ARG GO_BASE ARG ALPINE_BASE # builder's own image: the build machine itself, compiled into a container. # # **The source is not vendored here.** builder's actual code — cmd/mesh-builder, internal/builder, # internal/catalogue — lives in the mesh-controller repository, the same control plane it is one # half of. This module ships the packaging, not a second copy of the source, so the build context # is the mesh-controller repository root (declared under build.artifacts[].context), and this # Dockerfile compiles ./cmd/mesh-builder from it — the same shape route-proxy already uses for the # same reason. FROM ${GO_BASE} AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-builder ./cmd/mesh-builder # Unlike mesh-controller's own FROM scratch (ADR 0006: nothing to audit but one binary), the build # machine's whole job is shelling out to git and docker — it needs a real userland to do that in, # not a second copy of either tool vendored into this image. apk installs both from the base's own # packages, not fetched on its own at build time. FROM ${ALPINE_BASE} RUN apk add --no-cache docker-cli git COPY --from=build /mesh-builder /usr/local/bin/mesh-builder ENTRYPOINT ["/usr/local/bin/mesh-builder"]