docker: a plain docker build . stamps the git version (closes #210)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
A plain `docker build .`, which is how upaas builds, stamped `dev`: `.dockerignore` left out `.git` and the builder declared `ARG VERSION=dev`. `.dockerignore` now sends `.git` without `.git/config`, which can hold a credential, and lists no tracked file, which git would count as deleted. `ARG VERSION` has no default. The Makefile takes a non-empty `VERSION` from the command line or the environment, so a build arg still wins; otherwise `git describe` runs in the builder, which trusts the checkout whoever owns it, as a context sent as a tar archive keeps its owners. A new `make version` prints the version; the build fails when the context carries `.git` and it comes out empty, `dev` or `unknown`. Model: opus-5-5
This commit was merged in pull request #213.
This commit is contained in:
+25
-5
@@ -24,6 +24,11 @@ FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4
|
||||
|
||||
RUN apk add --no-cache git make gcc musl-dev binutils-gold
|
||||
|
||||
# A build context sent as a tar archive keeps its files' owners, and git
|
||||
# refuses to read a checkout owned by another user. Trust this one
|
||||
# whoever owns it.
|
||||
RUN git config --system --add safe.directory /src
|
||||
|
||||
# Force BuildKit to run the lint stage before proceeding
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
|
||||
@@ -36,11 +41,26 @@ COPY . .
|
||||
# Run the tests - build fails if any test fails
|
||||
RUN make test
|
||||
|
||||
# Build the binary. .dockerignore leaves out .git, so `git describe` in
|
||||
# the Makefile cannot find the version here: script/docker passes it as
|
||||
# --build-arg VERSION, and a build that passes none reports `dev`.
|
||||
ARG VERSION=dev
|
||||
RUN make build VERSION="${VERSION}"
|
||||
# Version stamped into the binary: the VERSION build arg when one is
|
||||
# given and not empty (script/docker passes one), otherwise what
|
||||
# `git describe` says of the .git in the build context, so a plain
|
||||
# `docker build .` of a clone stamps its tag or short commit. The build
|
||||
# arg reaches make through the environment.
|
||||
ARG VERSION
|
||||
|
||||
# A context that carries .git, as a directory or as a file, must yield a
|
||||
# real version: one that is empty, `dev` or `unknown` cannot be traced
|
||||
# back to a commit.
|
||||
RUN version="$(make version)"; \
|
||||
if [ -e .git ]; then \
|
||||
case "$version" in \
|
||||
"" | dev | unknown) \
|
||||
echo "version is \"$version\" although the build context carries .git" >&2; \
|
||||
exit 1 ;; \
|
||||
esac; \
|
||||
fi
|
||||
|
||||
RUN make build
|
||||
|
||||
# Runtime stage
|
||||
# alpine 3.21, 2026-02-28
|
||||
|
||||
Reference in New Issue
Block a user