ci: move Go steps to the estate-built gobuilder image (#127)

Packer-built almalinux9-gobuilder is retiring. Moves test and
pre-commit steps to artifactapi docker-internal/gobuilder 0.1.2-alma9
(estate CA, go1.26.7, go-cache-plugin baked in).

- Repoint both steps at the new image, quoted (has a colon)
- Drop curl/sha256sum bootstrap for go-cache-plugin; it's on PATH now
- Set GOCACHEPROG as a static env var instead of a conditional export
- Verified build/test still pass with unreachable/invalid S3 creds —
  best-effort degrade is a plugin runtime property, unaffected

Reviewed-on: #127
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #127.
This commit is contained in:
2026-10-03 00:26:02 +10:00
committed by BenVincent
parent 7a4f4054cc
commit 0b159dad90
2 changed files with 7 additions and 8 deletions
+4 -4
View File
@@ -3,15 +3,15 @@ when:
steps:
- name: pre-commit
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
# gobuilder trusts the internal CA, which the S3 build cache endpoint needs.
# go-cache-plugin is baked into the image; S3 errors degrade to cache misses.
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
commands:
# Best-effort S3 build cache for the go vet hook: if the plugin cannot be
# fetched, GOCACHEPROG stays unset. S3 errors degrade to cache misses.
- "curl -fsSLo /tmp/gocacheprog https://git.unkin.net/unkin/go-cache-plugin/releases/download/v0.1.0/go-cache-plugin-linux-amd64 && echo '0eb23d06a0dcf395559cb6447864579c220e60148fdcd6a6f841c2b17169b9b8 /tmp/gocacheprog' | sha256sum -c - && chmod +x /tmp/gocacheprog && export GOCACHEPROG=\"/tmp/gocacheprog --cache-dir=/tmp/gocache\" || echo 'go build cache unavailable, compiling without it'"
- uvx pre-commit run --all-files
environment:
# golib lives on Gitea; skip the public proxy/sum db.
GOPRIVATE: git.unkin.net
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
GOCACHE_S3_BUCKET: gocache
# Explicit region skips a GetBucketLocation probe RGW handles poorly.
GOCACHE_S3_REGION: us-east-1
+3 -4
View File
@@ -4,15 +4,14 @@ when:
steps:
- name: test
# gobuilder trusts the internal CA, which the S3 build cache endpoint needs.
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
# go-cache-plugin is baked into the image; S3 errors degrade to cache misses.
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
commands:
# Best-effort S3 build cache: if the plugin cannot be fetched, GOCACHEPROG
# stays unset and the compile runs as before. S3 errors degrade to misses.
- "curl -fsSLo /tmp/gocacheprog https://git.unkin.net/unkin/go-cache-plugin/releases/download/v0.1.0/go-cache-plugin-linux-amd64 && echo '0eb23d06a0dcf395559cb6447864579c220e60148fdcd6a6f841c2b17169b9b8 /tmp/gocacheprog' | sha256sum -c - && chmod +x /tmp/gocacheprog && export GOCACHEPROG=\"/tmp/gocacheprog --cache-dir=/tmp/gocache\" || echo 'go build cache unavailable, compiling without it'"
- go test -race -count=1 ./pkg/... ./internal/...
environment:
# golib lives on Gitea; skip the public proxy/sum db.
GOPRIVATE: git.unkin.net
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
GOCACHE_S3_BUCKET: gocache
# Explicit region skips a GetBucketLocation probe RGW handles poorly.
GOCACHE_S3_REGION: us-east-1