# Hugo static-site build image. The build runs `make check` (a clean # `hugo --minify` production build, the `--printPathWarnings` lint # build, then the read-only prettier docs check), so the image build # fails on any formatting or Hugo build error. This is what CI # (script/cibuild) runs on every push. # alpine 3.21, 2026-02-28 FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709 WORKDIR /src # Install build dependencies first so the layer caches until the # scripts change (script/bootstrap installs git, make, go, hugo, # node/npm). Hugo is not an apk package here: script/bootstrap builds # the exact pinned version with `go install`, hash-verified against # sum.golang.org, so the published artifact does not depend on whatever # hugo this base image's repos happen to serve. COPY script/ script/ RUN script/bootstrap COPY . . # Run all checks - build fails if any check fails. RUN make check