3173abfba2
The Dockerfile builder was still golang:1.25-alpine, which resolves to
Go 1.25.14, so eb63e5e moved CI and the release workflow to 1.26.9 but the
published binary kept the standard library it was meant to leave. v0.44.0's
image scan reported CVE-2026-78667, CVE-2026-78669 and CVE-2026-97031 in
it, all fixed in 1.26.9. Pin the builder to the same version the
workflows use.
Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
34 lines
1.7 KiB
Docker
34 lines
1.7 KiB
Docker
# --platform=$BUILDPLATFORM pins the builder to the machine doing the building, so a
|
|
# multi-arch build compiles both targets natively instead of running an emulated arm64
|
|
# toolchain under QEMU. Go cross-compiles from TARGETOS/TARGETARCH, which BuildKit fills
|
|
# in per platform. The CI runner has no binfmt registration and no way to get one (the
|
|
# JS action that used to install it cannot run there), so this is not just an
|
|
# optimisation -- it is what makes the arm64 image buildable at all.
|
|
FROM --platform=$BUILDPLATFORM golang:1.26.9-alpine AS builder
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
ARG VERSION=dev
|
|
ARG TARGETOS
|
|
ARG TARGETARCH
|
|
RUN CGO_ENABLED=0 GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
|
|
go build -ldflags="-w -s -X main.version=${VERSION}" -o /terdut ./cmd/terdut
|
|
|
|
FROM scratch
|
|
# scratch has no trust store, and a Go binary on it fails every HTTPS call with
|
|
# "x509: certificate signed by unknown authority". Nothing needed one until single
|
|
# sign-on: discovery and the token exchange are HTTPS calls to the identity provider.
|
|
# The bundle is the builder's, copied by name so a missing file fails the build
|
|
# rather than shipping an image that cannot sign anybody in.
|
|
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
|
|
COPY --from=builder /terdut /terdut
|
|
EXPOSE 8080
|
|
# Numeric, not a name: scratch has no /etc/passwd for one to resolve against,
|
|
# and Docker's USER accepts a bare UID:GID without it. 65532 is the common
|
|
# "nonroot" convention (distroless's own uid), chosen so the chart's pod
|
|
# securityContext (runAsNonRoot, runAsUser: 65532) matches what the image
|
|
# already runs as rather than fighting it.
|
|
USER 65532:65532
|
|
ENTRYPOINT ["/terdut"]
|