docker: a plain docker build . stamps the git version (closes #210)
check / check (push) Failing after 1m54s
check / check (push) Failing after 1m54s
A plain `docker build .`, which is how upaas builds, stamped `dev`: `.dockerignore` left out `.git` and the builder declared `ARG VERSION=dev`. `.dockerignore` now sends `.git` without `.git/config`, which can hold a credential, and lists no tracked file, which git in the build would count as deleted and mark `-dirty`. `ARG VERSION` has no default. The Makefile takes a non-empty `VERSION` from the command line or the environment, so a build arg still wins (`script/docker` keeps passing one); otherwise `git describe` runs in the builder. A new `make version` prints the version, and the builder fails when the context carries `.git`, directory or file, and it comes out empty, `dev` or `unknown`. Model: opus-5-5
This commit is contained in:
@@ -574,6 +574,7 @@ provide:
|
||||
|
||||
```sh
|
||||
make build # Build binary to bin/dnswatcher
|
||||
make version # Print the version make build stamps
|
||||
make test # Run tests with race detector
|
||||
make lint # Run golangci-lint in Docker (requires docker)
|
||||
make fmt # Format code and Markdown (requires docker)
|
||||
@@ -584,13 +585,22 @@ make clean # Remove build artifacts
|
||||
### Build-Time Variables
|
||||
|
||||
`make build` sets the version with `-ldflags "-X main.Version=..."`, taking it
|
||||
from `git describe --tags --always --dirty`, or from `VERSION` when given on the
|
||||
command line (`make build VERSION=1.2.3`). The version appears in the startup
|
||||
log and in the health check response.
|
||||
from `VERSION` when given on the command line (`make build VERSION=1.2.3`) or in
|
||||
the environment, otherwise from `git describe --tags --always --dirty`, and
|
||||
`dev` without git metadata. An empty `VERSION` counts as not given. The version
|
||||
appears in the startup log and in the health check response.
|
||||
|
||||
The Docker image has no `.git`, so the `Dockerfile` takes the version as
|
||||
`--build-arg VERSION`. `make docker` passes it; a plain `docker build` passes
|
||||
none, and that image reports `dev`.
|
||||
The image takes it the same way, from the `.git` the build context carries, so a
|
||||
plain `docker build .` of a clone stamps the commit it was built from; a clone
|
||||
without tags stamps the short commit. A shallow clone carries only a tag on its
|
||||
own commit, so a shallow clone of an untagged commit stamps the short commit.
|
||||
`.dockerignore` sends `.git` without `.git/config`, which `git describe` does
|
||||
not need and which can hold a credential. A non-empty `--build-arg VERSION=...`
|
||||
takes precedence; `make docker` passes the version `git describe` gives on the
|
||||
host. The build fails when the context carries `.git`, as a directory or as a
|
||||
file, and the version comes out empty, `dev` or `unknown`. `.dockerignore` must
|
||||
list no tracked file: git in the build would see it as deleted and mark the
|
||||
version `-dirty`.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user