needs
fernando-villalba be07532
Corrected unnecessary comment
fernando-villalba 5180363
Adding Dockerfile and removing intermediate image scanning for now
fernando-villalba be6a94b
reinstate comment about syncing intermediate image
rcambrj 9bf1ac0
switch back to more secure alpine
rcambrj 15b8573
dont build go outside of container
rcambrj 4b34466
use golang:alpine
rcambrj 15de4c1
approximate reproducible builds
rcambrj File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,35 @@ | ||
| # Git | ||
| .git | ||
| .gitignore | ||
|
|
||
| # Local development environment (Nix, direnv) | ||
| .direnv/ | ||
| result* | ||
| flake.nix | ||
| flake.lock | ||
| devshell.nix | ||
| .envrc* | ||
|
|
||
| # Build artifacts and local tools | ||
| bin/ | ||
| dist/ | ||
|
|
||
| # Test and linting artifacts | ||
| cover.out | ||
| cover.html | ||
| .golangci.toml | ||
| .testcoverage.yml | ||
|
|
||
| # CI/CD & Temporary files | ||
| Dockerfile.cross | ||
|
|
||
| # Documentation and planning | ||
| docs/ | ||
| plans/ | ||
| README.md | ||
| *.md | ||
|
|
||
| # Project and configuration files not needed for the build | ||
| Makefile | ||
| PROJECT | ||
| scripts/ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| # Containerfile for multigres-operator | ||
|
|
||
| # Github workflow step anchore/scan-action scans only the final image | ||
| # sync this intermediate FROM reference with: | ||
| # build-and-release.yaml => scan-intermediate-image | ||
| FROM golang:1.25.3-alpine3.22 AS builder | ||
|
|
||
| ARG TARGETOS | ||
| ARG TARGETARCH | ||
|
|
||
| WORKDIR /workspace | ||
| # Copy the Go Modules manifests | ||
| COPY go.mod go.mod | ||
| COPY go.sum go.sum | ||
| # cache deps before building and copying source so that we don't need to re-download as much | ||
| # and so that source changes don't invalidate our downloaded layer | ||
| RUN go mod download | ||
|
|
||
| # Copy the Go source (relies on .dockerignore to filter) | ||
| COPY . . | ||
|
|
||
| # Build | ||
| # the GOARCH has no default value to allow the binary to be built according to the host where the command | ||
| # was called. For example, if we call make docker-build in a local env which has the Apple Silicon M1 SO | ||
| # the docker BUILDPLATFORM arg will be linux/arm64 when for Apple x86 it will be linux/amd64. Therefore, | ||
| # by leaving it empty we can ensure that the container and binary shipped on it will have the same platform. | ||
| RUN CGO_ENABLED=0 \ | ||
| GOOS=${TARGETOS:-linux} \ | ||
| GOARCH=${TARGETARCH} \ | ||
| go build \ | ||
| -ldflags '-s -w -buildid=' \ | ||
| -trimpath -mod=readonly \ | ||
| -a -o manager \ | ||
| cmd/multigres-operator/main.go | ||
|
|
||
| # Use distroless as minimal base image to package the manager binary | ||
| # Refer to https://github.com/GoogleContainerTools/distroless for more details | ||
| FROM gcr.io/distroless/static:nonroot | ||
| WORKDIR / | ||
| COPY --from=builder /workspace/manager . | ||
| USER 65532:65532 | ||
|
|
||
| ENTRYPOINT ["/manager"] | ||
Empty file.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.