diff --git a/.project-docs/30-worklog/tasks/20260815-go-mod-download-timeout-5b8e2c.md b/.project-docs/30-worklog/tasks/20260815-go-mod-download-timeout-5b8e2c.md new file mode 100644 index 0000000..8a88c42 --- /dev/null +++ b/.project-docs/30-worklog/tasks/20260815-go-mod-download-timeout-5b8e2c.md @@ -0,0 +1,54 @@ +# Task: Diagnose Go module download timeout during Docker build + +## Identity + +- Task ID: 20260815-go-mod-download-timeout-5b8e2c +- Mode: Feature +- Branch: main +- Worktree: D:\Datas\OthersProjects\NianAIGC +- Base commit: 9f40162c6be33797792a447fbda3843faf4621e5 +- Owner: codex +- Status: Ready for Integration + +## Scope + +- Diagnose the Jenkins Docker build failure at `backend/Dockerfile:20` without changing application or deployment code. +- Verify whether `github.com/jackc/pgpassfile@v1.0.0` is invalid or whether the failure is limited to dependency-network access. +- Identify the repository-supported build path for China-hosted CI and provide a target-environment verification command. +- Make the standard Go Docker build use a China-reachable, integrity-checked module source by default while allowing CI to override it. + +## Intent And Constraints + +- Treat the supplied Jenkins log as the production-environment failure artifact and keep confirmed repository facts separate from target-network assumptions. +- Keep the implementation surgical: change only the standard Go Docker build configuration and its task record; Jenkins configuration is outside this repository. +- Do not weaken module integrity checks (`go.sum`/`GOSUMDB`) to work around a transport timeout. + +## Outcome + +- The failure occurs before compilation while the standard `backend/Dockerfile` runs `go mod download`; its build stage has no `GOPROXY` override and therefore attempted `https://proxy.golang.org`. +- The failing module is a valid indirect dependency of `github.com/jackc/pgx/v5@v5.5.5`, and both its module and checksum entries are present. +- A cold download of the failing module and then the complete module set succeeded through `https://goproxy.cn,direct`; the individual fetch completed in 0.18 seconds and the complete set in 1 second in the diagnostic environment. +- The repository already supplies `backend/Dockerfile.alpine` as the recommended China-CI build. It uses the Aliyun Alpine package mirror, `GOPROXY=https://goproxy.cn,direct`, and `GOSUMDB=sum.golang.google.cn`. +- Updated the standard `backend/Dockerfile` to use the same integrity-checked Go module endpoints by default and expose `GOPROXY`/`GOSUMDB` as build arguments for internal or global proxy overrides. +- No application, deployment manifest, dependency, checksum, or CI file was changed. + +## Verification + +- Confirmed that the supplied `Dockerfile:20` location matches `backend/Dockerfile` and that `backend/Dockerfile.alpine` places its module download at line 17. +- Ran a fresh-cache `go mod download -x github.com/jackc/pgpassfile@v1.0.0` through `goproxy.cn`: exit 0. +- Ran a fresh-cache full `go mod download` through `goproxy.cn`: exit 0. +- Confirmed with `go mod graph` that `pgx/v5@v5.5.5` depends on `pgpassfile@v1.0.0`. +- Static Dockerfile contract check passed: both proxy arguments and their environment bindings precede `RUN go mod download`. +- `go test ./...` passed for all 19 Go packages, and `go vet ./...` passed. +- Re-ran a fresh-cache full module download using the new defaults: exit 0. +- Ran `go mod verify`: all downloaded modules verified. +- Could not run a full Docker image build because the local Docker Desktop Linux daemon is unavailable; the Jenkins-node rerun remains the authoritative end-to-end check. + +## Follow-ups + +- Re-run the existing standard Docker build on the Jenkins agent; `backend/Dockerfile.alpine` remains the more self-contained fallback when Alpine package downloads also need an Aliyun mirror. +- If that command still times out, test HTTPS egress/DNS from the Jenkins Docker build network to `mirrors.aliyun.com`, `goproxy.cn`, and `sum.golang.google.cn`, or use the organization's internal Go module proxy. + +## Promotion Candidates + +- None recorded. diff --git a/backend/Dockerfile b/backend/Dockerfile index caac47e..628b92d 100644 --- a/backend/Dockerfile +++ b/backend/Dockerfile @@ -6,6 +6,7 @@ # docker build -f backend/Dockerfile \ # --build-arg GOLANG_IMAGE=/golang:1.21-alpine \ # --build-arg RUNTIME_IMAGE=/alpine:3.20 \ +# --build-arg GOPROXY=https://,direct \ # -t REGISTRY/PROJECT/zhinian-go-api:TAG backend/ # # If no mirror can serve the golang image at all, use backend/Dockerfile.runtime @@ -15,7 +16,12 @@ ARG RUNTIME_IMAGE=alpine:3.20 FROM ${GOLANG_IMAGE} AS build WORKDIR /src -ENV CGO_ENABLED=0 GOOS=linux +ARG GOPROXY=https://goproxy.cn,direct +ARG GOSUMDB=sum.golang.google.cn +ENV CGO_ENABLED=0 \ + GOOS=linux \ + GOPROXY=${GOPROXY} \ + GOSUMDB=${GOSUMDB} COPY go.mod go.sum ./ RUN go mod download COPY . .