check / check (push) Successful in 59s
attrsum --version now prints the git tag or short commit. make build stamps it with -X from git describe, and the Dockerfile takes the VERSION build argument when given, otherwise git describe --tags --always on the .git in the build context, failing if .git is present and no version comes out. A new .dockerignore, the canonical one, keeps .git/config out of the context, and also this repo's host-built /attrsum. CI checks out full history so it sees the 1.0.0 tag and stamps what a full clone does. script/docker is replaced with the canonical copy. Model: opus-5-5
59 lines
2.1 KiB
Docker
59 lines
2.1 KiB
Docker
# Build stage
|
|
# golang 1.25-alpine, 2026-02-28
|
|
FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder
|
|
|
|
RUN apk add --no-cache git make gcc musl-dev binutils-gold
|
|
|
|
# golangci-lint v2.10.1
|
|
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@5d1e709b7be35cb2025444e19de266b056b7b7ee
|
|
# goimports v0.42.0
|
|
RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0
|
|
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
|
|
# Run the checks as an unprivileged user. Root bypasses file mode bits, which
|
|
# would make the permission tests (expecting EACCES on a 0000 file) spuriously
|
|
# pass with no error. Caches live under /tmp (world-writable) so the user needs
|
|
# no home directory of its own.
|
|
ENV GOCACHE=/tmp/gocache
|
|
ENV XDG_CACHE_HOME=/tmp/xdgcache
|
|
RUN adduser -D -u 1000 builder && chown -R builder:builder /src /go
|
|
USER builder
|
|
|
|
# Run all checks - build fails if any check fails
|
|
RUN make check
|
|
|
|
# Build the binary (still as the unprivileged user: it owns /src, so git VCS
|
|
# stamping sees consistent ownership).
|
|
#
|
|
# The version stamped into the binary: the VERSION build argument when one
|
|
# is given, otherwise `git describe --tags --always` of the .git the build
|
|
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
|
|
# one, the short commit when no tag is reachable. A context that carries .git
|
|
# and still yields no version fails the build. With neither, as from a source
|
|
# tarball, the binary reports dev.
|
|
ARG VERSION
|
|
RUN version="${VERSION:-$(git describe --tags --always)}"; \
|
|
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
|
[ "$version" = unknown ]; }; then \
|
|
echo "version is '$version' although .git is present" >&2; \
|
|
exit 1; \
|
|
fi; \
|
|
make build VERSION="${version:-dev}"
|
|
|
|
# Runtime stage
|
|
# alpine 3.21, 2026-02-28
|
|
FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
|
|
|
RUN apk add --no-cache ca-certificates tzdata
|
|
|
|
WORKDIR /app
|
|
|
|
COPY --from=builder /src/attrsum /app/attrsum
|
|
|
|
ENTRYPOINT ["/app/attrsum"]
|