From bc317456073690c1f23a72c195eb5a15ca4ee604 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 29 Sep 2026 17:45:11 +0200 Subject: [PATCH] make image reads its base from the manifest It was broken and stayed broken: the Dockerfile's fallback base is a Go older than go.mod asks for, so every hand build died at 'go mod download' with 'go.mod requires go >= 1.26.0'. The pipeline never saw it because the pipeline passes the declared base in, so the cost fell entirely on whoever built the image themselves and had to find the digest by hand (novox/hq 04-ISSUES/146). Read from module.json rather than written here as well, so the two cannot disagree, and refused outright if the manifest declares none. --- Makefile | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/Makefile b/Makefile index a41e6d7..7f50f12 100644 --- a/Makefile +++ b/Makefile @@ -27,8 +27,18 @@ build: IMAGE ?= mesh-controller:$(VERSION) DEV_TAG ?= mesh-controller:development +# The base the module declares, read from the manifest rather than written here twice. +# +# **`make image` was broken and stayed broken**, because the Dockerfile's fallback base was a Go +# older than go.mod asks for: every build died at `go mod download` with "go.mod requires go >= +# 1.26.0", and the pipeline never saw it because the pipeline passes the declared base in. Anybody +# building the image by hand hit it and had to find the digest themselves (novox/hq 04-ISSUES/146, +# what it cost). +GO_BASE ?= $(shell python3 -c "import json;print(next(o['image'] for o in json.load(open('module.json'))['build']['on'] if o['arg']=='GO_BASE'))" 2>/dev/null) + image: - docker build --build-arg VERSION=$(VERSION) -t $(IMAGE) -t $(DEV_TAG) . + @test -n "$(GO_BASE)" || { echo "module.json declares no GO_BASE; pass GO_BASE= or fix the manifest"; exit 1; } + docker build --build-arg GO_BASE=$(GO_BASE) --build-arg VERSION=$(VERSION) -t $(IMAGE) -t $(DEV_TAG) . @echo @docker image inspect $(IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes' @@ -38,7 +48,8 @@ BUILDER_IMAGE ?= mesh-builder:$(VERSION) BUILDER_DEV_TAG ?= mesh-builder:development builder-image: - docker build -f cmd/mesh-builder/Dockerfile -t $(BUILDER_IMAGE) -t $(BUILDER_DEV_TAG) . + @test -n "$(GO_BASE)" || { echo "module.json declares no GO_BASE; pass GO_BASE= or fix the manifest"; exit 1; } + docker build --build-arg GO_BASE=$(GO_BASE) -f cmd/mesh-builder/Dockerfile -t $(BUILDER_IMAGE) -t $(BUILDER_DEV_TAG) . @echo @docker image inspect $(BUILDER_IMAGE) --format 'built {{.RepoTags}} {{.Size}} bytes'