docker: a plain docker build . stamps the git version (closes #210)
check / check (push) Successful in 1m37s
check / check (push) Successful in 1m37s
A plain `docker build .`, which is how upaas builds, stamped `dev`: `.dockerignore` left out `.git` and the builder declared `ARG VERSION=dev`. `.dockerignore` now sends `.git` without `.git/config`, which can hold a credential, and lists no tracked file, which git in the build would count as deleted and mark `-dirty`. `ARG VERSION` has no default. The Makefile takes a non-empty `VERSION` from the command line or the environment, so a build arg still wins (`script/docker` keeps passing one); otherwise `git describe` runs in the builder. A new `make version` prints the version, and the builder fails when the context carries `.git`, directory or file, and it comes out empty, `dev` or `unknown`. Model: opus-5-5
This commit is contained in:
+7
-7
@@ -1,9 +1,9 @@
|
||||
.git/
|
||||
# .git is sent, without its config: the builder stage derives the version it
|
||||
# stamps into the binary from it, and `git describe` does not need the config,
|
||||
# which can hold a credential (a password in the remote URL, a CI token). No
|
||||
# tracked file may be listed here: git in the build would see it as deleted
|
||||
# and mark the version -dirty, and an excluded .md would silently drop out of
|
||||
# the prettier check in Dockerfile.fmt.
|
||||
.git/config
|
||||
bin/
|
||||
node_modules/
|
||||
# No .md may be excluded: Dockerfile.fmt checks every document with
|
||||
# prettier, and an exclusion here would drop a file from that check while
|
||||
# prettier still reports every file it was handed clean.
|
||||
LICENSE
|
||||
.editorconfig
|
||||
.gitignore
|
||||
|
||||
Reference in New Issue
Block a user