Merge pull request 'Build multi-arch images for amd64 and arm64' (#1) from multi-arch into main
Reviewed-on: #1
This commit was merged in pull request #1.
This commit is contained in:
+12
-5
@@ -37,20 +37,27 @@ ARG MAX_CONNECTIONS="100"
|
|||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
FROM golang:1.27-alpine AS build
|
# The compiler always runs natively and cross-compiles for the target
|
||||||
|
# platform, so an arm64 image builds without emulation.
|
||||||
|
FROM --platform=$BUILDPLATFORM golang:1.27-alpine AS build
|
||||||
ARG ALLOWED_DOMAINS ALLOWED_NETWORKS SMTP_HOSTNAME SMTP_PORT MAX_MESSAGE_SIZE MAX_RECIPIENTS MAX_CONNECTIONS
|
ARG ALLOWED_DOMAINS ALLOWED_NETWORKS SMTP_HOSTNAME SMTP_PORT MAX_MESSAGE_SIZE MAX_RECIPIENTS MAX_CONNECTIONS
|
||||||
|
ARG TARGETOS TARGETARCH
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod main.go ./
|
COPY go.mod main.go ./
|
||||||
RUN CGO_ENABLED=0 go build -trimpath -o /mailsink -ldflags "-s -w \
|
RUN set -e; \
|
||||||
|
ldflags="-s -w \
|
||||||
-X 'main.allowedDomains=${ALLOWED_DOMAINS}' \
|
-X 'main.allowedDomains=${ALLOWED_DOMAINS}' \
|
||||||
-X 'main.allowedNetworks=${ALLOWED_NETWORKS}' \
|
-X 'main.allowedNetworks=${ALLOWED_NETWORKS}' \
|
||||||
-X 'main.hostname=${SMTP_HOSTNAME}' \
|
-X 'main.hostname=${SMTP_HOSTNAME}' \
|
||||||
-X 'main.port=${SMTP_PORT}' \
|
-X 'main.port=${SMTP_PORT}' \
|
||||||
-X 'main.maxMessageSize=${MAX_MESSAGE_SIZE}' \
|
-X 'main.maxMessageSize=${MAX_MESSAGE_SIZE}' \
|
||||||
-X 'main.maxRecipients=${MAX_RECIPIENTS}' \
|
-X 'main.maxRecipients=${MAX_RECIPIENTS}' \
|
||||||
-X 'main.maxConnections=${MAX_CONNECTIONS}'" . \
|
-X 'main.maxConnections=${MAX_CONNECTIONS}'"; \
|
||||||
# Fail the build on a bad setting rather than at container start.
|
# Fail the build on a bad setting rather than at container start. The
|
||||||
&& /mailsink -check
|
# check runs a native build, since the target binary may not run here.
|
||||||
|
CGO_ENABLED=0 go build -trimpath -o /tmp/check -ldflags "$ldflags" .; \
|
||||||
|
/tmp/check -check; \
|
||||||
|
CGO_ENABLED=0 GOOS=$TARGETOS GOARCH=$TARGETARCH go build -trimpath -o /mailsink -ldflags "$ldflags" .
|
||||||
|
|
||||||
# The runtime image holds the one static binary and nothing else: no shell,
|
# The runtime image holds the one static binary and nothing else: no shell,
|
||||||
# no MTA, no mail spool, no network tools.
|
# no MTA, no mail spool, no network tools.
|
||||||
|
|||||||
@@ -40,6 +40,13 @@ docker compose up -d --build
|
|||||||
sudo ./egress-lockdown.sh # optional second layer; see below
|
sudo ./egress-lockdown.sh # optional second layer; see below
|
||||||
```
|
```
|
||||||
|
|
||||||
|
The Dockerfile cross-compiles, so one build covers amd64 and arm64 without
|
||||||
|
emulation:
|
||||||
|
|
||||||
|
```sh
|
||||||
|
docker buildx build --platform linux/amd64,linux/arm64 -t mailsink .
|
||||||
|
```
|
||||||
|
|
||||||
Point applications at the Docker host on port 25. Any username and password
|
Point applications at the Docker host on port 25. Any username and password
|
||||||
are accepted, so apps configured for authenticated SMTP work unchanged. There
|
are accepted, so apps configured for authenticated SMTP work unchanged. There
|
||||||
is no TLS: clients must allow a plaintext connection.
|
is no TLS: clients must allow a plaintext connection.
|
||||||
|
|||||||
Reference in New Issue
Block a user