<#1020 Migrate GoReleaser to dockers_v2> Pull requ...
# osctrl
g
#1020 Migrate GoReleaser to dockers_v2 Pull request opened by javuto Migrate GoReleaser to dockers_v2
goreleaser check
was emitting on every run:
dockers
and
docker_manifests
are being phased out and will eventually be
replaced by
dockers_v2
Changes
.goreleaser.yml
— replaced 8
dockers
entries (one per image × arch) and 8
docker_manifests
entries with 4
dockers_v2
entries
, one per image, each declaring
platforms: [linux/amd64, linux/arm64]
and
tags: ["{{ .Version }}", "latest"]
. buildx now builds every platform and pushes the manifest list itself, so the per-arch `-amd64`/`-arm64` tags and the manifest-fuse step are gone — which also retires the
docker exporter does not currently support exporting manifest lists
workaround those two sections existed for. Net −164/+101 lines.
docker_signs
keeps cosign but drops
artifacts: all
, as the deprecation notice instructs. Two deliberate departures from
dockers_v2
defaults, to keep published output byte-identical in shape:
sbom: false
and
--provenance=false
.
dockers_v2
defaults
sbom
to true, and the extra attestation manifests would appear under each tag — the release workflow resolves a tag to a single digest for cosign verification and does not expect them.
Dockerfile-osctrl-{tls,api,cli}
— required by the migration, not cosmetic.
dockers_v2
stages binaries per platform in the build context (
linux/amd64/…
) rather than flat, so each Dockerfile now declares buildx's
TARGETPLATFORM
/
TARGETOS
/
TARGETARCH
and copies
${TARGETPLATFORM}/osctrl-${COMPONENT}-${TARGETOS}-${TARGETARCH}
. The old `GOOS`/`GOARCH` args existed only to make the flat path resolve and are removed. The frontend Dockerfile is unchanged — it ships only
extra_files
. Validation
goreleaser check
passes with no deprecation warnings (goreleaser 2.18.0;
dockers_v2
landed in 2.12, OSS). A local
goreleaser release --snapshot --clean
built all four images: •
osctrl-tls:…-arm64
runs its copied binary —
osctrl-tls version=0.5.8-SNAPSHOT-5505a384 commit=5505a384… date=…
— proving the new per-platform COPY resolves. •
osctrl-frontend
built on both arches and contains
index.html
plus both nginx server blocks, proving
extra_files
still preserve project-relative paths and
ids: []
stages no binary. Also checked: the release workflow's verify step uses plain tags via
buildx imagetools inspect
(manifest-list compatible); nothing in the repo referenced the retired per-arch tags; and the only other consumer of these Dockerfiles,
.github/actions/build/docker/action.yml
, is dead code — no workflow references anything under
.github/actions/
. Caveats • The local snapshot hit GoReleaser's 1h timeout after 53m, so the emulated amd64 variants of tls/api/cli did not finish. That is this Mac emulating x86, not a config fault — CI builds amd64 natively and emulates only arm64, the same work the old config did. • The release workflow sets up buildx but not
setup-qemu
. Unchanged by this PR (v1 also cross-built arm64), but worth adding explicitly rather than relying on the runner's preinstalled binfmt handlers. • Not verifiable without a real tag: whether
docker_signs
signs the manifest-list digest the workflow's cosign step verifies. Snapshots neither push nor sign. jmpsec/osctrl