Two Dependabot PRs are stuck behind the same number. #35 raises the go directive to 1.26.0 in six modules, because golang.org/x/crypto v0.56.0 requires it -- x/crypto tracks the two most recent Go releases and 0.56 dropped 1.25. A module that says 1.26 cannot be built by the 1.25 this repository pins in two places, so that PR fails every Go job. #29 raises actions/setup-go to v7, which sets GOTOOLCHAIN=local. With that set, `go install golang.org/x/vuln/cmd/govulncheck@latest` cannot quietly fetch a newer toolchain, and stops with golang.org/x/[email protected] requires go >= 1.26.0 (running go 1.25.14) Under setup-go v5 the same install succeeded by downloading 1.26 behind our backs, which is its own reason to be on 1.26 deliberately instead. So: security-scan's go-version and all eight Dockerfiles move together, 1.25 -> 1.26. Nothing else needs to. A newer toolchain builds an older directive happily, so this stands on its own before #35 lands, and the go.mod files stay where they are here. Checked by building rather than by reading: the api and ingest images both build on golang:1.26-alpine, and api, ingest and enterprise still `go build ./...` clean against their existing 1.25 directives.
26 lines
1.4 KiB
Docker
26 lines
1.4 KiB
Docker
# AGPLv3 module (same as core as of Phase 6), built like every other Go service here --
|
|
# context must be the repo root, not enterprise/ alone. enterprise/go.mod
|
|
# has replace directives for api/, ingest/, and proto/ (all resolved as
|
|
# sibling directories, e.g. ../api), and enterprise-auth needs api/
|
|
# specifically for two real reasons: cmd/enterprise-auth/main.go imports
|
|
# api/httpserver directly (WithCredentialedCORS, for the tenant-picker's
|
|
# credentialed cross-origin requests), and internal/rbacstore's
|
|
# DashboardPermissions adapter imports api/dashboards transitively.
|
|
# Go's module resolution needs the whole module's go.mod satisfied to
|
|
# build any one package in it, so this was never actually optional the
|
|
# way the old enterprise/-only context assumed -- confirmed broken the
|
|
# first time this was built with real Docker access after those two
|
|
# imports existed; the repo-root context below is the same shape
|
|
# enterprise-api's and enterprise-ingest's Dockerfiles already use for
|
|
# the identical reason.
|
|
# docker build -f enterprise/Dockerfile -t cairnobs-enterprise-auth .
|
|
FROM golang:1.26-alpine AS builder
|
|
WORKDIR /src
|
|
COPY . .
|
|
WORKDIR /src/enterprise
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/enterprise-auth ./cmd/enterprise-auth
|
|
|
|
FROM gcr.io/distroless/static-debian12
|
|
COPY --from=builder /out/enterprise-auth /enterprise-auth
|
|
ENTRYPOINT ["/enterprise-auth"]
|