From 8da72222fe1253ea782d07e13bfa4d70ab1af859 Mon Sep 17 00:00:00 2001 From: jochens Date: Fri, 2 Oct 2026 15:38:29 +0200 Subject: [PATCH] The example images build from the Go the manifest pins Four example Dockerfiles named golang:1.25 while go.mod requires 1.26; the control plane's image takes GO_BASE from the manifest and these did not, so a build that could not fetch a newer toolchain failed at go mod download (found running the lab through the mesh). --- Makefile | 8 ++++---- examples/objectstore-provisioner/Dockerfile | 5 ++++- examples/postgres-provisioner/Dockerfile | 5 ++++- examples/redis-provisioner/Dockerfile | 5 ++++- examples/route-proxy/Dockerfile | 5 ++++- 5 files changed, 20 insertions(+), 8 deletions(-) diff --git a/Makefile b/Makefile index 7f50f12..9395e5d 100644 --- a/Makefile +++ b/Makefile @@ -59,7 +59,7 @@ PROVISIONER_IMAGE ?= mesh-provision-postgres:$(VERSION) PROVISIONER_DEV_TAG ?= mesh-provision-postgres:development provisioner-image: - docker build -f examples/postgres-provisioner/Dockerfile \ + docker build --build-arg GO_BASE=$(GO_BASE) -f examples/postgres-provisioner/Dockerfile \ -t $(PROVISIONER_IMAGE) -t $(PROVISIONER_DEV_TAG) . @echo @docker image inspect $(PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes' @@ -70,7 +70,7 @@ OBJECTSTORE_IMAGE ?= mesh-provision-objectstore:$(VERSION) OBJECTSTORE_DEV_TAG ?= mesh-provision-objectstore:development objectstore-image: - docker build -f examples/objectstore-provisioner/Dockerfile \ + docker build --build-arg GO_BASE=$(GO_BASE) -f examples/objectstore-provisioner/Dockerfile \ -t $(OBJECTSTORE_IMAGE) -t $(OBJECTSTORE_DEV_TAG) . @echo @docker image inspect $(OBJECTSTORE_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes' @@ -81,7 +81,7 @@ REDIS_PROVISIONER_IMAGE ?= mesh-provision-redis:$(VERSION) REDIS_PROVISIONER_DEV_TAG ?= mesh-provision-redis:development redis-provisioner-image: - docker build -f examples/redis-provisioner/Dockerfile \ + docker build --build-arg GO_BASE=$(GO_BASE) -f examples/redis-provisioner/Dockerfile \ -t $(REDIS_PROVISIONER_IMAGE) -t $(REDIS_PROVISIONER_DEV_TAG) . @echo @docker image inspect $(REDIS_PROVISIONER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes' @@ -91,7 +91,7 @@ PROXY_IMAGE ?= mesh-route-proxy:$(VERSION) PROXY_DEV_TAG ?= mesh-route-proxy:development proxy-image: - docker build -f examples/route-proxy/Dockerfile -t $(PROXY_IMAGE) -t $(PROXY_DEV_TAG) . + docker build --build-arg GO_BASE=$(GO_BASE) -f examples/route-proxy/Dockerfile -t $(PROXY_IMAGE) -t $(PROXY_DEV_TAG) . @echo @docker image inspect $(PROXY_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes' diff --git a/examples/objectstore-provisioner/Dockerfile b/examples/objectstore-provisioner/Dockerfile index 4976616..136a5f1 100644 --- a/examples/objectstore-provisioner/Dockerfile +++ b/examples/objectstore-provisioner/Dockerfile @@ -10,7 +10,10 @@ # The client is copied from the vendor's own image rather than installed from a distribution: # `apk add mc` on Alpine installs Midnight Commander, which is a different program with the same # name, and the failure would be a provisioner that starts cleanly and cannot do anything. -FROM golang:1.25-alpine AS build +# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the +# build machine alike; the default only serves a hand build, and matches go.mod. +ARG GO_BASE=golang:1.26-alpine +FROM ${GO_BASE} AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download diff --git a/examples/postgres-provisioner/Dockerfile b/examples/postgres-provisioner/Dockerfile index 54562b5..585cf08 100644 --- a/examples/postgres-provisioner/Dockerfile +++ b/examples/postgres-provisioner/Dockerfile @@ -3,7 +3,10 @@ # Built here so a machine can be given it by the mesh rather than by somebody putting a binary on # it. Static and FROM scratch for the same reason the control plane's image is: it is fetched by # digest and run on a machine, and everything in it is something a person would have to audit. -FROM golang:1.25-alpine AS build +# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the +# build machine alike; the default only serves a hand build, and matches go.mod. +ARG GO_BASE=golang:1.26-alpine +FROM ${GO_BASE} AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download diff --git a/examples/redis-provisioner/Dockerfile b/examples/redis-provisioner/Dockerfile index 7a3b678..ade39a7 100644 --- a/examples/redis-provisioner/Dockerfile +++ b/examples/redis-provisioner/Dockerfile @@ -2,7 +2,10 @@ # # FROM scratch, like the postgres one and unlike the bucket one: it speaks the store's own wire # protocol directly and needs no client in the image. -FROM golang:1.25-alpine AS build +# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the +# build machine alike; the default only serves a hand build, and matches go.mod. +ARG GO_BASE=golang:1.26-alpine +FROM ${GO_BASE} AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download diff --git a/examples/route-proxy/Dockerfile b/examples/route-proxy/Dockerfile index c807c3d..1c03627 100644 --- a/examples/route-proxy/Dockerfile +++ b/examples/route-proxy/Dockerfile @@ -2,7 +2,10 @@ # # Static and FROM scratch like the control plane's image, and for the same reason: it is fetched # by digest and run on a machine, so everything in it is something a person would have to audit. -FROM golang:1.25-alpine AS build +# The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the +# build machine alike; the default only serves a hand build, and matches go.mod. +ARG GO_BASE=golang:1.26-alpine +FROM ${GO_BASE} AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download