GitHub
09/03/2026, 8:06 PMgoreleaser check was emitting on every run:
anddockersare being phased out and will eventually bedocker_manifests
replaced byChangesdockers_v2
.goreleaser.yml — replaced 8 dockers entries (one per image × arch) and 8
docker_manifests entries with 4 dockers_v2 entries, one per image, each
declaring platforms: [linux/amd64, linux/arm64] and tags: ["{{ .Version }}", "latest"]. buildx now builds every platform and pushes the manifest list itself,
so the per-arch `-amd64`/`-arm64` tags and the manifest-fuse step are gone — which
also retires the docker exporter does not currently support exporting manifest lists workaround those two sections existed for. Net −164/+101 lines.
docker_signs keeps cosign but drops artifacts: all, as the deprecation notice
instructs.
Two deliberate departures from dockers_v2 defaults, to keep published output
byte-identical in shape: sbom: false and --provenance=false.
dockers_v2 defaults sbom to true, and the extra attestation manifests would
appear under each tag — the release workflow resolves a tag to a single digest for
cosign verification and does not expect them.
Dockerfile-osctrl-{tls,api,cli} — required by the migration, not cosmetic.
dockers_v2 stages binaries per platform in the build context (linux/amd64/…)
rather than flat, so each Dockerfile now declares buildx's TARGETPLATFORM /
TARGETOS / TARGETARCH and copies
${TARGETPLATFORM}/osctrl-${COMPONENT}-${TARGETOS}-${TARGETARCH}. The old
`GOOS`/`GOARCH` args existed only to make the flat path resolve and are removed.
The frontend Dockerfile is unchanged — it ships only extra_files.
Validation
goreleaser check passes with no deprecation warnings (goreleaser 2.18.0;
dockers_v2 landed in 2.12, OSS). A local goreleaser release --snapshot --clean
built all four images:
• osctrl-tls:…-arm64 runs its copied binary — osctrl-tls version=0.5.8-SNAPSHOT-5505a384 commit=5505a384… date=… — proving the new per-platform COPY resolves.
• osctrl-frontend built on both arches and contains index.html plus both nginx
server blocks, proving extra_files still preserve project-relative paths and
ids: [] stages no binary.
Also checked: the release workflow's verify step uses plain tags via
buildx imagetools inspect (manifest-list compatible); nothing in the repo
referenced the retired per-arch tags; and the only other consumer of these
Dockerfiles, .github/actions/build/docker/action.yml, is dead code — no workflow
references anything under .github/actions/.
Caveats
• The local snapshot hit GoReleaser's 1h timeout after 53m, so the emulated
amd64 variants of tls/api/cli did not finish. That is this Mac emulating x86,
not a config fault — CI builds amd64 natively and emulates only arm64, the same
work the old config did.
• The release workflow sets up buildx but not setup-qemu. Unchanged by this PR
(v1 also cross-built arm64), but worth adding explicitly rather than relying on
the runner's preinstalled binfmt handlers.
• Not verifiable without a real tag: whether docker_signs signs the manifest-list
digest the workflow's cosign step verifies. Snapshots neither push nor sign.
jmpsec/osctrlGitHub
09/03/2026, 8:51 PM