# The route-proxy module's runtime image: the reference reverse proxy compiled into a container. # # **The proxy source is not vendored here.** The canonical proxy โ€” the contract written as something # that runs โ€” lives in the mesh-control repository at examples/route-proxy (novox/hq 08-connectivity # ยง3). This module ships the *packaging*, not a second copy of the contract, so the build context is # the mesh-control repository root, and this Dockerfile compiles ./examples/route-proxy from it. # # docker build -f mesh-catalog/modules/route-proxy/Dockerfile \ # -t mesh-route-proxy:development /mesh-control # # The mesh pins the digest of what this produces; the committed module.json carries the placeholder # digest every mesh-built image does, replaced at publish. FROM golang:1.25 AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-route-proxy ./examples/route-proxy # A small runtime with the public CA roots the ACME client needs to reach a real authority, and run # as root so it can bind :80 and :443 โ€” the two privileged ports a public front door listens on. FROM alpine:3.20 RUN apk add --no-cache ca-certificates COPY --from=build /mesh-route-proxy /usr/local/bin/mesh-route-proxy ENTRYPOINT ["/usr/local/bin/mesh-route-proxy"]