Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

How should I use vendor in Go 1.6?

Tags:

go

vendor

First I have read this answer: Vendoring in Go 1.6, then I use it as my example.

My gopath is GOPATH="/Users/thinkerou/xyz/", and the follow like:

thinkerou@MacBook-Pro-thinkerou:~/xyz/src/ou$ pwd /Users/baidu/xyz/src/ou thinkerou@MacBook-Pro-thinkerou:~/xyz/src/ou$ ls main.go vendor 

Now, I use go get, then becomes this:

thinkerou@MacBook-Pro-thinkerou:~/xyz/src/ou$ ls main.go vendor thinkerou@MacBook-Pro-thinkerou:~/xyz/src/ou$ cd vendor/ thinkerou@MacBook-Pro-thinkerou:~/xyz/src/ou/vendor$ ls vendor.json thinkerou@MacBook-Pro-thinkerou:~/xyz/src/ou/vendor$ cd ../.. thinkerou@MacBook-Pro-thinkerou:~/xyz/src$ ls github.com ou thinkerou@MacBook-Pro-thinkerou:~/xyz/src$ cd github.com/ thinkerou@MacBook-Pro-thinkerou:~/xyz/src/github.com$ ls zenazn 

vendor.json is this:

{     "comment": "",     "package": [         {             "path": "github.com/zenazn/goji"         }     ] } 

then, I should use what commands? why have no use vendor? My go version is 1.6.2.

like image 575
thinkerou Avatar asked May 15 '16 10:05

thinkerou


People also ask

How does Go mod vendor work?

The go mod vendor command constructs a directory named vendor in the main module's root directory that contains copies of all packages needed to support builds and tests of packages in the main module. Packages that are only imported by tests of packages outside the main module are not included.

Should I commit vendor folder Golang?

The general recommendation is no. The vendor directory (or wherever your dependencies are installed) should be added to . gitignore / svn:ignore /etc. The best practice is to then have all the developers use Composer to install the dependencies.

What is vendor directory in Go?

js land, Golang's vendor directory is basically the same as Node's node_modules . It is a directory found at the root of a Go module that stores a copy of all the code the module depends on. The vendored code is used to compile the final executable when the go build command is run.


1 Answers

With Go1.6, vendoring is built in as you read. What does this mean? Only one thing to keep in mind:

When using the go tools such as go build or go run, they first check to see if the dependencies are located in ./vendor/. If so, use it. If not, revert to the $GOPATH/src/ directory.

The actual "lookup paths" in Go 1.6 are, in order:

./vendor/github.com/zenazn/goji $GOPATH/src/github.com/zenazn/goji $GOROOT/src/github.com/zenazn/goji 

With that said, go get will continue to install into you $GOPATH/src; and, go install will install into $GOPATH/bin for binaries or $GOPATH/pkg for package caching.

So, how do I use ./vendor?!?!

Hehe, armed with the knowledge above, it's pretty simple:

mkdir -p $GOPATH/src/ou/vendor/github.com/zenazn/goji cp -r $GOPATH/src/github.com/zenazn/goji/ $GOPATH/src/ou/vendor/github.com/zenazn/goji 

In short, to use vendoring, you copy the files using the same github.com/zenazn/goji full path, into your vendor director.

Now, the go build/install/run tooling will see and use your vendor folder.

An easier way instead of copying everything manually

Instead of finding and copying all 25+ vendor items, managing their versions, updating other projects etc... It would be better to use a dependency management tool. There are many out there and a little googling will point to you several.

Let me mention two that works with the vendor folder and doesn't fight you:

  • godep
  • govendor

In short, these tools will inspect your ou code, find the remote dependencies, and copy them from your $GOPATH/src to your $GOPATH/src/ou/vendor directory (actually, whatever current directory you are in when you run them).

For example, say you have all of your dependencies installed and working normally in your $GOPATH/src/ou/ project using the normal GOPATH/src/github installation of your dependencies. Your project runs and your tests validate everything is working with the exact version of the repos you have. With Godep as an example, you'd run this from your project root folder $GOPATH/src/ou/:

godep save ./... 

This would copy all dependencies your project uses into your ./vendor folder.

Godep is by far and large the most popular. They have their own Slack channel on the Gopher Slack group. And, it's the one I use on my teams.

Govendor is another alternative I read has a nice sync feature. I haven't used it though.

Over Usage of Dependency Management Tool

This is purely opinion, and I'm sure haters will downvote... But as I need to finish my blog post on the subject, let me mention here that most people worry too much about depdency management in Go.

Yes, there is a need to lock in a repo to a version you depend on so you can ensure your system builds in production. Yes there is a need to ensure no breaking changes to a way a dependency is interrupting something.

Use dependency management for those, absolutely.

But, there is overuse of simple projects that lock in huge amounts of dependencies when in reality...

You may only need to lock in only 1 dependencies; otherwise, you want the latest version of MySQL drivers and test assertion frameworks for bug fixes.

This is where using the ./vendor/ folder apart from dependency managrment tools can really shine: you'd only need to copy that repo that need you lock in.

You selectively pick the one misbehaving repo and put it into your ./vendor/ folder. By doing this, you are telling your consumers:

Hey, this one repo needs to be held back at this revision. All others are fine and use the latest of those and update often with go get -u ./...; but, this one failed with newer versions so don't upgrade this one repo.

But if blanketly saving all your dependencies with a dependency management tool, you are basically telling your consumers:

There may or may not be a problem with one or more repos out of the 20 in the vendor folder. You may or may not be able to update them. You may or may not be able to get the latest MySQL driver. We simply don't know which may or may not be causing problems and just locked in something that worked at the time that I ran godep save. So yeah, upgrade at your own risk.

Personally, I have ran into this several times. A dependency was updated with a breaking change, and we have dozens of repos dependent on it. Vendoring just that one repo in /vendor allows us to use that one version of dependency, while go get ./... continues to run normally for all other repos to get the latest. We run with the latest bug fixes in PSQL and MySQL and others (there are constant fixes for these!) and so on.

like image 130
eduncan911 Avatar answered Oct 02 '22 14:10

eduncan911