Build multi-arch images for amd64 and arm64 #1

Merged
jcoffey-dev merged 1 commits from multi-arch into main 2026-09-24 19:47:01 +00:00
2 changed files with 19 additions and 5 deletions
Showing only changes of commit 8a201db412 - Show all commits
+12 -5
View File
@@ -37,20 +37,27 @@ ARG MAX_CONNECTIONS="100"
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
FROM golang:1.27-alpine AS build # The compiler always runs natively and cross-compiles for the target
# platform, so an arm64 image builds without emulation.
FROM --platform=$BUILDPLATFORM golang:1.27-alpine AS build
ARG ALLOWED_DOMAINS ALLOWED_NETWORKS SMTP_HOSTNAME SMTP_PORT MAX_MESSAGE_SIZE MAX_RECIPIENTS MAX_CONNECTIONS ARG ALLOWED_DOMAINS ALLOWED_NETWORKS SMTP_HOSTNAME SMTP_PORT MAX_MESSAGE_SIZE MAX_RECIPIENTS MAX_CONNECTIONS
ARG TARGETOS TARGETARCH
WORKDIR /src WORKDIR /src
COPY go.mod main.go ./ COPY go.mod main.go ./
RUN CGO_ENABLED=0 go build -trimpath -o /mailsink -ldflags "-s -w \ RUN set -e; \
ldflags="-s -w \
-X 'main.allowedDomains=${ALLOWED_DOMAINS}' \ -X 'main.allowedDomains=${ALLOWED_DOMAINS}' \
-X 'main.allowedNetworks=${ALLOWED_NETWORKS}' \ -X 'main.allowedNetworks=${ALLOWED_NETWORKS}' \
-X 'main.hostname=${SMTP_HOSTNAME}' \ -X 'main.hostname=${SMTP_HOSTNAME}' \
-X 'main.port=${SMTP_PORT}' \ -X 'main.port=${SMTP_PORT}' \
-X 'main.maxMessageSize=${MAX_MESSAGE_SIZE}' \ -X 'main.maxMessageSize=${MAX_MESSAGE_SIZE}' \
-X 'main.maxRecipients=${MAX_RECIPIENTS}' \ -X 'main.maxRecipients=${MAX_RECIPIENTS}' \
-X 'main.maxConnections=${MAX_CONNECTIONS}'" . \ -X 'main.maxConnections=${MAX_CONNECTIONS}'"; \
# Fail the build on a bad setting rather than at container start. # Fail the build on a bad setting rather than at container start. The
&& /mailsink -check # check runs a native build, since the target binary may not run here.
CGO_ENABLED=0 go build -trimpath -o /tmp/check -ldflags "$ldflags" .; \
/tmp/check -check; \
CGO_ENABLED=0 GOOS=$TARGETOS GOARCH=$TARGETARCH go build -trimpath -o /mailsink -ldflags "$ldflags" .
# The runtime image holds the one static binary and nothing else: no shell, # The runtime image holds the one static binary and nothing else: no shell,
# no MTA, no mail spool, no network tools. # no MTA, no mail spool, no network tools.
+7
View File
@@ -40,6 +40,13 @@ docker compose up -d --build
sudo ./egress-lockdown.sh # optional second layer; see below sudo ./egress-lockdown.sh # optional second layer; see below
``` ```
The Dockerfile cross-compiles, so one build covers amd64 and arm64 without
emulation:
```sh
docker buildx build --platform linux/amd64,linux/arm64 -t mailsink .
```
Point applications at the Docker host on port 25. Any username and password Point applications at the Docker host on port 25. Any username and password
are accepted, so apps configured for authenticated SMTP work unchanged. There are accepted, so apps configured for authenticated SMTP work unchanged. There
is no TLS: clients must allow a plaintext connection. is no TLS: clients must allow a plaintext connection.