split goreleaser to support pkcs11 and exclude on docker

This commit is contained in:
pascal
2026-09-17 00:17:37 +02:00
parent 25078c4af0
commit 92d76acdd3
2 changed files with 27 additions and 5 deletions
+22 -2
View File
@@ -40,6 +40,26 @@ builds:
tags: tags:
- load_wgnt_from_rsrc - load_wgnt_from_rsrc
# deb and rpm packages target glibc distributions, so they carry the PKCS#11 store, which
# links libc. Tarballs and the Alpine-based images keep the static build above.
- id: netbird-pkcs11
dir: client
binary: netbird
env: [CGO_ENABLED=0]
goos:
- linux
goarch:
- arm
- amd64
- arm64
- 386
ldflags:
- -s -w -X github.com/netbirdio/netbird/version.version={{.Version}} -X main.commit={{.Commit}} -X main.date={{.CommitDate}} -X main.builtBy=goreleaser
mod_timestamp: "{{ .CommitTimestamp }}"
tags:
- load_wgnt_from_rsrc
- pkcs11
- id: netbird-static - id: netbird-static
dir: client dir: client
binary: netbird binary: netbird
@@ -216,7 +236,7 @@ nfpms:
id: netbird_deb id: netbird_deb
bindir: /usr/bin bindir: /usr/bin
builds: builds:
- netbird - netbird-pkcs11
formats: formats:
- deb - deb
scripts: scripts:
@@ -231,7 +251,7 @@ nfpms:
id: netbird_rpm id: netbird_rpm
bindir: /usr/bin bindir: /usr/bin
builds: builds:
- netbird - netbird-pkcs11
formats: formats:
- rpm - rpm
scripts: scripts:
+5 -3
View File
@@ -171,9 +171,11 @@ should be root-only. And a wrong PIN counts against the TPM's dictionary-attack
which is shared with everything else on the machine that uses the TPM. which is shared with everything else on the machine that uses the TPM.
The module is loaded at runtime without cgo, through `purego`, which means the binary is The module is loaded at runtime without cgo, through `purego`, which means the binary is
dynamically linked against libc. The standard release binary stays fully static, so the dynamically linked against libc. The store is therefore compiled in only with `-tags pkcs11`
PKCS#11 store is compiled in only with `-tags pkcs11` on linux/amd64 and linux/arm64. on linux/amd64 and linux/arm64: the deb and rpm packages are built that way, since they
Without the tag, setting `NB_CERT_PKCS11_URI` logs that the build lacks the support. target glibc distributions, while the release tarballs and the Alpine-based container
images keep the fully static build. Without the tag, setting `NB_CERT_PKCS11_URI` logs that
the build lacks the support.
To exercise the path without hardware, initialise a SoftHSM token and run the end-to-end To exercise the path without hardware, initialise a SoftHSM token and run the end-to-end
test, which imports a key and certificate itself: test, which imports a key and certificate itself: