From 10671884d2f17e8b2990a79f7855be114bb8d07b Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Fri, 2 Oct 2026 23:45:55 +1000 Subject: [PATCH] ci: move Go steps to the estate-built gobuilder image The packer-built almalinux9-gobuilder image is being retired. Switch test and pre-commit steps to artifactapi docker-internal/gobuilder 0.1.2-alma9, which trusts the estate CA and ships go-cache-plugin baked in on PATH. - Point test/pre-commit steps at the new image - Drop the curl/sha256sum bootstrap for go-cache-plugin; set GOCACHEPROG directly as a static env var since the binary is always present now - Best-effort S3 cache behaviour is unchanged: verified go build/test still succeed with unreachable/invalid S3 credentials, since the plugin itself degrades to cache misses at runtime --- .woodpecker/pre-commit.yaml | 8 ++++---- .woodpecker/test.yaml | 7 +++---- 2 files changed, 7 insertions(+), 8 deletions(-) diff --git a/.woodpecker/pre-commit.yaml b/.woodpecker/pre-commit.yaml index 1732204..939e92c 100644 --- a/.woodpecker/pre-commit.yaml +++ b/.woodpecker/pre-commit.yaml @@ -3,15 +3,15 @@ when: steps: - name: pre-commit - image: git.unkin.net/unkin/almalinux9-gobuilder:20260606 + # gobuilder trusts the internal CA, which the S3 build cache endpoint needs. + # go-cache-plugin is baked into the image; S3 errors degrade to cache misses. + image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9" commands: - # Best-effort S3 build cache for the go vet hook: if the plugin cannot be - # fetched, GOCACHEPROG stays unset. S3 errors degrade to cache misses. - - "curl -fsSLo /tmp/gocacheprog https://git.unkin.net/unkin/go-cache-plugin/releases/download/v0.1.0/go-cache-plugin-linux-amd64 && echo '0eb23d06a0dcf395559cb6447864579c220e60148fdcd6a6f841c2b17169b9b8 /tmp/gocacheprog' | sha256sum -c - && chmod +x /tmp/gocacheprog && export GOCACHEPROG=\"/tmp/gocacheprog --cache-dir=/tmp/gocache\" || echo 'go build cache unavailable, compiling without it'" - uvx pre-commit run --all-files environment: # golib lives on Gitea; skip the public proxy/sum db. GOPRIVATE: git.unkin.net + GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache" GOCACHE_S3_BUCKET: gocache # Explicit region skips a GetBucketLocation probe RGW handles poorly. GOCACHE_S3_REGION: us-east-1 diff --git a/.woodpecker/test.yaml b/.woodpecker/test.yaml index 4df101a..e7964ba 100644 --- a/.woodpecker/test.yaml +++ b/.woodpecker/test.yaml @@ -4,15 +4,14 @@ when: steps: - name: test # gobuilder trusts the internal CA, which the S3 build cache endpoint needs. - image: git.unkin.net/unkin/almalinux9-gobuilder:20260606 + # go-cache-plugin is baked into the image; S3 errors degrade to cache misses. + image: "artifactapi.k8s.syd1.au.unkin.net/docker-internal/gobuilder:0.1.2-alma9" commands: - # Best-effort S3 build cache: if the plugin cannot be fetched, GOCACHEPROG - # stays unset and the compile runs as before. S3 errors degrade to misses. - - "curl -fsSLo /tmp/gocacheprog https://git.unkin.net/unkin/go-cache-plugin/releases/download/v0.1.0/go-cache-plugin-linux-amd64 && echo '0eb23d06a0dcf395559cb6447864579c220e60148fdcd6a6f841c2b17169b9b8 /tmp/gocacheprog' | sha256sum -c - && chmod +x /tmp/gocacheprog && export GOCACHEPROG=\"/tmp/gocacheprog --cache-dir=/tmp/gocache\" || echo 'go build cache unavailable, compiling without it'" - go test -race -count=1 ./pkg/... ./internal/... environment: # golib lives on Gitea; skip the public proxy/sum db. GOPRIVATE: git.unkin.net + GOCACHEPROG: "go-cache-plugin --cache-dir=/tmp/gocache" GOCACHE_S3_BUCKET: gocache # Explicit region skips a GetBucketLocation probe RGW handles poorly. GOCACHE_S3_REGION: us-east-1 -- 2.47.3