chore(go): move the toolchain to Go 1.27 #74

Merged
rcsheets merged 1 commit from chore/go-1.27 into main 2026-09-17 08:40:12 +00:00
Owner

Moves the toolchain floor to Go 1.27: go.mod, the three image builds, and the AGENTS.md repo fact.

Changes

  • go.mod: go 1.26 -> go 1.27.
  • Dockerfile, Dockerfile.cuda: golang:1.26 -> golang:1.27.
  • Dockerfile.cuda-prerelease: golang:1.27-trixie, not the bare tag. It installs NVIDIA's trixie packages, and where golang:1.26 was trixie, the bare golang:1.27 tag resolves to a different base -- so the suffix now carries weight the comment used to get for free.
  • ci.yaml: a step printing go version and go env GOTOOLCHAIN GOPROXY.

Verified locally (go1.27.1)

gofmt, go vet ./..., go test ./..., go build ./..., and the cuda-tagged build all pass.

What this PR's CI run is actually testing

The pool's runner image bundles the toolchain (the workflow sets no container: and no setup step), so no run has ever recorded which Go built it -- hence the new step. That matters because go.mod's directive is only a floor: a runner older than it downloads a toolchain through GOPROXY, which fails closed if the proxy will not serve golang.org/toolchain.

The runner image (forgejo-runner-operator, RUNNER_GO_VERSION) still pins golang:1.26-alpine, and those images are built by hand, so the deployed forgejo-runner-go:12-latest is very likely 1.26. I could not confirm it: Harbor needs credentials, and Athens refuses requests from outside the cluster (403 on everything, /healthz included), so whether it serves toolchain modules in-cluster is unknown from here.

So this run resolves it either way:

  • passes -- the runner is already 1.27, or it downloaded 1.27 through Athens. Nothing else to do.
  • fails on the toolchain -- bump RUNNER_GO_VERSION to 1.27-alpine in forgejo-runner-operator (plus the README row), rebuild and push forgejo-runner-go:12-latest, restart the pool, then re-run this PR.

🤖 Generated with Claude Code

Moves the toolchain floor to **Go 1.27**: `go.mod`, the three image builds, and the AGENTS.md repo fact. ## Changes - `go.mod`: `go 1.26` -> `go 1.27`. - `Dockerfile`, `Dockerfile.cuda`: `golang:1.26` -> `golang:1.27`. - `Dockerfile.cuda-prerelease`: `golang:1.27-trixie`, **not** the bare tag. It installs NVIDIA's trixie packages, and where `golang:1.26` was trixie, the bare `golang:1.27` tag resolves to a different base -- so the suffix now carries weight the comment used to get for free. - `ci.yaml`: a step printing `go version` and `go env GOTOOLCHAIN GOPROXY`. ## Verified locally (go1.27.1) `gofmt`, `go vet ./...`, `go test ./...`, `go build ./...`, and the `cuda`-tagged build all pass. ## What this PR's CI run is actually testing The pool's runner image bundles the toolchain (the workflow sets no `container:` and no setup step), so **no run has ever recorded which Go built it** -- hence the new step. That matters because `go.mod`'s directive is only a floor: a runner older than it downloads a toolchain through `GOPROXY`, which fails closed if the proxy will not serve `golang.org/toolchain`. The runner image (`forgejo-runner-operator`, `RUNNER_GO_VERSION`) still pins `golang:1.26-alpine`, and those images are built by hand, so the deployed `forgejo-runner-go:12-latest` is very likely 1.26. I could not confirm it: Harbor needs credentials, and Athens refuses requests from outside the cluster (403 on everything, `/healthz` included), so whether it serves toolchain modules in-cluster is unknown from here. So this run resolves it either way: - **passes** -- the runner is already 1.27, or it downloaded 1.27 through Athens. Nothing else to do. - **fails** on the toolchain -- bump `RUNNER_GO_VERSION` to `1.27-alpine` in `forgejo-runner-operator` (plus the README row), rebuild and push `forgejo-runner-go:12-latest`, restart the pool, then re-run this PR. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
chore(go): move the toolchain to Go 1.27
All checks were successful
ci / test_and_build (pull_request) Successful in 1m51s
2a09a8085d
go.mod's floor, the three image builds, and the AGENTS.md repo fact all move
from 1.26 to 1.27. Verified locally on go1.27.1: gofmt, vet, the full test
suite, the pure-Go build, and the cuda-tagged build.

Dockerfile.cuda-prerelease pins golang:1.27-trixie rather than the bare tag.
It installs NVIDIA's trixie packages, and where golang:1.26 was trixie, the
bare golang:1.27 tag now resolves to a different base, so the suffix carries
weight the comment used to get for free.

CI prints the toolchain it ran with, which nothing recorded before: the pool's
runner image bundles Go (no container:, no setup step), so a run's Go version
was invisible. It matters here because go.mod's directive is only a floor -- a
runner older than it downloads a toolchain through GOPROXY, and that fails
closed if the proxy does not serve golang.org/toolchain.

The runner image (forgejo-runner-operator, RUNNER_GO_VERSION) still pins
golang:1.26-alpine, so this PR's own CI run is the test of whether that
download path works. If it does not, the runner image needs the same bump
before this can land.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Author
Owner

Blocked on forgejo-runner-operator#53, which builds forgejo-runner-go on Go 1.27.

The CI run here answered the question this PR was opened to settle -- the pool's runner is 1.26 and cannot download a newer toolchain:

go: go.mod requires go >= 1.27 (running go 1.26.5; GOTOOLCHAIN=local)

GOTOOLCHAIN=local comes from the official golang image, so there is no fetch path regardless of what Athens serves. The new "Go toolchain" step is what makes that visible.

Order: merge #53, rebuild and push forgejo-runner-go from main (make container-build-runner-go, then push), get the pool onto the new image (it pins the moving 12-latest with no imagePullPolicy, so IfNotPresent can keep a cached copy -- pinning the immutable 12-<VERSION> tag is the deterministic fix), then re-run this PR.

Blocked on [forgejo-runner-operator#53](https://git.brooktrails.org/brooktrails/forgejo-runner-operator/pulls/53), which builds `forgejo-runner-go` on Go 1.27. The CI run here answered the question this PR was opened to settle -- the pool's runner is 1.26 and cannot download a newer toolchain: ``` go: go.mod requires go >= 1.27 (running go 1.26.5; GOTOOLCHAIN=local) ``` `GOTOOLCHAIN=local` comes from the official `golang` image, so there is no fetch path regardless of what Athens serves. The new "Go toolchain" step is what makes that visible. Order: merge #53, rebuild and push `forgejo-runner-go` from `main` (`make container-build-runner-go`, then push), get the pool onto the new image (it pins the moving `12-latest` with no `imagePullPolicy`, so `IfNotPresent` can keep a cached copy -- pinning the immutable `12-<VERSION>` tag is the deterministic fix), then re-run this PR.
rcsheets deleted branch chore/go-1.27 2026-09-17 08:40:13 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
brooktrails/gllm!74
No description provided.