6
.gitignore
vendored
6
.gitignore
vendored
@@ -1,4 +1,8 @@
|
|||||||
bin/
|
bin/
|
||||||
node_modules/
|
node_modules/
|
||||||
.turbo
|
.turbo
|
||||||
.vscode
|
.vscode
|
||||||
|
dist/
|
||||||
|
sbom.json
|
||||||
|
sbom-docker.json
|
||||||
|
*_sbom.json
|
||||||
200
.goreleaser.yaml
Normal file
200
.goreleaser.yaml
Normal file
@@ -0,0 +1,200 @@
|
|||||||
|
# yaml-language-server: $schema=https://goreleaser.com/static/schema.json
|
||||||
|
version: 2
|
||||||
|
|
||||||
|
project_name: probod
|
||||||
|
|
||||||
|
before:
|
||||||
|
hooks:
|
||||||
|
- make @probo/console
|
||||||
|
|
||||||
|
builds:
|
||||||
|
- id: probod
|
||||||
|
main: ./cmd/probod/main.go
|
||||||
|
binary: probod
|
||||||
|
ldflags:
|
||||||
|
- -s -w
|
||||||
|
- -X 'main.version={{.Version}}'
|
||||||
|
- -X 'main.env=prod'
|
||||||
|
gcflags:
|
||||||
|
- -e
|
||||||
|
env:
|
||||||
|
- CGO_ENABLED=0
|
||||||
|
goos:
|
||||||
|
- windows
|
||||||
|
- darwin
|
||||||
|
goarch:
|
||||||
|
- amd64
|
||||||
|
- arm64
|
||||||
|
ignore:
|
||||||
|
- goos: windows
|
||||||
|
goarch: arm64
|
||||||
|
# Docker-specific builds for Linux only
|
||||||
|
- id: probod-docker
|
||||||
|
main: ./cmd/probod/main.go
|
||||||
|
binary: probod
|
||||||
|
ldflags:
|
||||||
|
- -s -w
|
||||||
|
- -X 'main.version={{.Version}}'
|
||||||
|
- -X 'main.env=prod'
|
||||||
|
gcflags:
|
||||||
|
- -e
|
||||||
|
env:
|
||||||
|
- CGO_ENABLED=0
|
||||||
|
goos:
|
||||||
|
- linux
|
||||||
|
goarch:
|
||||||
|
- amd64
|
||||||
|
- arm64
|
||||||
|
|
||||||
|
archives:
|
||||||
|
- name_template: >-
|
||||||
|
{{ .ProjectName }}_
|
||||||
|
{{- title .Os }}_
|
||||||
|
{{- if eq .Arch "amd64" }}x86_64
|
||||||
|
{{- else if eq .Arch "386" }}i386
|
||||||
|
{{- else }}{{ .Arch }}{{ end }}
|
||||||
|
{{- if .Arm }}v{{ .Arm }}{{ end }}
|
||||||
|
files:
|
||||||
|
- README.md
|
||||||
|
- LICENSE
|
||||||
|
- CHANGELOG.md
|
||||||
|
|
||||||
|
checksum:
|
||||||
|
name_template: "checksums.txt"
|
||||||
|
|
||||||
|
sboms:
|
||||||
|
- artifacts: archive
|
||||||
|
documents:
|
||||||
|
- "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
|
||||||
|
cmd: syft
|
||||||
|
args:
|
||||||
|
- "dir:."
|
||||||
|
- "--output=cyclonedx-json={{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
|
||||||
|
- "--source-name={{ .ProjectName }}"
|
||||||
|
- "--source-version={{ .Version }}"
|
||||||
|
|
||||||
|
signs:
|
||||||
|
- cmd: cosign
|
||||||
|
env:
|
||||||
|
- COSIGN_EXPERIMENTAL=1
|
||||||
|
certificate: "${artifact}.pem"
|
||||||
|
args:
|
||||||
|
- sign-blob
|
||||||
|
- "--output-certificate=${certificate}"
|
||||||
|
- "--output-signature=${signature}"
|
||||||
|
- "${artifact}"
|
||||||
|
- "--yes"
|
||||||
|
artifacts: checksum
|
||||||
|
output: true
|
||||||
|
|
||||||
|
docker_manifests:
|
||||||
|
- name_template: "ghcr.io/getprobo/probo:{{ .Version }}"
|
||||||
|
image_templates:
|
||||||
|
- "ghcr.io/getprobo/probo:{{ .Version }}-amd64"
|
||||||
|
- "ghcr.io/getprobo/probo:{{ .Version }}-arm64"
|
||||||
|
skip_push: "{{ .IsSnapshot }}"
|
||||||
|
- name_template: "ghcr.io/getprobo/probo:latest"
|
||||||
|
image_templates:
|
||||||
|
- "ghcr.io/getprobo/probo:latest-amd64"
|
||||||
|
- "ghcr.io/getprobo/probo:latest-arm64"
|
||||||
|
skip_push: "{{ .IsSnapshot }}"
|
||||||
|
|
||||||
|
docker_signs:
|
||||||
|
- id: images
|
||||||
|
cmd: cosign
|
||||||
|
env:
|
||||||
|
- COSIGN_EXPERIMENTAL=1
|
||||||
|
artifacts: images
|
||||||
|
output: true
|
||||||
|
args:
|
||||||
|
- "sign"
|
||||||
|
- "${artifact}"
|
||||||
|
- "--yes"
|
||||||
|
- id: manifests
|
||||||
|
cmd: cosign
|
||||||
|
env:
|
||||||
|
- COSIGN_EXPERIMENTAL=1
|
||||||
|
artifacts: manifests
|
||||||
|
output: true
|
||||||
|
args:
|
||||||
|
- "sign"
|
||||||
|
- "${artifact}"
|
||||||
|
- "--yes"
|
||||||
|
|
||||||
|
dockers:
|
||||||
|
- image_templates:
|
||||||
|
- "ghcr.io/getprobo/probo:{{ .Version }}-amd64"
|
||||||
|
- "ghcr.io/getprobo/probo:latest-amd64"
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
use: buildx
|
||||||
|
build_flag_templates:
|
||||||
|
- "--platform=linux/amd64"
|
||||||
|
- "--label=org.opencontainers.image.title={{.ProjectName}}"
|
||||||
|
- "--label=org.opencontainers.image.description=Probo compliance management platform"
|
||||||
|
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
|
||||||
|
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Version}}"
|
||||||
|
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.licenses=MIT"
|
||||||
|
# Use the Docker-specific build with AMD64 filtering
|
||||||
|
ids:
|
||||||
|
- probod-docker
|
||||||
|
goos: linux
|
||||||
|
goarch: amd64
|
||||||
|
skip_push: "{{ .IsSnapshot }}"
|
||||||
|
- image_templates:
|
||||||
|
- "ghcr.io/getprobo/probo:{{ .Version }}-arm64"
|
||||||
|
- "ghcr.io/getprobo/probo:latest-arm64"
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
use: buildx
|
||||||
|
build_flag_templates:
|
||||||
|
- "--platform=linux/arm64"
|
||||||
|
- "--label=org.opencontainers.image.title={{.ProjectName}}"
|
||||||
|
- "--label=org.opencontainers.image.description=Probo compliance management platform"
|
||||||
|
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
|
||||||
|
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
|
||||||
|
- "--label=org.opencontainers.image.version={{.Version}}"
|
||||||
|
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
|
||||||
|
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
|
||||||
|
- "--label=org.opencontainers.image.licenses=MIT"
|
||||||
|
# Use the Docker-specific build with ARM64 filtering
|
||||||
|
ids:
|
||||||
|
- probod-docker
|
||||||
|
goos: linux
|
||||||
|
goarch: arm64
|
||||||
|
skip_push: "{{ .IsSnapshot }}"
|
||||||
|
|
||||||
|
changelog:
|
||||||
|
sort: asc
|
||||||
|
filters:
|
||||||
|
exclude:
|
||||||
|
- "^docs:"
|
||||||
|
- "^test:"
|
||||||
|
- "^chore:"
|
||||||
|
- "^style:"
|
||||||
|
- "^refactor:"
|
||||||
|
- "^ci:"
|
||||||
|
- "^build:"
|
||||||
|
- Merge pull request
|
||||||
|
- Merge branch
|
||||||
|
- go mod tidy
|
||||||
|
|
||||||
|
release:
|
||||||
|
draft: false
|
||||||
|
prerelease: auto
|
||||||
|
mode: replace
|
||||||
|
header: |
|
||||||
|
## Changes in {{ .Tag }}
|
||||||
|
footer: |
|
||||||
|
## Docker Images
|
||||||
|
- `ghcr.io/getprobo/probo:{{ .Version }}` (multi-arch: linux/amd64, linux/arm64)
|
||||||
|
- `ghcr.io/getprobo/probo:latest` (multi-arch: linux/amd64, linux/arm64)
|
||||||
|
|
||||||
|
### Architecture-specific images
|
||||||
|
- `ghcr.io/getprobo/probo:{{ .Version }}-amd64`
|
||||||
|
- `ghcr.io/getprobo/probo:{{ .Version }}-arm64`
|
||||||
|
|
||||||
|
extra_files:
|
||||||
|
- glob: "*.json"
|
||||||
|
name_template: "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
|
||||||
30
Dockerfile
30
Dockerfile
@@ -1,29 +1,25 @@
|
|||||||
FROM node:22 AS frontend-builder
|
# syntax=docker/dockerfile:1
|
||||||
WORKDIR /workdir
|
|
||||||
COPY . .
|
|
||||||
RUN npm ci
|
|
||||||
RUN npm run build
|
|
||||||
|
|
||||||
FROM golang:1.24 AS backend-builder
|
|
||||||
WORKDIR /workdir
|
|
||||||
COPY go.mod go.sum ./
|
|
||||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
|
||||||
go mod download
|
|
||||||
COPY . .
|
|
||||||
COPY --from=frontend-builder /workdir/apps/console/dist ./apps/console/dist
|
|
||||||
RUN --mount=type=cache,target=/root/.cache/go-build \
|
|
||||||
make bin/probod
|
|
||||||
|
|
||||||
FROM ubuntu:24.04
|
FROM ubuntu:24.04
|
||||||
|
|
||||||
LABEL org.opencontainers.image.source="https://github.com/getprobo/probo"
|
LABEL org.opencontainers.image.source="https://github.com/getprobo/probo"
|
||||||
LABEL org.opencontainers.image.licenses="MIT"
|
LABEL org.opencontainers.image.licenses="MIT"
|
||||||
LABEL org.opencontainers.image.vendor="Probo Inc"
|
LABEL org.opencontainers.image.vendor="Probo Inc"
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Install dependencies and create user
|
||||||
RUN useradd -m probo && \
|
RUN useradd -m probo && \
|
||||||
apt-get update && \
|
apt-get update && \
|
||||||
apt-get upgrade -y && \
|
apt-get upgrade -y && \
|
||||||
apt-get install -y ca-certificates && \
|
apt-get install -y ca-certificates && \
|
||||||
rm -rf /var/lib/apt/lists/*
|
rm -rf /var/lib/apt/lists/*
|
||||||
COPY --from=backend-builder /workdir/bin /usr/local/bin/
|
|
||||||
|
# Copy the architecture-specific pre-built binary from GoReleaser
|
||||||
|
COPY probod /usr/local/bin/probod
|
||||||
|
|
||||||
|
# Ensure the binary is executable
|
||||||
|
RUN chmod +x /usr/local/bin/probod
|
||||||
|
|
||||||
USER probo
|
USER probo
|
||||||
|
|
||||||
ENTRYPOINT ["probod"]
|
ENTRYPOINT ["probod"]
|
||||||
|
|||||||
@@ -122,3 +122,11 @@ stack-ps: ## List the docker stack containers
|
|||||||
.PHONY: psql
|
.PHONY: psql
|
||||||
psql: ## Open a psql shell to the postgres container
|
psql: ## Open a psql shell to the postgres container
|
||||||
$(DOCKER_COMPOSE) exec postgres psql -U probod -d probod
|
$(DOCKER_COMPOSE) exec postgres psql -U probod -d probod
|
||||||
|
|
||||||
|
.PHONY: goreleaser-snapshot
|
||||||
|
goreleaser-snapshot: ## Build a snapshot release with goreleaser
|
||||||
|
goreleaser release --snapshot --clean --config .goreleaser.yaml
|
||||||
|
|
||||||
|
.PHONY: goreleaser-check
|
||||||
|
goreleaser-check: ## Check goreleaser configuration
|
||||||
|
goreleaser check
|
||||||
|
|||||||
Reference in New Issue
Block a user