Configure goreleaser

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2025-07-11 10:48:49 +02:00
parent 6fda84e5c7
commit 53dfdf3b0e
4 changed files with 226 additions and 18 deletions

6
.gitignore vendored
View File

@@ -1,4 +1,8 @@
bin/
node_modules/
.turbo
.vscode
.vscode
dist/
sbom.json
sbom-docker.json
*_sbom.json

200
.goreleaser.yaml Normal file
View File

@@ -0,0 +1,200 @@
# yaml-language-server: $schema=https://goreleaser.com/static/schema.json
version: 2
project_name: probod
before:
hooks:
- make @probo/console
builds:
- id: probod
main: ./cmd/probod/main.go
binary: probod
ldflags:
- -s -w
- -X 'main.version={{.Version}}'
- -X 'main.env=prod'
gcflags:
- -e
env:
- CGO_ENABLED=0
goos:
- windows
- darwin
goarch:
- amd64
- arm64
ignore:
- goos: windows
goarch: arm64
# Docker-specific builds for Linux only
- id: probod-docker
main: ./cmd/probod/main.go
binary: probod
ldflags:
- -s -w
- -X 'main.version={{.Version}}'
- -X 'main.env=prod'
gcflags:
- -e
env:
- CGO_ENABLED=0
goos:
- linux
goarch:
- amd64
- arm64
archives:
- name_template: >-
{{ .ProjectName }}_
{{- title .Os }}_
{{- if eq .Arch "amd64" }}x86_64
{{- else if eq .Arch "386" }}i386
{{- else }}{{ .Arch }}{{ end }}
{{- if .Arm }}v{{ .Arm }}{{ end }}
files:
- README.md
- LICENSE
- CHANGELOG.md
checksum:
name_template: "checksums.txt"
sboms:
- artifacts: archive
documents:
- "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
cmd: syft
args:
- "dir:."
- "--output=cyclonedx-json={{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
- "--source-name={{ .ProjectName }}"
- "--source-version={{ .Version }}"
signs:
- cmd: cosign
env:
- COSIGN_EXPERIMENTAL=1
certificate: "${artifact}.pem"
args:
- sign-blob
- "--output-certificate=${certificate}"
- "--output-signature=${signature}"
- "${artifact}"
- "--yes"
artifacts: checksum
output: true
docker_manifests:
- name_template: "ghcr.io/getprobo/probo:{{ .Version }}"
image_templates:
- "ghcr.io/getprobo/probo:{{ .Version }}-amd64"
- "ghcr.io/getprobo/probo:{{ .Version }}-arm64"
skip_push: "{{ .IsSnapshot }}"
- name_template: "ghcr.io/getprobo/probo:latest"
image_templates:
- "ghcr.io/getprobo/probo:latest-amd64"
- "ghcr.io/getprobo/probo:latest-arm64"
skip_push: "{{ .IsSnapshot }}"
docker_signs:
- id: images
cmd: cosign
env:
- COSIGN_EXPERIMENTAL=1
artifacts: images
output: true
args:
- "sign"
- "${artifact}"
- "--yes"
- id: manifests
cmd: cosign
env:
- COSIGN_EXPERIMENTAL=1
artifacts: manifests
output: true
args:
- "sign"
- "${artifact}"
- "--yes"
dockers:
- image_templates:
- "ghcr.io/getprobo/probo:{{ .Version }}-amd64"
- "ghcr.io/getprobo/probo:latest-amd64"
dockerfile: Dockerfile
use: buildx
build_flag_templates:
- "--platform=linux/amd64"
- "--label=org.opencontainers.image.title={{.ProjectName}}"
- "--label=org.opencontainers.image.description=Probo compliance management platform"
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.version={{.Version}}"
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
- "--label=org.opencontainers.image.licenses=MIT"
# Use the Docker-specific build with AMD64 filtering
ids:
- probod-docker
goos: linux
goarch: amd64
skip_push: "{{ .IsSnapshot }}"
- image_templates:
- "ghcr.io/getprobo/probo:{{ .Version }}-arm64"
- "ghcr.io/getprobo/probo:latest-arm64"
dockerfile: Dockerfile
use: buildx
build_flag_templates:
- "--platform=linux/arm64"
- "--label=org.opencontainers.image.title={{.ProjectName}}"
- "--label=org.opencontainers.image.description=Probo compliance management platform"
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.version={{.Version}}"
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
- "--label=org.opencontainers.image.licenses=MIT"
# Use the Docker-specific build with ARM64 filtering
ids:
- probod-docker
goos: linux
goarch: arm64
skip_push: "{{ .IsSnapshot }}"
changelog:
sort: asc
filters:
exclude:
- "^docs:"
- "^test:"
- "^chore:"
- "^style:"
- "^refactor:"
- "^ci:"
- "^build:"
- Merge pull request
- Merge branch
- go mod tidy
release:
draft: false
prerelease: auto
mode: replace
header: |
## Changes in {{ .Tag }}
footer: |
## Docker Images
- `ghcr.io/getprobo/probo:{{ .Version }}` (multi-arch: linux/amd64, linux/arm64)
- `ghcr.io/getprobo/probo:latest` (multi-arch: linux/amd64, linux/arm64)
### Architecture-specific images
- `ghcr.io/getprobo/probo:{{ .Version }}-amd64`
- `ghcr.io/getprobo/probo:{{ .Version }}-arm64`
extra_files:
- glob: "*.json"
name_template: "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"

View File

@@ -1,29 +1,25 @@
FROM node:22 AS frontend-builder
WORKDIR /workdir
COPY . .
RUN npm ci
RUN npm run build
FROM golang:1.24 AS backend-builder
WORKDIR /workdir
COPY go.mod go.sum ./
RUN --mount=type=cache,target=/go/pkg/mod \
go mod download
COPY . .
COPY --from=frontend-builder /workdir/apps/console/dist ./apps/console/dist
RUN --mount=type=cache,target=/root/.cache/go-build \
make bin/probod
# syntax=docker/dockerfile:1
FROM ubuntu:24.04
LABEL org.opencontainers.image.source="https://github.com/getprobo/probo"
LABEL org.opencontainers.image.licenses="MIT"
LABEL org.opencontainers.image.vendor="Probo Inc"
WORKDIR /app
# Install dependencies and create user
RUN useradd -m probo && \
apt-get update && \
apt-get upgrade -y && \
apt-get install -y ca-certificates && \
rm -rf /var/lib/apt/lists/*
COPY --from=backend-builder /workdir/bin /usr/local/bin/
# Copy the architecture-specific pre-built binary from GoReleaser
COPY probod /usr/local/bin/probod
# Ensure the binary is executable
RUN chmod +x /usr/local/bin/probod
USER probo
ENTRYPOINT ["probod"]

View File

@@ -122,3 +122,11 @@ stack-ps: ## List the docker stack containers
.PHONY: psql
psql: ## Open a psql shell to the postgres container
$(DOCKER_COMPOSE) exec postgres psql -U probod -d probod
.PHONY: goreleaser-snapshot
goreleaser-snapshot: ## Build a snapshot release with goreleaser
goreleaser release --snapshot --clean --config .goreleaser.yaml
.PHONY: goreleaser-check
goreleaser-check: ## Check goreleaser configuration
goreleaser check