-
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
29 lines (24 loc) · 915 Bytes
/
Copy pathDockerfile
File metadata and controls
29 lines (24 loc) · 915 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
# Build the manager binary.
FROM docker.io/library/golang:1.26-bookworm AS builder
WORKDIR /workspace
# Deps first for tight layer caching: this layer only invalidates when go.mod
# or go.sum change, not on every source edit.
COPY go.mod go.sum ./
RUN go mod download
COPY cmd/ cmd/
COPY api/ api/
COPY internal/ internal/
# CGO_ENABLED=0 produces a static binary we can put on distroless below.
# TARGETOS / TARGETARCH are set automatically by buildx for multi-arch builds;
# defaulting to linux/amd64 when built without buildx (e.g. a direct
# `docker build`).
ARG TARGETOS=linux
ARG TARGETARCH=amd64
RUN CGO_ENABLED=0 GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
go build -trimpath -ldflags='-s -w' -o /out/manager ./cmd
# Distroless runtime — no shell, tiny attack surface.
FROM gcr.io/distroless/static:nonroot
WORKDIR /
COPY --from=builder /out/manager /manager
USER 65532:65532
ENTRYPOINT ["/manager"]