You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Golang Distroless镜像运行报错:stat VERSION不存在及ENTRYPOINT异常

问题排查:Golang二进制Distroless镜像运行异常

我在PopOS 22.04系统中为Golang二进制文件构建Distroless Docker镜像时遇到两个问题:

  • 使用Distroless镜像作为最终层时,运行容器报错:2023/11/25 16:58:50 stat VERSION: no such file or directory
  • 将最终层替换为Alpine镜像后,进入容器能确认二进制文件已复制且可执行,但通过指定的ENTRYPOINT运行时无响应;仅使用builder镜像(设置ENTRYPOINT)时能正常输出帮助信息。

构建与运行命令

构建命令

docker build -t mkm29/gocloak:0.2.2-alpha.7 -f Dockerfile  .

运行命令

docker run --rm mkm29/gocloak:0.2.2-alpha.7 help

正常输出(仅使用builder镜像时)

docker run --rm smigula/gocloak:0.2.2-alpha.8 help                              
gocloak

2023/11/25 21:41:27 Debugging enabled
2023/11/25 21:41:27 Checking variables
Usage:
  gocloak [flags]
  gocloak [command]

Available Commands:
  completion  Generate the autocompletion script for the specified shell
  exportRealm Export a realm from Keycloak
  help        Help about any command
  version     Print the version number of gocloak
...

Dockerfile内容

# Build the binary
ARG BASE_REGISTRY=<NEXUS_URL>
ARG TARGETOS=linux
ARG TARGETARCH=amd64
ARG GIT_COMMIT
ARG GO_VERSION
ARG VERSION
ARG BUILD_DATE
ARG BUILD_PLATFORM="${TARGETOS}/${TARGETARCH}"
ARG MAINTAINER

FROM ${BASE_REGISTRY}/ironbank/google/golang/golang-1.20:1.20.0 as builder
LABEL git-revision=${GIT_COMMIT} \
      version=${VERSION} \
      build-date=${BUILD_DATE} \
      build-platform=${BUILD_PLATFORM} \
      maintainer=${MAINTAINER} \
      go-version=${GO_VERSION}
WORKDIR /workspace
# Copy the Go Modules manifests
COPY go.mod go.mod
# COPY go.sum go.sum
# cache deps before building and copying source so that we don't need to re-download as much
# and so that source changes don't invalidate our downloaded layer
RUN go mod download

# Copy the go source
COPY . .

# Build
# the GOARCH has not a default value to allow the binary be built according to the host where the command
# was called. For example, if we call make docker-build in a local env which has the Apple Silicon M1 SO
# the docker BUILDPLATFORM arg will be linux/arm64 when for Apple x86 it will be linux/amd64. Therefore,
# by leaving it empty we can ensure that the container and binary shipped on it will have the same platform.
RUN CGO_ENABLED=0 GOOS=${TARGETOS:-linux} GOARCH=${TARGETARCH:-amd64} go build -a -o gocloak main.go
#ENV PATH=$PATH:/workspace
#ENTRYPOINT ["/workspace/gocloak"]

# Use distroless as minimal base image to package the manager binary
# Refer to https://github.com/GoogleContainerTools/distroless for more details
# FROM ${BASE_REGISTRY}/ironbank/google/distroless/base:nonroot

FROM gcr.io/distroless/static-debian12:nonroot AS final-image
ARG GIT_COMMIT
ARG GO_VERSION
ARG VERSION
ARG BUILD_DATE
ARG BUILD_PLATFORM
ARG MAINTAINER
LABEL git-revision=${GIT_COMMIT} \
      version=${VERSION} \
      build-date=${BUILD_DATE} \
      build-platform=${BUILD_PLATFORM} \
      maintainer=${MAINTAINER} \
      go-version=${GO_VERSION}
COPY --chown=65532:65532 --from=builder /workspace/gocloak .
USER 65532:65532

ENTRYPOINT ["/gocloak"]

排查方向及解决建议

1. 解决stat VERSION: no such file or directory错误

你的Golang程序启动时会尝试读取当前目录下的VERSION文件,但Distroless镜像仅复制了二进制文件,未包含该文件。

  • 修复方法:在final-image阶段添加复制命令,将VERSION文件同步到镜像中:
    COPY --chown=65532:65532 --from=builder /workspace/VERSION .
    
  • 若VERSION文件是构建时生成的,需确保在builder阶段正确生成该文件后再复制。

2. Alpine镜像下ENTRYPOINT无法运行的问题

Alpine使用musl libc,而你的二进制基于Debian系builder镜像(glibc环境)构建,可能存在兼容性问题。

  • 修复方法:
    • 编译时添加静态链接参数,确保二进制不依赖系统库:
      RUN CGO_ENABLED=0 GOOS=${TARGETOS:-linux} GOARCH=${TARGETARCH:-amd64} go build -a -ldflags '-w -s' -o gocloak main.go
      
    • 或改用Alpine作为builder镜像,保持编译与运行环境一致:
      FROM golang:1.20-alpine as builder
      RUN apk add --no-cache git
      WORKDIR /workspace
      COPY go.mod go.mod
      RUN go mod download
      COPY . .
      RUN CGO_ENABLED=0 GOOS=${TARGETOS:-linux} GOARCH=${TARGETARCH:-amd64} go build -a -o gocloak main.go
      

3. 验证二进制文件路径

在final-image阶段,你将二进制复制到当前目录(.),但ENTRYPOINT指定的是/gocloak,可能存在路径不匹配的问题。可修改COPY命令直接指定目标路径:

COPY --chown=65532:65532 --from=builder /workspace/gocloak /gocloak

内容的提问来源于stack exchange,提问作者user1314147

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 11:35:55