# The control plane's image. # # novox/hq ADR 0006: this image is pinned by digest in the bundle the host carries, fetched on a # machine where no mesh exists yet, and run before there is anything to check it against. So it # holds the program and nothing else — no shell, no package manager, no libc, nothing with a CVE # feed of its own. What a person has to audit before trusting a first node is one binary. # # There are no CA certificates in here on purpose. Nothing it does today makes an outbound TLS # connection to a public name: it reaches PostgreSQL on the machine it was raised on, and the # broker is verified against a fingerprint pinned in a token rather than against a public root # (novox/hq ADR 0004). Adding them "just in case" would put a trust store in the one image whose # whole argument is that it contains nothing to reason about. FROM golang:1.25-alpine AS build WORKDIR /src # Dependencies first, so a change to the source does not refetch them. COPY go.mod go.sum ./ RUN go mod download COPY . . ARG VERSION=development RUN CGO_ENABLED=0 go build -trimpath \ -ldflags "-s -w -X main.version=${VERSION}" \ -o /mesh-controller ./cmd/mesh-controller FROM scratch COPY --from=build /mesh-controller /mesh-controller # Numeric because there is no /etc/passwd to look a name up in. Nothing here needs to be root: # it opens outbound connections and writes nothing to its own filesystem. USER 65534:65534 ENTRYPOINT ["/mesh-controller"]