Skip to content

Fix README enclave build steps - #38

Merged
nickpell merged 4 commits into
mainfrom
nick/readme-enclave-build-steps
Oct 1, 2026
Merged

nickpell merged 4 commits into
mainfrom
nick/readme-enclave-build-steps

Conversation

@nickpell

@nickpell nickpell commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

  • enclave-image/Dockerfile copies a prebuilt ./bin/tee-arbiter-enclave, so the README's docker build fails on a clean checkout with "/bin/tee-arbiter-enclave": not found. The README now runs the go build command from .github/workflows/docker.yml first, with the same flags. The docker build line gets --platform linux/arm64, so the image platform matches the binary, as the workflow's platforms input does. On an amd64 Linux host, the image's RUN steps need arm64 emulation, so the README gives the tonistiigi/binfmt command that docker/setup-qemu-action runs in the workflow.
  • A new .gitignore ignores /bin/, so the README build leaves git status clean. No tracked file lives under a bin/ directory.
  • Fix README enclave build steps and import example openauction#80 makes the same build-step fix in openauction. The two PRs do not depend on each other.

Pre-merge checklist

  • Documented build steps succeed from a clean checkout: the two README commands, run verbatim under bash, build a static linux/arm64 ELF binary and a linux/arm64 image.
  • The README go build line is byte-identical to the one in docker.yml.
  • Go and Docker Build workflows green on this branch: lint, test and Ratchet Lint pass, and Docker Build run 36878534701 built the head commit without publishing. Neither workflow runs the README commands.
  • After the README build, git status --porcelain prints nothing, and git check-ignore matches the binary to /bin/.
  • Diff contains no unintended changes: README.md and .gitignore only.

Not run: the image itself, which needs a Nitro Enclave host, and the emulation command, which needs an amd64 Linux host. The EIF build runs only on main.

Post-deploy/apply verification

  • The next Build EIF run on main after the merge is green, including update-pcrs Run 36916611509 on merge commit 134d1a04 succeeded, and update-pcrs pushed bf5c31e22.

enclave-image/Dockerfile copies a prebuilt ./bin/tee-arbiter-enclave,
so the documented docker build failed on a clean checkout. Add the go
build command from docker.yml and pin the image platform to match
GOARCH.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The instructions omit the ARM64 emulation prerequisite required on common amd64 Linux hosts.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Updates enclave build documentation to reflect the required prebuilt ARM64 binary.

Changes:

  • Adds the workflow-aligned Go build command.
  • Builds the Docker image for linux/arm64.
File Description
README.md Corrects enclave image build instructions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread README.md

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The arm64 emulation prerequisite appears after the Docker command that requires it.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The documentation runs an unpinned third-party image with privileged host access.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

Comment thread README.md

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documented commands align with the workflow and Dockerfile requirements.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@nickpell
nickpell merged commit 134d1a0 into main Oct 1, 2026
4 checks passed
@nickpell
nickpell deleted the nick/readme-enclave-build-steps branch October 1, 2026 19:40
nickpell added a commit to cloudx-io/openauction that referenced this pull request Oct 1, 2026
## Summary

- `enclave/Dockerfile` copies a prebuilt `./bin/tee-auction-enclave`, so
the README's `docker build` fails on a clean checkout with
`"/bin/tee-auction-enclave": not found`. The README now runs the `go
build` command from `.github/workflows/docker.yml` first, with the same
flags and the workflow's default `GOARCH=arm64`. The `docker build` line
gets `--platform linux/arm64`, so the image platform matches the binary,
as the workflow's `platforms` input does. One line gives the amd64
variant that the workflow's manual dispatch offers. On an amd64 Linux
host, the image's `RUN` steps need arm64 emulation, so the README gives
the `tonistiigi/binfmt` command that `docker/setup-qemu-action` runs in
the workflow.
- The usage example no longer imports
`github.com/cloudx-io/openauction/enclave`. That directory is `package
main`, and Go rejects the import: `is a program, not an importable
package`.
- `.gitignore` now ignores `/bin/`, so the README build leaves `git
status` clean. No tracked file lives under a `bin/` directory.
- cloudx-io/openarbiter#38 makes the same build-step fix in openarbiter.
The two PRs do not depend on each other.

## Notes for reviewers

The README's `docker build` line matched the original multi-stage
Dockerfile. #7 moved compilation into `docker.yml`
to make image builds faster and more cacheable, and the README kept the
old step. This PR keeps the prebuilt-binary design and documents the
step it needs.

## Pre-merge checklist

- [x] Documented build steps succeed from a clean checkout: the two
README commands, run verbatim under `bash`, build a static linux/arm64
ELF binary and a `linux/arm64` image. The amd64 variant builds a static
x86-64 binary and a `linux/amd64` image.
- [x] The README `go build` line is byte-identical to the one in
`docker.yml`, with `${ARCHITECTURE}` at its `arm64` default.
- [x] The trimmed import block (`core`, `enclaveapi`) compiles in a
scratch module that replaces `github.com/cloudx-io/openauction` with
this branch. With `enclave` added back, the build fails as described
above.
- [x] Go and Docker Build workflows green on this branch: `lint`, `test`
and `Ratchet Lint` pass, and Docker Build run
[36878528554](https://github.com/cloudx-io/openauction/actions/runs/36878528554)
built the head commit without publishing. Neither workflow runs the
README commands.
- [x] After the README build, `git status --porcelain` prints nothing,
and `git check-ignore` matches the binary to `/bin/`.
- [x] Diff contains no unintended changes: `README.md` and `.gitignore`
only.

Not run: the image itself, which needs a Nitro Enclave host, and the
emulation command, which needs an amd64 Linux host. The EIF build runs
only on `main`.

## Post-deploy/apply verification

- [ ] The next Build EIF run on `main` after the merge is green,
including `update-pcrs`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants