The builder's manifest with one change that matters: it claims node-build-agent, a node seat, so it is assignable to every machine with a container runtime, and every holder pulls one build at a time from the role's one work queue. A tier of many images is then built by as many machines as hold the seat and are online. The builder module stays until this is assigned where it was; then it goes.
26 lines
1.3 KiB
Docker
26 lines
1.3 KiB
Docker
ARG GO_BASE
|
|
ARG ALPINE_BASE
|
|
# build-agent's image: the build machine itself, compiled into a container (novox/hq ADR 0190).
|
|
#
|
|
# **The source is not vendored here.** builder's actual code — cmd/mesh-builder, internal/builder,
|
|
# internal/catalogue — lives in the mesh-controller repository, the same control plane it is one
|
|
# half of. This module ships the packaging, not a second copy of the source, so the build context
|
|
# is the mesh-controller repository root (declared under build.artifacts[].context), and this
|
|
# Dockerfile compiles ./cmd/mesh-builder from it — the same shape route-proxy already uses for the
|
|
# same reason.
|
|
FROM ${GO_BASE} AS build
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-builder ./cmd/mesh-builder
|
|
|
|
# Unlike mesh-controller's own FROM scratch (ADR 0006: nothing to audit but one binary), the build
|
|
# machine's whole job is shelling out to git and docker — it needs a real userland to do that in,
|
|
# not a second copy of either tool vendored into this image. apk installs both from the base's own
|
|
# packages, not fetched on its own at build time.
|
|
FROM ${ALPINE_BASE}
|
|
RUN apk add --no-cache docker-cli git
|
|
COPY --from=build /mesh-builder /usr/local/bin/mesh-builder
|
|
ENTRYPOINT ["/usr/local/bin/mesh-builder"]
|