Fix README enclave build steps - #38
Merged
Merged
Conversation
enclave-image/Dockerfile copies a prebuilt ./bin/tee-arbiter-enclave, so the documented docker build failed on a clean checkout. Add the go build command from docker.yml and pin the image platform to match GOARCH.
7 tasks done
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The instructions omit the ARM64 emulation prerequisite required on common amd64 Linux hosts.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates enclave build documentation to reflect the required prebuilt ARM64 binary.
Changes:
- Adds the workflow-aligned Go build command.
- Builds the Docker image for
linux/arm64.
| File | Description |
|---|---|
| README.md | Corrects enclave image build instructions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
nickpell
added a commit
to cloudx-io/openauction
that referenced
this pull request
Oct 1, 2026
## Summary - `enclave/Dockerfile` copies a prebuilt `./bin/tee-auction-enclave`, so the README's `docker build` fails on a clean checkout with `"/bin/tee-auction-enclave": not found`. The README now runs the `go build` command from `.github/workflows/docker.yml` first, with the same flags and the workflow's default `GOARCH=arm64`. The `docker build` line gets `--platform linux/arm64`, so the image platform matches the binary, as the workflow's `platforms` input does. One line gives the amd64 variant that the workflow's manual dispatch offers. On an amd64 Linux host, the image's `RUN` steps need arm64 emulation, so the README gives the `tonistiigi/binfmt` command that `docker/setup-qemu-action` runs in the workflow. - The usage example no longer imports `github.com/cloudx-io/openauction/enclave`. That directory is `package main`, and Go rejects the import: `is a program, not an importable package`. - `.gitignore` now ignores `/bin/`, so the README build leaves `git status` clean. No tracked file lives under a `bin/` directory. - cloudx-io/openarbiter#38 makes the same build-step fix in openarbiter. The two PRs do not depend on each other. ## Notes for reviewers The README's `docker build` line matched the original multi-stage Dockerfile. #7 moved compilation into `docker.yml` to make image builds faster and more cacheable, and the README kept the old step. This PR keeps the prebuilt-binary design and documents the step it needs. ## Pre-merge checklist - [x] Documented build steps succeed from a clean checkout: the two README commands, run verbatim under `bash`, build a static linux/arm64 ELF binary and a `linux/arm64` image. The amd64 variant builds a static x86-64 binary and a `linux/amd64` image. - [x] The README `go build` line is byte-identical to the one in `docker.yml`, with `${ARCHITECTURE}` at its `arm64` default. - [x] The trimmed import block (`core`, `enclaveapi`) compiles in a scratch module that replaces `github.com/cloudx-io/openauction` with this branch. With `enclave` added back, the build fails as described above. - [x] Go and Docker Build workflows green on this branch: `lint`, `test` and `Ratchet Lint` pass, and Docker Build run [36878528554](https://github.com/cloudx-io/openauction/actions/runs/36878528554) built the head commit without publishing. Neither workflow runs the README commands. - [x] After the README build, `git status --porcelain` prints nothing, and `git check-ignore` matches the binary to `/bin/`. - [x] Diff contains no unintended changes: `README.md` and `.gitignore` only. Not run: the image itself, which needs a Nitro Enclave host, and the emulation command, which needs an amd64 Linux host. The EIF build runs only on `main`. ## Post-deploy/apply verification - [ ] The next Build EIF run on `main` after the merge is green, including `update-pcrs`
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
enclave-image/Dockerfilecopies a prebuilt./bin/tee-arbiter-enclave, so the README'sdocker buildfails on a clean checkout with"/bin/tee-arbiter-enclave": not found. The README now runs thego buildcommand from.github/workflows/docker.ymlfirst, with the same flags. Thedocker buildline gets--platform linux/arm64, so the image platform matches the binary, as the workflow'splatformsinput does. On an amd64 Linux host, the image'sRUNsteps need arm64 emulation, so the README gives thetonistiigi/binfmtcommand thatdocker/setup-qemu-actionruns in the workflow..gitignoreignores/bin/, so the README build leavesgit statusclean. No tracked file lives under abin/directory.Pre-merge checklist
bash, build a static linux/arm64 ELF binary and alinux/arm64image.go buildline is byte-identical to the one indocker.yml.lint,testandRatchet Lintpass, and Docker Build run 36878534701 built the head commit without publishing. Neither workflow runs the README commands.git status --porcelainprints nothing, andgit check-ignorematches the binary to/bin/.README.mdand.gitignoreonly.Not run: the image itself, which needs a Nitro Enclave host, and the emulation command, which needs an amd64 Linux host. The EIF build runs only on
main.Post-deploy/apply verification
mainafter the merge is green, includingupdate-pcrsRun 36916611509 on merge commit134d1a04succeeded, andupdate-pcrspushedbf5c31e22.