go: go.mod requires go >= 1.22 (running go 1.21; GOTOOLCHAIN=local) – choosing toolchain policy
0 reputation · 21 Feb 2023, 14:23 UTC
Teams adopting Go modules for repeatable development must decide how to enforce the toolchain version declared in go.mod. The go directive sets a minimum required version, while the optional toolchain directive can request a specific version when GOTOOLCHAIN=auto. The unresolved decision is whether to lock the toolchain locally (GOTOOLCHAIN=local) to guarantee hermetic builds in CI, or to allow automatic toolchain selection (GOTOOLCHAIN=auto) for developer convenience, accepting that the exact version may vary across machines.
Considerations include network access to the Go mirror, the ability to pre‑install toolchains in air‑gapped environments, and the need to keep go.mod changes under code review when the required version changes.
What policy should CI pipelines use for GOTOOLCHAIN to balance reproducibility and setup simplicity? Should the toolchain directive be treated as a minimum requirement or a preferred version, and how does that affect go.mod updates? How can teams verify that the chosen toolchain setting does not introduce silent version drift in dependency builds?