Build a multi-arch Image from the Pin and smoke-test it locally #4

Closed
opened 2026-09-30 13:14:52 +00:00 by piscis · 0 comments
Owner

What to build

The tracer bullet. Add the Pin (Upstream Version v3.2.0, the commit that tag points to, Rebuild 1) and our own Dockerfile. One local command builds the Image for linux/amd64 and linux/arm64 from the canonical Upstream (git.b4mad.industries/agentic-forges/forgejo-mcp) at the pinned tag.

  • Commit check: the build fails if the tag no longer resolves to the pinned commit.
  • Compilation: Go is cross-compiled natively for each architecture, without QEMU in the compile step. It uses the same version ldflags as Upstream, so the binary reports the Upstream Version.
  • Runtime: a minimal static base running as non-root. ENTRYPOINT is the server and the default CMD selects the stdio transport. No Forgejo URL or token is baked in.
  • Metadata: OCI labels for source (the Upstream tag), version, revision (the Upstream commit) and license GPL-3.0, plus Upstream's LICENSE file inside the Image.

A second local command runs the smoke test against each architecture. It starts the Image over stdio with no token, sends an MCP initialize followed by tools/list, and asserts the tool list is not empty. This smoke test is reused by CI later, so it needs to be a standalone script, not inlined in a workflow.

Acceptance criteria

  • The Pin is a single file that both the build and (later) CI read
  • A local command builds both architectures successfully on an arm64 Mac
  • Changing the pinned commit to a wrong value makes the build fail with a clear message
  • The Image runs as a non-root user, and --version reports 3.2.0
  • The smoke test passes for amd64 and arm64, and fails if the tool list is empty or the server doesn't answer
  • OCI labels and the LICENSE file are present in the Image

Blocked by

  • None (can start immediately)

Context: see GLOSSARY.md (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and docs/adr/ (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags).

## What to build The tracer bullet. Add the Pin (Upstream Version `v3.2.0`, the commit that tag points to, Rebuild `1`) and our own Dockerfile. One local command builds the Image for linux/amd64 and linux/arm64 from the canonical Upstream (`git.b4mad.industries/agentic-forges/forgejo-mcp`) at the pinned tag. - **Commit check:** the build fails if the tag no longer resolves to the pinned commit. - **Compilation:** Go is cross-compiled natively for each architecture, without QEMU in the compile step. It uses the same version ldflags as Upstream, so the binary reports the Upstream Version. - **Runtime:** a minimal static base running as non-root. ENTRYPOINT is the server and the default CMD selects the stdio transport. No Forgejo URL or token is baked in. - **Metadata:** OCI labels for source (the Upstream tag), version, revision (the Upstream commit) and license `GPL-3.0`, plus Upstream's LICENSE file inside the Image. A second local command runs the **smoke test** against each architecture. It starts the Image over stdio with no token, sends an MCP `initialize` followed by `tools/list`, and asserts the tool list is not empty. This smoke test is reused by CI later, so it needs to be a standalone script, not inlined in a workflow. ## Acceptance criteria - [ ] The Pin is a single file that both the build and (later) CI read - [ ] A local command builds both architectures successfully on an arm64 Mac - [ ] Changing the pinned commit to a wrong value makes the build fail with a clear message - [ ] The Image runs as a non-root user, and `--version` reports `3.2.0` - [ ] The smoke test passes for amd64 and arm64, and fails if the tool list is empty or the server doesn't answer - [ ] OCI labels and the LICENSE file are present in the Image ## Blocked by - None (can start immediately) Context: see `GLOSSARY.md` (Upstream, Upstream Version, Image, Rebuild, Consumer, Pin) and `docs/adr/` (0001 build from Upstream source for multi-arch, 0002 canonical Upstream not the Codeberg mirror, 0003 tag scheme and immutable Rebuild tags).
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Blocks
Reference
vicoli-oss/docker-forgejo-mcp#4
No description provided.