docker: a plain docker build . stamps the git version (closes #210)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
A plain `docker build .`, which is how upaas builds, stamped `dev`: `.dockerignore` left out `.git` and the builder declared `ARG VERSION=dev`. `.dockerignore` now sends `.git` without `.git/config`, which can hold a credential, and lists no tracked file, which git would count as deleted. `ARG VERSION` has no default. The Makefile takes a non-empty `VERSION` from the command line or the environment, so a build arg still wins; otherwise `git describe` runs in the builder, which trusts the checkout whoever owns it, as a context sent as a tar archive keeps its owners. A new `make version` prints the version; the build fails when the context carries `.git` and it comes out empty, `dev` or `unknown`. Model: opus-5-5
This commit was merged in pull request #213.
This commit is contained in:
+2
-2
@@ -14,8 +14,8 @@ main() {
|
||||
cd "$ROOT"
|
||||
# Own line: a failing command substitution inside an argument does
|
||||
# not trip `set -e`, so the inline form degrades silently to an
|
||||
# empty constant. VERSION is computed here because .dockerignore
|
||||
# excludes .git, so `git describe` in a build stage cannot find it.
|
||||
# empty constant. The VERSION build arg takes precedence over what
|
||||
# the build would derive from the .git in its context.
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
docker build --no-cache-filter=lint,builder \
|
||||
|
||||
Reference in New Issue
Block a user