-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
23 lines (22 loc) · 992 Bytes
/
Copy pathDockerfile
File metadata and controls
23 lines (22 loc) · 992 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
# --platform pins the builder to the BUILD host so a multi-arch build
# cross-compiles instead of running this whole stage under emulation.
FROM --platform=$BUILDPLATFORM docker.io/library/golang:1.27.1-alpine AS builder
ARG TARGETOS TARGETARCH
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS="${TARGETOS:-linux}" GOARCH="${TARGETARCH}" go build -o /app/payment-service ./cmd/main.go
# Pinned base (not :latest) for reproducibility; busybox provides the wget the
# compose healthcheck uses. Runs as a non-root user (least privilege; also
# satisfies the cluster PSS-restricted runAsNonRoot policy).
FROM alpine:3.24
RUN apk --no-cache add ca-certificates \
&& adduser -D -u 10001 app
WORKDIR /app
COPY --from=builder /app/payment-service .
USER 10001
EXPOSE 8080
# ENTRYPOINT (not CMD) so the migrate init container/compose can pass the
# `migrate` subcommand via args while the main container serves with no args.
ENTRYPOINT ["./payment-service"]