The mesh's own images declare theirs now, so the refusal ADR 0097 deferred is live. The builder's own image and the examples take arguments with defaults; make builds them, not the mesh.
23 lines
1006 B
Docker
23 lines
1006 B
Docker
ARG ALPINE_BASE=alpine:3
|
|
ARG GO_BASE=golang:1.25-alpine
|
|
# The builder, as a module ships one.
|
|
#
|
|
# Not FROM scratch, unlike the control plane: this one runs git and a container client, so it
|
|
# needs a filesystem with them on it. That is the honest cost of a machine whose job is to build —
|
|
# and it is why building is a MODULE on a machine that has a runtime rather than something the
|
|
# control plane does (novox/hq ADR 0005).
|
|
FROM ${GO_BASE} AS build
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN CGO_ENABLED=0 go build -trimpath -ldflags '-s -w' -o /mesh-builder ./cmd/mesh-builder
|
|
|
|
FROM ${ALPINE_BASE}
|
|
# git to clone what it is asked to build, and the docker client to build and push it. The daemon
|
|
# is the machine's, reached through its socket — a build machine shares the runtime it was given
|
|
# rather than running one inside itself.
|
|
RUN apk add --no-cache git docker-cli
|
|
COPY --from=build /mesh-builder /usr/local/bin/mesh-builder
|
|
ENTRYPOINT ["/usr/local/bin/mesh-builder"]
|