[misc] Build the upload server from source, nonroot on Chainguard (#7663)

upload-server/Dockerfile only packaged the goreleaser-built binary, so
the image could not be built from a checkout.  It is now a multi-stage
build on Chainguard static, running as the nonroot user (uid 65532),
with a VARIANT=debug build arg that swaps in busybox for a shell.

The goreleaser packaging file moves unchanged to Dockerfile.release and
.goreleaser.yaml points at it, so the published netbirdio/upload image
stays as it was: distroless and root.

The bases are pinned by digest, since Chainguard publishes only :latest
for free.  A Dependabot docker entry for /upload-server moves them
weekly, leaving the release base alone and holding golang to patch
updates.
This commit is contained in:
Brad Ison
2026-09-25 12:15:59 +02:00
committed by GitHub
parent aa1e66cc88
commit 6cf07caaf6
4 changed files with 78 additions and 5 deletions
+22
View File
@@ -46,3 +46,25 @@ updates:
wireguard:
patterns:
- "golang.zx2c4.com/wireguard*"
# Base images of the source-build Dockerfiles, pinned by digest (Chainguard
# publishes only :latest for free). Dockerfile.release files feed goreleaser
# and keep the published images as they are, so their bases are left alone.
- package-ecosystem: "docker"
directories:
- "/upload-server"
schedule:
interval: "weekly"
open-pull-requests-limit: 3
groups:
base-images:
patterns:
- "*"
ignore:
- dependency-name: "gcr.io/distroless/base"
# Go minor and major versions move with the rest of the repository;
# patch releases and new digests of the pinned tag still come through.
- dependency-name: "golang"
update-types:
- "version-update:semver-minor"
- "version-update:semver-major"