[PR #5172] [CLOSED] feat(build): Add multi-stage Dockerfile for management server #27275

Open
opened 2026-08-05 07:08:28 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/5172
Author: @obtFusi
Created: 1/24/2026
Status: Closed

Base: mainHead: feature/multistage-dockerfile


📝 Commits (10+)

  • dfcaebe ci: add GitHub configuration from network-agent pattern
  • 3d1defe Merge pull request #1 from obtFusi/ci/github-config
  • b036814 feat(auth): Add mTLS authentication for Machine Tunnel (S-1 Spikes)
  • 634bd3c chore: add AUDIT files to gitignore
  • 5357588 feat(spike): Add S-1 Windows mTLS spikes - CNG signer and SAN parser
  • e594b07 feat(lab): Add CA bootstrap and verification scripts
  • f52cd3d fix(lab): Fix verify-lab-ca.ps1 parsing bugs
  • 6f72ca7 feat(proto): Generate Go code for Machine Tunnel RPCs
  • a4deec3 feat(mtls): Add per-account AllowedDomains for multi-tenant isolation
  • 648b532 feat(mtls): Add Machine Tunnel RPC handlers (T-3.6)

📊 Changes

51 files changed (+7388 additions, -1912 deletions)

View changed files

.githooks/pre-commit (+31 -0)
.github/ISSUE_TEMPLATE/bug_report.md (+29 -0)
.github/ISSUE_TEMPLATE/config.yml (+8 -0)
.github/ISSUE_TEMPLATE/epic.md (+39 -0)
📝 .github/ISSUE_TEMPLATE/feature_request.md (+2 -2)
.github/ISSUE_TEMPLATE/story.md (+32 -0)
.github/ISSUE_TEMPLATE/task.md (+31 -0)
.github/dependabot.yml (+31 -0)
.github/workflows/auto-label.yml (+97 -0)
.github/workflows/pr-lint.yml (+36 -0)
📝 .gitignore (+48 -1)
📝 Makefile (+51 -2)
docs/ADR-001-mTLS-Port-Strategy.md (+139 -0)
docs/ADR-002-CNG-Signer-Interface.md (+132 -0)
management/Dockerfile.multistage (+13 -0)
📝 management/internals/server/boot.go (+131 -5)
📝 management/internals/server/config/config.go (+27 -0)
management/internals/server/mtls_auth.go (+679 -0)
management/internals/server/mtls_auth_test.go (+605 -0)
management/internals/server/mtls_server.go (+223 -0)

...and 31 more files

📄 Description

Summary

  • Adds Dockerfile.multistage for building management server with correct binary format
  • Solves ar archive issue (binary was library instead of executable)

Problem

Building with go build ./management/cmd/ produced an ar archive because cmd/ has package cmd, not package main.

Solution

  • Use ./management/ which has main.go with package main
  • Multi-stage build inside golang:1.25 container
  • No cross-compilation issues

Usage

docker build -f management/Dockerfile.multistage -t netbird-fork/management:latest .

Test plan

  • Binary is ELF executable (verified with file command)
  • Container starts successfully
  • mTLS server runs on port 33074
  • Deployed and tested on lab (10.0.0.103)

Relates to: #93

🤖 Generated with Claude Code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added mTLS certificate-based authentication for machine peers with dedicated registration and management endpoints.
    • Introduced automated dependency updates via Dependabot configuration.
    • Added GitHub issue templates for structured bug reports, features, epics, stories, and tasks.
  • CI/CD Improvements

    • Implemented automatic issue and pull request labeling based on title analysis.
    • Added pull request linting to enforce consistent commit message conventions.
    • Configured pre-commit hooks for code quality checks.
  • Build & Infrastructure

    • Enhanced build system with multi-platform cross-compilation support.
    • Added containerized management service deployment.
    • Introduced lab automation scripts for testing environments.

✏️ Tip: You can customize this high-level summary in your review settings.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/5172 **Author:** [@obtFusi](https://github.com/obtFusi) **Created:** 1/24/2026 **Status:** ❌ Closed **Base:** `main` ← **Head:** `feature/multistage-dockerfile` --- ### 📝 Commits (10+) - [`dfcaebe`](https://github.com/netbirdio/netbird/commit/dfcaebe41c86a8aadccc35876b55a2f4d8361bed) ci: add GitHub configuration from network-agent pattern - [`3d1defe`](https://github.com/netbirdio/netbird/commit/3d1defea7cece943ec2b11e760478d0c524ae62b) Merge pull request #1 from obtFusi/ci/github-config - [`b036814`](https://github.com/netbirdio/netbird/commit/b036814fdcdf153323cefc3765c9fd40ae428084) feat(auth): Add mTLS authentication for Machine Tunnel (S-1 Spikes) - [`634bd3c`](https://github.com/netbirdio/netbird/commit/634bd3c19ec7831c3390ba88b3435f16ed626b87) chore: add AUDIT files to gitignore - [`5357588`](https://github.com/netbirdio/netbird/commit/535758810ff5885e4444ac30a8b54d7301844af4) feat(spike): Add S-1 Windows mTLS spikes - CNG signer and SAN parser - [`e594b07`](https://github.com/netbirdio/netbird/commit/e594b07f096b340c63b361b24e13d47105d39203) feat(lab): Add CA bootstrap and verification scripts - [`f52cd3d`](https://github.com/netbirdio/netbird/commit/f52cd3d7880e02974d826c5eeb8f55721beef64d) fix(lab): Fix verify-lab-ca.ps1 parsing bugs - [`6f72ca7`](https://github.com/netbirdio/netbird/commit/6f72ca78a1a3817d35ee4078ec2282ab55c61ea5) feat(proto): Generate Go code for Machine Tunnel RPCs - [`a4deec3`](https://github.com/netbirdio/netbird/commit/a4deec3109066e55f11c61f5d999df84a4c2ad4c) feat(mtls): Add per-account AllowedDomains for multi-tenant isolation - [`648b532`](https://github.com/netbirdio/netbird/commit/648b532034cf9d829fdfdad3dab6034fbf0e04a8) feat(mtls): Add Machine Tunnel RPC handlers (T-3.6) ### 📊 Changes **51 files changed** (+7388 additions, -1912 deletions) <details> <summary>View changed files</summary> ➕ `.githooks/pre-commit` (+31 -0) ➕ `.github/ISSUE_TEMPLATE/bug_report.md` (+29 -0) ➕ `.github/ISSUE_TEMPLATE/config.yml` (+8 -0) ➕ `.github/ISSUE_TEMPLATE/epic.md` (+39 -0) 📝 `.github/ISSUE_TEMPLATE/feature_request.md` (+2 -2) ➕ `.github/ISSUE_TEMPLATE/story.md` (+32 -0) ➕ `.github/ISSUE_TEMPLATE/task.md` (+31 -0) ➕ `.github/dependabot.yml` (+31 -0) ➕ `.github/workflows/auto-label.yml` (+97 -0) ➕ `.github/workflows/pr-lint.yml` (+36 -0) 📝 `.gitignore` (+48 -1) 📝 `Makefile` (+51 -2) ➕ `docs/ADR-001-mTLS-Port-Strategy.md` (+139 -0) ➕ `docs/ADR-002-CNG-Signer-Interface.md` (+132 -0) ➕ `management/Dockerfile.multistage` (+13 -0) 📝 `management/internals/server/boot.go` (+131 -5) 📝 `management/internals/server/config/config.go` (+27 -0) ➕ `management/internals/server/mtls_auth.go` (+679 -0) ➕ `management/internals/server/mtls_auth_test.go` (+605 -0) ➕ `management/internals/server/mtls_server.go` (+223 -0) _...and 31 more files_ </details> ### 📄 Description ## Summary - Adds `Dockerfile.multistage` for building management server with correct binary format - Solves ar archive issue (binary was library instead of executable) ## Problem Building with `go build ./management/cmd/` produced an ar archive because `cmd/` has `package cmd`, not `package main`. ## Solution - Use `./management/` which has `main.go` with `package main` - Multi-stage build inside golang:1.25 container - No cross-compilation issues ## Usage ```bash docker build -f management/Dockerfile.multistage -t netbird-fork/management:latest . ``` ## Test plan - [x] Binary is ELF executable (verified with `file` command) - [x] Container starts successfully - [x] mTLS server runs on port 33074 - [x] Deployed and tested on lab (10.0.0.103) Relates to: #93 🤖 Generated with [Claude Code](https://claude.ai/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **New Features** * Added mTLS certificate-based authentication for machine peers with dedicated registration and management endpoints. * Introduced automated dependency updates via Dependabot configuration. * Added GitHub issue templates for structured bug reports, features, epics, stories, and tasks. * **CI/CD Improvements** * Implemented automatic issue and pull request labeling based on title analysis. * Added pull request linting to enforce consistent commit message conventions. * Configured pre-commit hooks for code quality checks. * **Build & Infrastructure** * Enhanced build system with multi-platform cross-compilation support. * Added containerized management service deployment. * Introduced lab automation scripts for testing environments. <sub>✏️ Tip: You can customize this high-level summary in your review settings.</sub> <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 07:08:28 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#27275