# The builder, as a module ships one. # # Not FROM scratch, unlike the control plane: this one runs git and a container client, so it # needs a filesystem with them on it. That is the honest cost of a machine whose job is to build — # and it is why building is a MODULE on a machine that has a runtime rather than something the # control plane does (novox/hq ADR 0005). FROM golang:1.25-alpine AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . RUN CGO_ENABLED=0 go build -trimpath -ldflags '-s -w' -o /mesh-builder ./cmd/mesh-builder FROM alpine:3 # git to clone what it is asked to build, and the docker client to build and push it. The daemon # is the machine's, reached through its socket — a build machine shares the runtime it was given # rather than running one inside itself. RUN apk add --no-cache git docker-cli COPY --from=build /mesh-builder /usr/local/bin/mesh-builder ENTRYPOINT ["/usr/local/bin/mesh-builder"]