# syntax=docker/dockerfile:1 # ── build ─────────────────────────────────────────────────────────────────── # templ output (*_templ.go) and the vendored htmx asset are committed, so a # plain `go build` produces a self-contained binary — no codegen, no CDN. FROM golang:1.26 AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . # CGO off + static linking so the binary runs in a distroless/scratch image with # no libc. Trim symbols/DWARF to shrink the layer. RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags='-s -w' -o /out/tapir ./cmd/tapir # ── runtime ───────────────────────────────────────────────────────────────── # distroless static + nonroot: no shell, no package manager, runs as uid 65532. # ca-certificates are bundled, which the OIDC/HTTPS clients need. FROM gcr.io/distroless/static-debian12:nonroot COPY --from=build /out/tapir /tapir EXPOSE 8080 USER nonroot:nonroot ENTRYPOINT ["/tapir"] CMD ["serve"]