diff --git a/Dockerfile b/Dockerfile index 25b314a1115..10718346a22 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,7 +13,7 @@ # limitations under the License. # Velero binary build section -FROM --platform=$BUILDPLATFORM golang:1.22-bookworm AS velero-builder +FROM --platform=$BUILDPLATFORM golang:1.22-bookworm AS velero-builder-base ARG GOPROXY ARG BIN @@ -36,15 +36,24 @@ ENV CGO_ENABLED=0 \ WORKDIR /go/src/github.com/vmware-tanzu/velero +COPY go.mod go.sum /go/src/github.com/vmware-tanzu/velero/ +# --mount=type=cache,target=/go/pkg/mod,id=vbb allows reuse of build cache across builds instead of invalidating whole cache when go.mod changes +# id is to allow other stages to use the same cache path without conflicting with this stage. +# velero-builder-helper and velero-builder share the same cache path and id to share the downloaded dependencies. +# restic-builder uses a different cache path and id to avoid sharing cache with velero-builder-helper and velero-builder. +RUN --mount=type=cache,target=/go/pkg/mod,id=vbb go mod download + COPY . /go/src/github.com/vmware-tanzu/velero -RUN mkdir -p /output/usr/bin && \ - export GOARM=$( echo "${GOARM}" | cut -c2-) && \ - go build -o /output/${BIN} \ - -ldflags "${LDFLAGS}" ${PKG}/cmd/${BIN} && \ - go build -o /output/velero-helper \ - -ldflags "${LDFLAGS}" ${PKG}/cmd/velero-helper && \ - go clean -modcache -cache +RUN mkdir -p /output/usr/bin + +FROM velero-builder-base AS velero-builder-helper +RUN --mount=type=cache,target=/go/pkg/mod,id=vbb GOARM=$( echo "${GOARM}" | cut -c2-) go build -o /output/velero-helper \ +-ldflags "${LDFLAGS}" ${PKG}/cmd/velero-helper + +FROM velero-builder-base AS velero-builder +RUN --mount=type=cache,target=/go/pkg/mod,id=vbb GOARM=$( echo "${GOARM}" | cut -c2-) go build -o /output/${BIN} \ + -ldflags "${LDFLAGS}" ${PKG}/cmd/${BIN} # Restic binary build section FROM --platform=$BUILDPLATFORM golang:1.22-bookworm AS restic-builder @@ -63,12 +72,33 @@ ENV CGO_ENABLED=0 \ GOARCH=${TARGETARCH} \ GOARM=${TARGETVARIANT} -COPY . /go/src/github.com/vmware-tanzu/velero - -RUN mkdir -p /output/usr/bin && \ - export GOARM=$(echo "${GOARM}" | cut -c2-) && \ - /go/src/github.com/vmware-tanzu/velero/hack/build-restic.sh && \ - go clean -modcache -cache +# /output dir needed by last stage to copy even when BIN is not velero +RUN mkdir -p /output/usr/bin + +# cache go mod download before applying patches +RUN --mount=type=cache,target=/go/pkg/mod,id=restic if [ "${BIN}" = "velero" ]; then \ + mkdir -p /build/restic && \ + cd /build/restic && \ + git clone --single-branch -b v${RESTIC_VERSION} https://github.com/restic/restic.git . && \ + go mod download; \ + fi + +# invalidate cache if patch changes +COPY hack/fix_restic_cve.txt /go/src/github.com/vmware-tanzu/velero/hack/ + +# cache go mod download after applying patches +RUN --mount=type=cache,target=/go/pkg/mod,id=restic if [ "${BIN}" = "velero" ]; then \ + cd /build/restic && \ + git apply /go/src/github.com/vmware-tanzu/velero/hack/fix_restic_cve.txt && \ + go mod download; \ + fi + +# arch specific build layer +RUN --mount=type=cache,target=/go/pkg/mod,id=restic if [ "${BIN}" = "velero" ]; then \ + cd /build/restic && \ + GOARM=$(echo "${GOARM}" | cut -c2-) go run build.go --goos "${GOOS}" --goarch "${GOARCH}" --goarm "${GOARM}" -o /output/usr/bin/restic && \ + chmod +x /output/usr/bin/restic; \ + fi # Velero image packing section FROM paketobuildpacks/run-jammy-tiny:latest @@ -77,6 +107,8 @@ LABEL maintainer="Xun Jiang " COPY --from=velero-builder /output / +COPY --from=velero-builder-helper /output / + COPY --from=restic-builder /output / USER cnb:cnb