ci: move Go steps to the estate-built gobuilder image
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

The packer-built almalinux9-gobuilder image is being retired. Switch
test and pre-commit steps to artifactapi docker-internal/gobuilder
0.1.2-alma9, which trusts the estate CA and ships go-cache-plugin
baked in on PATH.

- Point test/pre-commit steps at the new image
- Drop the curl/sha256sum bootstrap for go-cache-plugin; set
  GOCACHEPROG directly as a static env var since the binary is
  always present now
- Best-effort S3 cache behaviour is unchanged: verified go build/test
  still succeed with unreachable/invalid S3 credentials, since the
  plugin itself degrades to cache misses at runtime
This commit is contained in:
2026-10-02 23:45:55 +10:00
parent 7a4f4054cc
commit 10671884d2
2 changed files with 7 additions and 8 deletions
+4 -4
View File
@@ -3,15 +3,15 @@ when:
steps:
- name: pre-commit
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
# gobuilder trusts the internal CA, which the S3 build cache endpoint needs.
# go-cache-plugin is baked into the image; S3 errors degrade to cache misses.
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
commands:
# Best-effort S3 build cache for the go vet hook: if the plugin cannot be
# fetched, GOCACHEPROG stays unset. S3 errors degrade to cache misses.
- "curl -fsSLo /tmp/gocacheprog https://git.unkin.net/unkin/go-cache-plugin/releases/download/v0.1.0/go-cache-plugin-linux-amd64 && echo '0eb23d06a0dcf395559cb6447864579c220e60148fdcd6a6f841c2b17169b9b8 /tmp/gocacheprog' | sha256sum -c - && chmod +x /tmp/gocacheprog && export GOCACHEPROG=\"/tmp/gocacheprog --cache-dir=/tmp/gocache\" || echo 'go build cache unavailable, compiling without it'"
- uvx pre-commit run --all-files
environment:
# golib lives on Gitea; skip the public proxy/sum db.
GOPRIVATE: git.unkin.net
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
GOCACHE_S3_BUCKET: gocache
# Explicit region skips a GetBucketLocation probe RGW handles poorly.
GOCACHE_S3_REGION: us-east-1
+3 -4
View File
@@ -4,15 +4,14 @@ when:
steps:
- name: test
# gobuilder trusts the internal CA, which the S3 build cache endpoint needs.
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
# go-cache-plugin is baked into the image; S3 errors degrade to cache misses.
image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9"
commands:
# Best-effort S3 build cache: if the plugin cannot be fetched, GOCACHEPROG
# stays unset and the compile runs as before. S3 errors degrade to misses.
- "curl -fsSLo /tmp/gocacheprog https://git.unkin.net/unkin/go-cache-plugin/releases/download/v0.1.0/go-cache-plugin-linux-amd64 && echo '0eb23d06a0dcf395559cb6447864579c220e60148fdcd6a6f841c2b17169b9b8 /tmp/gocacheprog' | sha256sum -c - && chmod +x /tmp/gocacheprog && export GOCACHEPROG=\"/tmp/gocacheprog --cache-dir=/tmp/gocache\" || echo 'go build cache unavailable, compiling without it'"
- go test -race -count=1 ./pkg/... ./internal/...
environment:
# golib lives on Gitea; skip the public proxy/sum db.
GOPRIVATE: git.unkin.net
GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache"
GOCACHE_S3_BUCKET: gocache
# Explicit region skips a GetBucketLocation probe RGW handles poorly.
GOCACHE_S3_REGION: us-east-1