From 53dfdf3b0e885d2e3757de6b7815e65a93206914 Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Fri, 11 Jul 2025 10:48:49 +0200 Subject: [PATCH] Configure goreleaser Signed-off-by: Bryan Frimin --- .gitignore | 6 +- .goreleaser.yaml | 200 +++++++++++++++++++++++++++++++++++++++++++++++ Dockerfile | 30 +++---- GNUmakefile | 8 ++ 4 files changed, 226 insertions(+), 18 deletions(-) create mode 100644 .goreleaser.yaml diff --git a/.gitignore b/.gitignore index d34066c27..abff4c056 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,8 @@ bin/ node_modules/ .turbo -.vscode \ No newline at end of file +.vscode +dist/ +sbom.json +sbom-docker.json +*_sbom.json \ No newline at end of file diff --git a/.goreleaser.yaml b/.goreleaser.yaml new file mode 100644 index 000000000..abd61c4ee --- /dev/null +++ b/.goreleaser.yaml @@ -0,0 +1,200 @@ +# yaml-language-server: $schema=https://goreleaser.com/static/schema.json +version: 2 + +project_name: probod + +before: + hooks: + - make @probo/console + +builds: + - id: probod + main: ./cmd/probod/main.go + binary: probod + ldflags: + - -s -w + - -X 'main.version={{.Version}}' + - -X 'main.env=prod' + gcflags: + - -e + env: + - CGO_ENABLED=0 + goos: + - windows + - darwin + goarch: + - amd64 + - arm64 + ignore: + - goos: windows + goarch: arm64 + # Docker-specific builds for Linux only + - id: probod-docker + main: ./cmd/probod/main.go + binary: probod + ldflags: + - -s -w + - -X 'main.version={{.Version}}' + - -X 'main.env=prod' + gcflags: + - -e + env: + - CGO_ENABLED=0 + goos: + - linux + goarch: + - amd64 + - arm64 + +archives: + - name_template: >- + {{ .ProjectName }}_ + {{- title .Os }}_ + {{- if eq .Arch "amd64" }}x86_64 + {{- else if eq .Arch "386" }}i386 + {{- else }}{{ .Arch }}{{ end }} + {{- if .Arm }}v{{ .Arm }}{{ end }} + files: + - README.md + - LICENSE + - CHANGELOG.md + +checksum: + name_template: "checksums.txt" + +sboms: + - artifacts: archive + documents: + - "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json" + cmd: syft + args: + - "dir:." + - "--output=cyclonedx-json={{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json" + - "--source-name={{ .ProjectName }}" + - "--source-version={{ .Version }}" + +signs: + - cmd: cosign + env: + - COSIGN_EXPERIMENTAL=1 + certificate: "${artifact}.pem" + args: + - sign-blob + - "--output-certificate=${certificate}" + - "--output-signature=${signature}" + - "${artifact}" + - "--yes" + artifacts: checksum + output: true + +docker_manifests: + - name_template: "ghcr.io/getprobo/probo:{{ .Version }}" + image_templates: + - "ghcr.io/getprobo/probo:{{ .Version }}-amd64" + - "ghcr.io/getprobo/probo:{{ .Version }}-arm64" + skip_push: "{{ .IsSnapshot }}" + - name_template: "ghcr.io/getprobo/probo:latest" + image_templates: + - "ghcr.io/getprobo/probo:latest-amd64" + - "ghcr.io/getprobo/probo:latest-arm64" + skip_push: "{{ .IsSnapshot }}" + +docker_signs: + - id: images + cmd: cosign + env: + - COSIGN_EXPERIMENTAL=1 + artifacts: images + output: true + args: + - "sign" + - "${artifact}" + - "--yes" + - id: manifests + cmd: cosign + env: + - COSIGN_EXPERIMENTAL=1 + artifacts: manifests + output: true + args: + - "sign" + - "${artifact}" + - "--yes" + +dockers: + - image_templates: + - "ghcr.io/getprobo/probo:{{ .Version }}-amd64" + - "ghcr.io/getprobo/probo:latest-amd64" + dockerfile: Dockerfile + use: buildx + build_flag_templates: + - "--platform=linux/amd64" + - "--label=org.opencontainers.image.title={{.ProjectName}}" + - "--label=org.opencontainers.image.description=Probo compliance management platform" + - "--label=org.opencontainers.image.url=https://github.com/getprobo/probo" + - "--label=org.opencontainers.image.source=https://github.com/getprobo/probo" + - "--label=org.opencontainers.image.version={{.Version}}" + - '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}' + - "--label=org.opencontainers.image.revision={{.FullCommit}}" + - "--label=org.opencontainers.image.licenses=MIT" + # Use the Docker-specific build with AMD64 filtering + ids: + - probod-docker + goos: linux + goarch: amd64 + skip_push: "{{ .IsSnapshot }}" + - image_templates: + - "ghcr.io/getprobo/probo:{{ .Version }}-arm64" + - "ghcr.io/getprobo/probo:latest-arm64" + dockerfile: Dockerfile + use: buildx + build_flag_templates: + - "--platform=linux/arm64" + - "--label=org.opencontainers.image.title={{.ProjectName}}" + - "--label=org.opencontainers.image.description=Probo compliance management platform" + - "--label=org.opencontainers.image.url=https://github.com/getprobo/probo" + - "--label=org.opencontainers.image.source=https://github.com/getprobo/probo" + - "--label=org.opencontainers.image.version={{.Version}}" + - '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}' + - "--label=org.opencontainers.image.revision={{.FullCommit}}" + - "--label=org.opencontainers.image.licenses=MIT" + # Use the Docker-specific build with ARM64 filtering + ids: + - probod-docker + goos: linux + goarch: arm64 + skip_push: "{{ .IsSnapshot }}" + +changelog: + sort: asc + filters: + exclude: + - "^docs:" + - "^test:" + - "^chore:" + - "^style:" + - "^refactor:" + - "^ci:" + - "^build:" + - Merge pull request + - Merge branch + - go mod tidy + +release: + draft: false + prerelease: auto + mode: replace + header: | + ## Changes in {{ .Tag }} + footer: | + ## Docker Images + - `ghcr.io/getprobo/probo:{{ .Version }}` (multi-arch: linux/amd64, linux/arm64) + - `ghcr.io/getprobo/probo:latest` (multi-arch: linux/amd64, linux/arm64) + + ### Architecture-specific images + - `ghcr.io/getprobo/probo:{{ .Version }}-amd64` + - `ghcr.io/getprobo/probo:{{ .Version }}-arm64` + + extra_files: + - glob: "*.json" + name_template: "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json" diff --git a/Dockerfile b/Dockerfile index 3df72941d..a73b6bcb6 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,29 +1,25 @@ -FROM node:22 AS frontend-builder -WORKDIR /workdir -COPY . . -RUN npm ci -RUN npm run build - -FROM golang:1.24 AS backend-builder -WORKDIR /workdir -COPY go.mod go.sum ./ -RUN --mount=type=cache,target=/go/pkg/mod \ - go mod download -COPY . . -COPY --from=frontend-builder /workdir/apps/console/dist ./apps/console/dist -RUN --mount=type=cache,target=/root/.cache/go-build \ - make bin/probod - +# syntax=docker/dockerfile:1 FROM ubuntu:24.04 + LABEL org.opencontainers.image.source="https://github.com/getprobo/probo" LABEL org.opencontainers.image.licenses="MIT" LABEL org.opencontainers.image.vendor="Probo Inc" + WORKDIR /app + +# Install dependencies and create user RUN useradd -m probo && \ apt-get update && \ apt-get upgrade -y && \ apt-get install -y ca-certificates && \ rm -rf /var/lib/apt/lists/* -COPY --from=backend-builder /workdir/bin /usr/local/bin/ + +# Copy the architecture-specific pre-built binary from GoReleaser +COPY probod /usr/local/bin/probod + +# Ensure the binary is executable +RUN chmod +x /usr/local/bin/probod + USER probo + ENTRYPOINT ["probod"] diff --git a/GNUmakefile b/GNUmakefile index 6c94229ec..99dc2f7da 100644 --- a/GNUmakefile +++ b/GNUmakefile @@ -122,3 +122,11 @@ stack-ps: ## List the docker stack containers .PHONY: psql psql: ## Open a psql shell to the postgres container $(DOCKER_COMPOSE) exec postgres psql -U probod -d probod + +.PHONY: goreleaser-snapshot +goreleaser-snapshot: ## Build a snapshot release with goreleaser + goreleaser release --snapshot --clean --config .goreleaser.yaml + +.PHONY: goreleaser-check +goreleaser-check: ## Check goreleaser configuration + goreleaser check