Part 9 · 1 chapters · ~8 min

In Production: What Go Is Paired With

The usual Go production stack: static binaries in distroless images, GOMAXPROCS and GOMEMLIMIT in containers, gRPC between services, Envoy and Istio, Prometheus and OpenTelemetry, NATS and Kafka, structured logging with slog, and configuration with envconfig.

15

The stack around a Go service

code
# Dockerfile: build static, run on distroless
FROM golang:1.23 AS build
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o /ledger ./cmd/ledger
FROM gcr.io/distroless/static:nonroot
COPY --from=build /ledger /ledger
USER nonroot
ENTRYPOINT ["/ledger"]
WHAT GO IS PAIRED WITH IN PRODUCTION
a small binary in a small container, inside a mesh
distroless image~15-30 MBKubernetesGOMAXPROCS + GOMEMLIMIT setEnvoy / IstiomTLS, retriesgRPC + protobufbetween servicesPrometheusclient_golang metricsNATS / Kafkaevents
swipe the figure sideways, or tap expand for full screen
1/5
the image
A static Go binary runs in a distroless or scratch image of a few tens of MB: fast pulls, tiny attack surface, starts in milliseconds.
static binary, tiny image, instant startFROM gcr.io/distroless/static