Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 8 additions & 4 deletions .azure-pipelines/steps/setup-go.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,16 @@
# Install the Go version declared in the repo's go.mod.
# ADO's GoTool@0 does not support "from go.mod" (unlike GitHub Actions'
# setup-go@v6), so we parse it explicitly and pass the value.
# Install the Go version that the repo's go.mod selects: the toolchain line
# if it exists, otherwise the go line. ADO's GoTool@0 does not read go.mod
# (unlike GitHub Actions' setup-go, which applies the same rule), so we parse
# it explicitly and pass the value.
#
# Assumes `checkout: self` has already run in the calling job.
steps:
- bash: |
set -euo pipefail
GO_VER=$(awk '/^go [0-9]/ {print $2; exit}' go.mod)
GO_VER=$(awk '/^toolchain go[0-9]/ {sub(/^go/, "", $2); print $2; exit}' go.mod)
if [ -z "$GO_VER" ]; then
GO_VER=$(awk '/^go [0-9]/ {print $2; exit}' go.mod)
fi
echo "Detected Go version from go.mod: $GO_VER"
echo "##vso[task.setvariable variable=GO_VERSION_FROM_GO_MOD]$GO_VER"
displayName: Read Go version from go.mod
Expand Down
6 changes: 6 additions & 0 deletions .github/dependabot.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,12 @@ updates:
# never becomes eligible.
cooldown:
default-days: 2
ignore:
# A Go minor version moves together with the go.mod toolchain line and
# the build changes it needs, so maintainers bump it by hand. Digest
# updates within a minor version still arrive here.
- dependency-name: "oss/go/microsoft/golang"
update-types: ["version-update:semver-minor"]
groups:
golang-base:
patterns: ["*golang*"]
Expand Down
8 changes: 2 additions & 6 deletions cli/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,9 +1,5 @@
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020 AS builder

# systemcrypto without cgo — required for arm64 cross-compile from amd64 host.
# Becomes redundant with Go 1.27+ (auto-selected when CGO_ENABLED=0).
ENV GOEXPERIMENT=ms_nocgo_opensslcrypto
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da AS builder

ARG VERSION
ARG APP_INSIGHTS_ID
Expand Down
12 changes: 3 additions & 9 deletions controller/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
# pinned base images

# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
# Pinned to $BUILDPLATFORM so the Go builds cross-compile natively from the
# host arch (fast). The eBPF .o files, which cannot be cleanly cross-compiled
# by bpf2go, are produced in the separate `bpf-gen` stage below (which runs
# at $TARGETPLATFORM — native on same-arch, emulated under QEMU otherwise).
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020 AS golang
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da AS golang

# skopeo inspect docker://mcr.microsoft.com/azurelinux/base/core:3.0 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/azurelinux/base/core:3.0.20260923@sha256:1324a2cf7ed34e5f48a1022816b205782b86c7305651658e611dcd3d30756751 AS azurelinux-core
Expand All @@ -20,13 +20,12 @@ FROM mcr.microsoft.com/azurelinux/distroless/minimal:3.0.20260923@sha256:792ea6e
# .o files via bpf2go/clang — those require native target-arch execution and
# cannot be cross-compiled from an amd64 host cleanly. Isolating this work in a
# small dedicated stage keeps the rest of the build fast at $BUILDPLATFORM.
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020 AS bpf-gen
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da AS bpf-gen
ARG GOOS=linux
ARG GOARCH=amd64
ENV GOOS=${GOOS}
ENV GOARCH=${GOARCH}
ENV CGO_ENABLED=0
ENV GOEXPERIMENT=ms_nocgo_opensslcrypto
RUN if [ "$GOOS" = "linux" ] ; then \
tdnf install -y clang lld bpftool libbpf-devel; \
fi
Expand All @@ -50,10 +49,6 @@ RUN set -eu; \

# intermediate go generate stage
FROM golang AS intermediate
# systemcrypto without cgo — required for arm64 cross-compile from amd64 host
# (Go auto-disables cgo when cross-compiling, and systemcrypto in Go <=1.26
# requires cgo unless this experiment is set). Becomes redundant with Go 1.27+.
ENV GOEXPERIMENT=ms_nocgo_opensslcrypto
ARG APP_INSIGHTS_ID # set to enable AI telemetry
ARG GOARCH=amd64 # default to amd64
ARG GOOS=linux # default to linux
Expand All @@ -75,7 +70,6 @@ RUN if [ "$GOOS" = "linux" ] ; then \
FROM golang AS hubble-bin
ARG GOARCH=amd64
ENV GOARCH=${GOARCH}
ENV GOEXPERIMENT=ms_nocgo_opensslcrypto
WORKDIR /go/src/github.com/microsoft/retina
COPY ./go.mod ./go.sum ./
RUN go mod download
Expand Down
4 changes: 2 additions & 2 deletions controller/Dockerfile.gogen
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da

# Default linux/architecture.
ARG GOOS=linux
Expand Down
4 changes: 2 additions & 2 deletions controller/Dockerfile.proto
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da

LABEL Name=retina-builder Version=0.0.1

Expand Down
2 changes: 1 addition & 1 deletion controller/Dockerfile.windows-cgo
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-windowsservercore-ltsc2022 --override-os windows --format "{{.Name}}@{{.Digest}}"
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-windowsservercore-ltsc2022 --override-os windows --format "{{.Name}}@{{.Digest}}"
FROM --platform=windows/amd64 mcr.microsoft.com/oss/go/microsoft/golang:1.27-windowsservercore-ltsc2022@sha256:10e42117182677d1657e791699d384c83d3f21528da0b7b9fc23d84eab5a1d70 AS cgo

SHELL ["powershell", "-Command", "$ErrorActionPreference = 'Stop'; $ProgressPreference = 'SilentlyContinue';"]
Expand Down
2 changes: 1 addition & 1 deletion controller/Dockerfile.windows-native
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
# buildx targets, and this one requires legacy build.
# Maybe one day: https://github.com/moby/buildkit/issues/616
ARG BUILDER_IMAGE
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-windowsservercore-ltsc2022 --override-os windows --format "{{.Name}}@{{.Digest}}"
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-windowsservercore-ltsc2022 --override-os windows --format "{{.Name}}@{{.Digest}}"
FROM --platform=windows/amd64 mcr.microsoft.com/oss/go/microsoft/golang:1.27-windowsservercore-ltsc2022@sha256:10e42117182677d1657e791699d384c83d3f21528da0b7b9fc23d84eab5a1d70 AS builder
WORKDIR C:\\retina
COPY go.mod .
Expand Down
2 changes: 2 additions & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@ module github.com/microsoft/retina

go 1.26.0

toolchain go1.27.1

require (
github.com/go-chi/chi/v5 v5.3.2
github.com/google/uuid v1.6.0
Expand Down
8 changes: 4 additions & 4 deletions hack/tools/kapinger/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Linux builder - runs natively on the target platform (amd64 or arm64)
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.26@sha256:4e652d1254a73a25bbc34dfda45dfca5dfae927f7245cc914310ff1057580499 AS builder
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.27@sha256:f6c0c89bd194d426d5f091d269e5dcb0755fd46173f92e96bb94b41054dfb583 AS builder

WORKDIR /build
ADD . .
Expand All @@ -16,8 +16,8 @@ COPY --from=builder /build/kapinger .
CMD ["./kapinger"]

# Windows builder - cross-compiles from Linux amd64 (GOOS=windows is not affected by systemcrypto)
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26@sha256:4e652d1254a73a25bbc34dfda45dfca5dfae927f7245cc914310ff1057580499 AS windows-builder
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.27@sha256:f6c0c89bd194d426d5f091d269e5dcb0755fd46173f92e96bb94b41054dfb583 AS windows-builder

WORKDIR /build
ADD . .
Expand Down
4 changes: 2 additions & 2 deletions hack/tools/toolbox/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.26@sha256:4e652d1254a73a25bbc34dfda45dfca5dfae927f7245cc914310ff1057580499 AS build
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.27@sha256:f6c0c89bd194d426d5f091d269e5dcb0755fd46173f92e96bb94b41054dfb583 AS build
ADD . .
WORKDIR /go/toolbox/
RUN GOOS=linux go build -o server .
Expand Down
8 changes: 2 additions & 6 deletions operator/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,9 +1,5 @@
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020 AS builder

# systemcrypto without cgo — required for arm64 cross-compile from amd64 host.
# Becomes redundant with Go 1.27+ (auto-selected when CGO_ENABLED=0).
ENV GOEXPERIMENT=ms_nocgo_opensslcrypto
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da AS builder

ARG VERSION
ARG APP_INSIGHTS_ID
Expand Down
4 changes: 2 additions & 2 deletions operator/Dockerfile.windows-2022
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020 AS builder
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM --platform=$BUILDPLATFORM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da AS builder

# Build args
ARG VERSION
Expand Down
9 changes: 3 additions & 6 deletions shell/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# pwru is built from a pinned source commit with this repo's Go builder, so
# its standard library tracks the golang base image instead of the upstream
# release cadence. Upstream publishes binaries only on tags.
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020 AS pwru-build
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da AS pwru-build
RUN tdnf install -y make git clang llvm gcc glibc-static gawk file flex bison tar diffutils
# https://github.com/cilium/pwru/releases/tag/v1.0.12
ARG PWRU_COMMIT=f1d6cf8898953ac1560401e181f3ac5f0e33b486
Expand All @@ -15,12 +15,9 @@ RUN set -eux; \
arm64) LIBPCAP_ARCH="aarch64-unknown-linux-gnu" ;; \
*) echo "Unsupported arch: $GOARCH" && exit 1 ;; \
esac; \
# GOEXPERIMENT=none disables the Microsoft Go OpenSSL crypto backend,
# which dlopens libcrypto at startup and crashes inside a statically
# linked binary. pwru does not need FIPS crypto.
# CC=clang: the ADO pipeline builds arm64 under QEMU, and gcc cc1
# crashes there with an internal compiler error. clang does not.
GOEXPERIMENT=none CC=clang make TARGET_GOARCH="$GOARCH" LIBPCAP_ARCH="$LIBPCAP_ARCH"; \
CC=clang make TARGET_GOARCH="$GOARCH" LIBPCAP_ARCH="$LIBPCAP_ARCH"; \
file pwru | grep -q 'ELF'; \
# the binary must start; a broken crypto backend or link crashes here
./pwru --version
Expand Down
4 changes: 2 additions & 2 deletions test/image/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# build stage
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.26-azurelinux3.0@sha256:7e3429507d92bb1e12fe45b7650c3dd3f24a4f0d1ca45622b1452834f54d8020 AS builder
# skopeo inspect docker://mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0 --format "{{.Name}}@{{.Digest}}"
FROM mcr.microsoft.com/oss/go/microsoft/golang:1.27-azurelinux3.0@sha256:0452a87b996c31987d673fda2fe348b7c61c190509a63a421dbb482be101d1da AS builder
ENV CGO_ENABLED=1
COPY . /go/src/github.com/microsoft/retina
WORKDIR /go/src/github.com/microsoft/retina
Expand Down
Loading