The language and the bundle ordering went into ADR 0006, where the substrate and the control plane already live, and the store-per-context mechanics into 0008, which already decided the rule. Nothing changed but where the reasoning is kept.
35 lines
1.4 KiB
Docker
35 lines
1.4 KiB
Docker
# The control plane's image.
|
|
#
|
|
# novox/hq ADR 0006: this image is pinned by digest in the bundle the host carries, fetched on a
|
|
# machine where no mesh exists yet, and run before there is anything to check it against. So it
|
|
# holds the program and nothing else — no shell, no package manager, no libc, nothing with a CVE
|
|
# feed of its own. What a person has to audit before trusting a first node is one binary.
|
|
#
|
|
# There are no CA certificates in here on purpose. Nothing it does today makes an outbound TLS
|
|
# connection to a public name: it reaches PostgreSQL on the machine it was raised on, and the
|
|
# broker is verified against a fingerprint pinned in a token rather than against a public root
|
|
# (novox/hq ADR 0004). Adding them "just in case" would put a trust store in the one image whose
|
|
# whole argument is that it contains nothing to reason about.
|
|
|
|
FROM golang:1.25-alpine AS build
|
|
WORKDIR /src
|
|
|
|
# Dependencies first, so a change to the source does not refetch them.
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
ARG VERSION=development
|
|
RUN CGO_ENABLED=0 go build -trimpath \
|
|
-ldflags "-s -w -X main.version=${VERSION}" \
|
|
-o /mesh-control ./cmd/mesh-control
|
|
|
|
FROM scratch
|
|
COPY --from=build /mesh-control /mesh-control
|
|
|
|
# Numeric because there is no /etc/passwd to look a name up in. Nothing here needs to be root:
|
|
# it opens outbound connections and writes nothing to its own filesystem.
|
|
USER 65534:65534
|
|
|
|
ENTRYPOINT ["/mesh-control"]
|