# The provisioner, as a module ships one. # # Built here so a machine can be given it by the mesh rather than by somebody putting a binary on # it. Static and FROM scratch for the same reason the control plane's image is: it is fetched by # digest and run on a machine, and everything in it is something a person would have to audit. # The Go it builds with is the one the manifest pins (build.on GO_BASE), passed by the Makefile and the # build machine alike; the default only serves a hand build, and matches go.mod. ARG GO_BASE=golang:1.26-alpine FROM ${GO_BASE} AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . RUN CGO_ENABLED=0 go build -trimpath -ldflags '-s -w' \ -o /mesh-provision-postgres ./examples/postgres-provisioner FROM scratch COPY --from=build /mesh-provision-postgres /mesh-provision-postgres # Watching by default, because that is what makes it a module: an ordinary long-running service # the host supervises, rather than something invoked after every declaration. ENTRYPOINT ["/mesh-provision-postgres", "--watch"]