Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
44 lines (35 loc) · 1.42 KB
/
Copy pathDockerfile
File metadata and controls
44 lines (35 loc) · 1.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
# syntax=docker/dockerfile:1
# The binary is pure Go, so the build stage always runs on the native
# architecture of the runner and cross-compiles. No QEMU, no per-arch runners.
FROM --platform=$BUILDPLATFORM golang:1.23-alpine AS build
RUN apk add --no-cache ca-certificates
WORKDIR /src
# No third-party dependencies, so there is no module download step to cache.
COPY go.mod ./
COPY cmd ./cmd
COPY internal ./internal
ARG VERSION=dev
# Provenance for the status page's build popover. All optional: an unset one
# just leaves that row off the page.
ARG COMMIT=
ARG BRANCH=
ARG BUILD_TIME=
ARG BUILD_NUMBER=
ARG TARGETOS
ARG TARGETARCH
RUN CGO_ENABLED=0 GOOS=${TARGETOS} GOARCH=${TARGETARCH} go build \
-trimpath \
-ldflags "-s -w -X main.version=${VERSION} -X main.commit=${COMMIT} \
-X main.branch=${BRANCH} -X main.buildTime=${BUILD_TIME} \
-X main.buildNumber=${BUILD_NUMBER}" \
-o /out/gh-proxy ./cmd/gh-proxy
# scratch: no shell, no package manager, nothing to pivot to if the proxy is
# ever compromised. The CA bundle is the only thing it needs, for TLS to GitHub.
FROM scratch
COPY --from=build /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
COPY --from=build /out/gh-proxy /gh-proxy
USER 65534:65534
EXPOSE 8899
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD ["/gh-proxy", "healthcheck"]
ENTRYPOINT ["/gh-proxy"]