6
.gitignore
vendored
6
.gitignore
vendored
@@ -1,4 +1,8 @@
|
||||
bin/
|
||||
node_modules/
|
||||
.turbo
|
||||
.vscode
|
||||
.vscode
|
||||
dist/
|
||||
sbom.json
|
||||
sbom-docker.json
|
||||
*_sbom.json
|
||||
200
.goreleaser.yaml
Normal file
200
.goreleaser.yaml
Normal file
@@ -0,0 +1,200 @@
|
||||
# yaml-language-server: $schema=https://goreleaser.com/static/schema.json
|
||||
version: 2
|
||||
|
||||
project_name: probod
|
||||
|
||||
before:
|
||||
hooks:
|
||||
- make @probo/console
|
||||
|
||||
builds:
|
||||
- id: probod
|
||||
main: ./cmd/probod/main.go
|
||||
binary: probod
|
||||
ldflags:
|
||||
- -s -w
|
||||
- -X 'main.version={{.Version}}'
|
||||
- -X 'main.env=prod'
|
||||
gcflags:
|
||||
- -e
|
||||
env:
|
||||
- CGO_ENABLED=0
|
||||
goos:
|
||||
- windows
|
||||
- darwin
|
||||
goarch:
|
||||
- amd64
|
||||
- arm64
|
||||
ignore:
|
||||
- goos: windows
|
||||
goarch: arm64
|
||||
# Docker-specific builds for Linux only
|
||||
- id: probod-docker
|
||||
main: ./cmd/probod/main.go
|
||||
binary: probod
|
||||
ldflags:
|
||||
- -s -w
|
||||
- -X 'main.version={{.Version}}'
|
||||
- -X 'main.env=prod'
|
||||
gcflags:
|
||||
- -e
|
||||
env:
|
||||
- CGO_ENABLED=0
|
||||
goos:
|
||||
- linux
|
||||
goarch:
|
||||
- amd64
|
||||
- arm64
|
||||
|
||||
archives:
|
||||
- name_template: >-
|
||||
{{ .ProjectName }}_
|
||||
{{- title .Os }}_
|
||||
{{- if eq .Arch "amd64" }}x86_64
|
||||
{{- else if eq .Arch "386" }}i386
|
||||
{{- else }}{{ .Arch }}{{ end }}
|
||||
{{- if .Arm }}v{{ .Arm }}{{ end }}
|
||||
files:
|
||||
- README.md
|
||||
- LICENSE
|
||||
- CHANGELOG.md
|
||||
|
||||
checksum:
|
||||
name_template: "checksums.txt"
|
||||
|
||||
sboms:
|
||||
- artifacts: archive
|
||||
documents:
|
||||
- "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
|
||||
cmd: syft
|
||||
args:
|
||||
- "dir:."
|
||||
- "--output=cyclonedx-json={{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
|
||||
- "--source-name={{ .ProjectName }}"
|
||||
- "--source-version={{ .Version }}"
|
||||
|
||||
signs:
|
||||
- cmd: cosign
|
||||
env:
|
||||
- COSIGN_EXPERIMENTAL=1
|
||||
certificate: "${artifact}.pem"
|
||||
args:
|
||||
- sign-blob
|
||||
- "--output-certificate=${certificate}"
|
||||
- "--output-signature=${signature}"
|
||||
- "${artifact}"
|
||||
- "--yes"
|
||||
artifacts: checksum
|
||||
output: true
|
||||
|
||||
docker_manifests:
|
||||
- name_template: "ghcr.io/getprobo/probo:{{ .Version }}"
|
||||
image_templates:
|
||||
- "ghcr.io/getprobo/probo:{{ .Version }}-amd64"
|
||||
- "ghcr.io/getprobo/probo:{{ .Version }}-arm64"
|
||||
skip_push: "{{ .IsSnapshot }}"
|
||||
- name_template: "ghcr.io/getprobo/probo:latest"
|
||||
image_templates:
|
||||
- "ghcr.io/getprobo/probo:latest-amd64"
|
||||
- "ghcr.io/getprobo/probo:latest-arm64"
|
||||
skip_push: "{{ .IsSnapshot }}"
|
||||
|
||||
docker_signs:
|
||||
- id: images
|
||||
cmd: cosign
|
||||
env:
|
||||
- COSIGN_EXPERIMENTAL=1
|
||||
artifacts: images
|
||||
output: true
|
||||
args:
|
||||
- "sign"
|
||||
- "${artifact}"
|
||||
- "--yes"
|
||||
- id: manifests
|
||||
cmd: cosign
|
||||
env:
|
||||
- COSIGN_EXPERIMENTAL=1
|
||||
artifacts: manifests
|
||||
output: true
|
||||
args:
|
||||
- "sign"
|
||||
- "${artifact}"
|
||||
- "--yes"
|
||||
|
||||
dockers:
|
||||
- image_templates:
|
||||
- "ghcr.io/getprobo/probo:{{ .Version }}-amd64"
|
||||
- "ghcr.io/getprobo/probo:latest-amd64"
|
||||
dockerfile: Dockerfile
|
||||
use: buildx
|
||||
build_flag_templates:
|
||||
- "--platform=linux/amd64"
|
||||
- "--label=org.opencontainers.image.title={{.ProjectName}}"
|
||||
- "--label=org.opencontainers.image.description=Probo compliance management platform"
|
||||
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
|
||||
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
|
||||
- "--label=org.opencontainers.image.version={{.Version}}"
|
||||
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.licenses=MIT"
|
||||
# Use the Docker-specific build with AMD64 filtering
|
||||
ids:
|
||||
- probod-docker
|
||||
goos: linux
|
||||
goarch: amd64
|
||||
skip_push: "{{ .IsSnapshot }}"
|
||||
- image_templates:
|
||||
- "ghcr.io/getprobo/probo:{{ .Version }}-arm64"
|
||||
- "ghcr.io/getprobo/probo:latest-arm64"
|
||||
dockerfile: Dockerfile
|
||||
use: buildx
|
||||
build_flag_templates:
|
||||
- "--platform=linux/arm64"
|
||||
- "--label=org.opencontainers.image.title={{.ProjectName}}"
|
||||
- "--label=org.opencontainers.image.description=Probo compliance management platform"
|
||||
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
|
||||
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
|
||||
- "--label=org.opencontainers.image.version={{.Version}}"
|
||||
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
|
||||
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||
- "--label=org.opencontainers.image.licenses=MIT"
|
||||
# Use the Docker-specific build with ARM64 filtering
|
||||
ids:
|
||||
- probod-docker
|
||||
goos: linux
|
||||
goarch: arm64
|
||||
skip_push: "{{ .IsSnapshot }}"
|
||||
|
||||
changelog:
|
||||
sort: asc
|
||||
filters:
|
||||
exclude:
|
||||
- "^docs:"
|
||||
- "^test:"
|
||||
- "^chore:"
|
||||
- "^style:"
|
||||
- "^refactor:"
|
||||
- "^ci:"
|
||||
- "^build:"
|
||||
- Merge pull request
|
||||
- Merge branch
|
||||
- go mod tidy
|
||||
|
||||
release:
|
||||
draft: false
|
||||
prerelease: auto
|
||||
mode: replace
|
||||
header: |
|
||||
## Changes in {{ .Tag }}
|
||||
footer: |
|
||||
## Docker Images
|
||||
- `ghcr.io/getprobo/probo:{{ .Version }}` (multi-arch: linux/amd64, linux/arm64)
|
||||
- `ghcr.io/getprobo/probo:latest` (multi-arch: linux/amd64, linux/arm64)
|
||||
|
||||
### Architecture-specific images
|
||||
- `ghcr.io/getprobo/probo:{{ .Version }}-amd64`
|
||||
- `ghcr.io/getprobo/probo:{{ .Version }}-arm64`
|
||||
|
||||
extra_files:
|
||||
- glob: "*.json"
|
||||
name_template: "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
|
||||
30
Dockerfile
30
Dockerfile
@@ -1,29 +1,25 @@
|
||||
FROM node:22 AS frontend-builder
|
||||
WORKDIR /workdir
|
||||
COPY . .
|
||||
RUN npm ci
|
||||
RUN npm run build
|
||||
|
||||
FROM golang:1.24 AS backend-builder
|
||||
WORKDIR /workdir
|
||||
COPY go.mod go.sum ./
|
||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
||||
go mod download
|
||||
COPY . .
|
||||
COPY --from=frontend-builder /workdir/apps/console/dist ./apps/console/dist
|
||||
RUN --mount=type=cache,target=/root/.cache/go-build \
|
||||
make bin/probod
|
||||
|
||||
# syntax=docker/dockerfile:1
|
||||
FROM ubuntu:24.04
|
||||
|
||||
LABEL org.opencontainers.image.source="https://github.com/getprobo/probo"
|
||||
LABEL org.opencontainers.image.licenses="MIT"
|
||||
LABEL org.opencontainers.image.vendor="Probo Inc"
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Install dependencies and create user
|
||||
RUN useradd -m probo && \
|
||||
apt-get update && \
|
||||
apt-get upgrade -y && \
|
||||
apt-get install -y ca-certificates && \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
COPY --from=backend-builder /workdir/bin /usr/local/bin/
|
||||
|
||||
# Copy the architecture-specific pre-built binary from GoReleaser
|
||||
COPY probod /usr/local/bin/probod
|
||||
|
||||
# Ensure the binary is executable
|
||||
RUN chmod +x /usr/local/bin/probod
|
||||
|
||||
USER probo
|
||||
|
||||
ENTRYPOINT ["probod"]
|
||||
|
||||
@@ -122,3 +122,11 @@ stack-ps: ## List the docker stack containers
|
||||
.PHONY: psql
|
||||
psql: ## Open a psql shell to the postgres container
|
||||
$(DOCKER_COMPOSE) exec postgres psql -U probod -d probod
|
||||
|
||||
.PHONY: goreleaser-snapshot
|
||||
goreleaser-snapshot: ## Build a snapshot release with goreleaser
|
||||
goreleaser release --snapshot --clean --config .goreleaser.yaml
|
||||
|
||||
.PHONY: goreleaser-check
|
||||
goreleaser-check: ## Check goreleaser configuration
|
||||
goreleaser check
|
||||
|
||||
Reference in New Issue
Block a user