check / check (push) Successful in 2m43s
`.dockerignore`, `.gitignore`, `.golangci.yml` and the workflow are their copies at that commit. This repo's own entries are kept after the canonical content: the anchored `/attrsum` binary, the Go entries in `.gitignore`, and tabs for `*.go` in the new `.editorconfig`. `REPO_POLICIES.md` is new. The workflow keeps `fetch-depth: 0`, which the policies require of a repo that stamps a tag-derived version. The lint phase moves to golangci-lint v2.14.0, which finds nothing in the code. `script/fmt` now runs goimports with `go run` at its pinned commit. A version-checked install by `script/bootstrap` would have to be found on `PATH`, and the CI runner's `PATH` lacks Go's bin directory. Model: opus-5-5
67 lines
2.5 KiB
Docker
67 lines
2.5 KiB
Docker
# Lint phase
|
|
# golangci/golangci-lint:v2.14.0, 2026-10-06
|
|
FROM golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f AS lint
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN golangci-lint run --config .golangci.yml ./...
|
|
|
|
# Test phase. -race needs cgo and so a C compiler, which the Debian Go
|
|
# image ships and the alpine one does not. The tests run as an
|
|
# unprivileged user: root can read a file with mode 0000, so the
|
|
# permission tests would fail.
|
|
# golang:1.25.7-trixie, 2026-10-06
|
|
FROM golang@sha256:2b174ffcf56c7ad0c47d30d2630693265639ddf2a5141149c2da34db921791b4 AS test
|
|
RUN useradd --create-home testuser
|
|
USER testuser
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
RUN go test -timeout 90s -race -cover ./... || \
|
|
{ echo "--- Rerunning with -v for details ---"; \
|
|
go test -timeout 90s -race -v ./...; exit 1; }
|
|
|
|
# Build stage. Nothing is wanted from either phase above; the copies
|
|
# are what make BuildKit build them first, so this stage cannot run
|
|
# unless lint and test passed.
|
|
# golang 1.25-alpine, 2026-02-28
|
|
FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder
|
|
COPY --from=lint /src/go.sum /dev/null
|
|
COPY --from=test /src/go.sum /dev/null
|
|
RUN apk add --no-cache git make
|
|
# A tar-stream context keeps the sender's file owners, which git refuses.
|
|
RUN git config --system --add safe.directory /src
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
|
|
# The version stamped into the binary: the VERSION build argument when one
|
|
# is given, otherwise `git describe --tags --always` of the .git the build
|
|
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
|
|
# one, the short commit when no tag is reachable. A context that carries .git
|
|
# and still yields no version fails the build. With neither, as from a source
|
|
# tarball, the binary reports dev.
|
|
ARG VERSION
|
|
RUN version="${VERSION:-$(git describe --tags --always)}"; \
|
|
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
|
[ "$version" = unknown ]; }; then \
|
|
echo "version is '$version' although .git is present" >&2; \
|
|
exit 1; \
|
|
fi; \
|
|
make build VERSION="${version:-dev}"
|
|
|
|
# Runtime stage
|
|
# alpine 3.21, 2026-02-28
|
|
FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
|
|
|
RUN apk add --no-cache ca-certificates tzdata
|
|
|
|
WORKDIR /app
|
|
|
|
COPY --from=builder /src/attrsum /app/attrsum
|
|
|
|
ENTRYPOINT ["/app/attrsum"]
|