
go-tool-base
The framework the rest of the estate is extracted from: everything a Go application needs around the part that's actually yours, whether it runs for a second or a month.
Matt Cockayne · building in the open since 2012
I'm Matt Cockayne. I build Go and Rust tooling, and the infrastructure that makes a release something you can prove came from you. Twenty years of it, most of it in the parts other people build on.

Showcases

The framework the rest of the estate is extracted from: everything a Go application needs around the part that's actually yours, whether it runs for a second or a month.
Release signing whose private key never leaves your key store, verification that cross-checks two places an attacker would have to break at once, and encrypted reports nobody holds the key to.
Current FFmpeg as a sandboxed WebAssembly engine and as a native driver built from the same code, run from a Go program with no CGO, nothing to install and no temp files, and every artefact signed.
If you only read five
Five posts that between them cover most of what this is: how the tooling works, what I think about the industry, and why any of it exists.
Latest
Or take a whole subject
The blog runs newest-first, which is right for reading along and no use at all if you have turned up with a problem. Each of these is one subject, start to finish, in the order it makes sense.

He answers questions about the projects on the Discord, and he is better at it than I am after nine o'clock. Bring a bug, an idea, or a questionable engineering decision.