Stamp the git tag or short commit in a plain docker build (closes #35) #36

Merged
clawbot merged 1 commits from issue-35-docker-version into next 2026-10-02 06:12:06 +02:00
Collaborator

Closes #35. A plain docker build . stamped dev: .dockerignore left out .git, so make build in the image had nothing to describe.

  • .dockerignore now sends .git, minus .git/config, whose remote URL can carry a credential; git describe does not need it.
  • The build stage (alpine, already installs git) takes the VERSION build argument when given, otherwise git describe --tags --always, and fails if the context carries .git and the result is empty, dev or unknown. The value goes in through make build VERSION=..., the existing -X stamping.

What the diff does not show:

  • No --dirty in the image: .gitea is tracked but still left out of the context, so git there sees it as deleted.
  • Without .git and without the argument (a source tarball), the step stamps dev, as the Makefile does; an empty make build VERSION= would stamp an empty version.
  • VERSION goes on the make command line because the Makefile's := ignores one from the environment.
  • The Makefile already runs git describe --tags --always --dirty; script/docker and script/cibuild pass no version, so they now get it from the build. Neither changed.
  • Dockerfile.lint shares .dockerignore, so .git reaches the lint build too.
  • No buildarch in the repo.

Disclosure: REPO_POLICIES.md still shows the old ARG VERSION=dev template; it is the synced canonical copy, changed through sneak/prompts#69.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/keyfunc/issues/35. A plain `docker build .` stamped `dev`: `.dockerignore` left out `.git`, so `make build` in the image had nothing to describe. - `.dockerignore` now sends `.git`, minus `.git/config`, whose remote URL can carry a credential; `git describe` does not need it. - The build stage (alpine, already installs `git`) takes the `VERSION` build argument when given, otherwise `git describe --tags --always`, and fails if the context carries `.git` and the result is empty, `dev` or `unknown`. The value goes in through `make build VERSION=...`, the existing `-X` stamping. What the diff does not show: - No `--dirty` in the image: `.gitea` is tracked but still left out of the context, so git there sees it as deleted. - Without `.git` and without the argument (a source tarball), the step stamps `dev`, as the Makefile does; an empty `make build VERSION=` would stamp an empty version. - `VERSION` goes on the `make` command line because the Makefile's `:=` ignores one from the environment. - The Makefile already runs `git describe --tags --always --dirty`; `script/docker` and `script/cibuild` pass no version, so they now get it from the build. Neither changed. - `Dockerfile.lint` shares `.dockerignore`, so `.git` reaches the lint build too. - No `buildarch` in the repo. Disclosure: `REPO_POLICIES.md` still shows the old `ARG VERSION=dev` template; it is the synced canonical copy, changed through https://git.eeqj.de/sneak/prompts/issues/69. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 05:21:45 +02:00
clawbot self-assigned this 2026-10-02 05:21:45 +02:00
clawbot added 1 commit 2026-10-02 05:21:45 +02:00
.dockerignore left out .git, so make build inside the image fell back to
"dev". The build context now carries .git, without its config, which can
hold a credential in the remote URL. The build stage takes the VERSION
build argument when one is given, otherwise git describe --tags --always,
and fails if the context carries .git and no version comes out.

Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 7f7fe33cd6 into next 2026-10-02 06:12:06 +02:00
clawbot deleted branch issue-35-docker-version 2026-10-02 06:12:06 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/keyfunc#36