Files
lora.vegas/TODO.md
sneak 4720c40cfa Install Hugo at a deliberate, hash-verified version (closes #26)
script/bootstrap did `pkg_install hugo hugo hugo hugo`, so the tool that
produces the published artifact was whatever the base image's package
repo happened to serve: alpine 3.21 gives hugo 0.139.0, about two years
behind upstream, chosen by nobody, and liable to change silently on any
base image digest bump. Hugo's version is a property of the site's
output, not of the build environment, so it now gets pinned like every
other external reference in this repo.

It is installed with `go install github.com/gohugoio/hugo@v0.164.0`,
which verifies the module against the sum.golang.org checksum database.
That is genuine hash verification rather than bare version pinning, it
is the mechanism REPO_POLICIES.md already names for Go, and it needs no
hand-maintained sha256. It also keeps a single pinned base image: a
digest-pinned Hugo container would have reintroduced the second base
image that #7 deliberately removed.

Two constants carry the decision, each with the canonical
`# name version, YYYY-MM-DD` comment:

  - HUGO_VERSION=v0.164.0, the current stable release.
  - HUGO_GOTOOLCHAIN=go1.26.5. hugo v0.164.0's go.mod requires
    go >= 1.26.0 and alpine 3.21's go package is 1.23.9 built with
    GOTOOLCHAIN=local, so a bare `go install` refuses to run at all.
    Naming the toolchain makes Go fetch it through the module proxy and
    verify it against sum.golang.org like any other module, so the chain
    stays hash-verified end to end and the compiler is deliberate too.

CGO_ENABLED=0 is deliberate: standard Hugo, not extended. Verified that
this site uses nothing extended provides - no .scss/.sass, no
resources.ToCSS, no PostCSS, and no image processing; the CSS is plain
and inlined by readFile in baseof.html. The `+extended` on the apk build
this replaces was incidental, and the script says so, so a later change
does not assume extended is required.

The binary is placed in /usr/local/bin rather than left in a GOPATH bin
directory, because it has to be on the default PATH of a *fresh* shell:
the Dockerfile's `RUN make check` and deploy.yml's `script/test` step
each start their own shell. The location is overridable via
HUGO_BIN_DIR for unprivileged installs, and `go install` itself runs as
the invoking user so a workstation's module cache is not populated as
root.

The idempotency guard is version-aware instead of `missing hugo`: an
older hugo already on PATH must be replaced, not accepted, or the pin
means nothing. A same-version build that happens to be `+extended` is
accepted, since it renders this site identically. After installing, the
script re-checks what `hugo` on PATH actually resolves to and fails
loudly if something else shadows it.

Rendered output was compared three ways in a container carrying both
binaries - apk 0.139.0 against 0.164.0 on identical sources. Across the
whole public/ tree the only byte that differs is the generator meta
tag's version string, which is the change describing itself. The RSS
<language> element and the html lang attribute are unchanged.

Cold `script/cibuild` is 2m36s, within the five-minute budget: 52.6s of
it is the bootstrap layer (apk go, toolchain fetch, compile) and 100s is
image export. The check image grows to 683 MB because the Go toolchain
and module cache stay in the bootstrap layer; that image is only ever
built to run checks, never published or deployed.
2026-08-09 14:41:14 +00:00

4.9 KiB

Workflow

  • branch (from main)
  • do the work in Next Step
  • move Next Step to the top of Completed Steps
  • move the top item of Future Steps into Next Step
  • commit (TODO.md changes in the same commit as the work)
  • merge to main if the branch is not protected, otherwise open a PR
  • push

Status

pre-1.0

No git tags. The site is live and now has the scripts-to-rule-them-all scaffold (Makefile, script/, Dockerfile, check.yml); still missing LICENSE and policy files. Every external reference in the repo is now pinned by cryptographic hash (or, for the wrangler CLI install, an exact version), and the Hugo that builds the published site is a deliberate pinned version rather than whatever the base image's package repo serves.

Next Step

Add the remaining policy scaffold: LICENSE, REPO_POLICIES.md, .editorconfig, and prettier config files (.prettierrc, .prettierignore). Update README.md accordingly.

Completed Steps

  • 2026-08-09: installed Hugo at a deliberate, hash-verified version instead of taking whatever alpine ships (closes #26). script/bootstrap no longer does pkg_install hugo; it installs github.com/gohugoio/hugo@v0.164.0 with go install, which verifies the module against sum.golang.org. The version is a commented constant, as is the Go toolchain (go1.26.5) — hugo v0.164.0 requires go >= 1.26.0 and alpine 3.21 ships go 1.23.9 with GOTOOLCHAIN=local, so a bare go install refuses to run. CGO_ENABLED=0 is deliberate: standard Hugo, not extended, because this site has no SCSS, no resources.ToCSS, no PostCSS and no image processing. This moves the build off apk's hugo 0.139.0, about two years behind, onto the current stable. Rendered output across the whole public/ tree is unchanged except the meta name=generator version string
  • 2026-08-09: made script/check run script/lint (closes #9). It previously ran only fmt-check then test, so script/lint executed nowhere — not in make check, not in the pre-commit hook, and not in CI, even though the Dockerfile runs make check and script/cibuild builds it. It now runs test, lint, fmt-check in the canonical order, so the hugo --printPathWarnings render-target-collision signal is no longer discarded. README.md's Entrypoints line was corrected to match
  • 2026-08-09: hash-pinned every external reference in .gitea/workflows/deploy.yml (closes #7): both job container images are pinned by digest, all three uses: are pinned by 40-hex commit SHA, and the wrangler install is pinned to an exact version. The abandoned klakegg/hugo:ext-alpine image is gone: the build job now runs on the same pinned alpine digest the Dockerfile uses, with a pre-checkout apk add nodejs git tar step (the Actions runner needs node inside the job container to execute JavaScript actions), an explicit shell: sh default, then script/bootstrap and script/test. The deploy job is guarded with if: github.ref_name == 'main' so it can never publish from a branch. Also dropped the dead feat/initial-site push trigger and reindented the file to 4-space YAML to match check.yml. This is the second attempt; the first broke the deploy and was reverted, so this one was verified by temporarily triggering the workflow on the PR branch and iterating until the build job ran green for real
  • 2026-07-25: added the scripts-to-rule-them-all scaffold (closes #4): script/ entrypoints, Makefile shims, a Hugo Dockerfile (sha256-pinned alpine) plus .dockerignore that runs make check, .gitea/workflows/check.yml running script/cibuild, and a README Entrypoints section. test/lint are a clean hugo --minify build; fmt/fmt-check run prettier over the repo's own top-level markdown only
  • 2026-02-10: design pass: minimal light theme with inline CSS, grey wells for mesh channels and signal groups, horizontal overflow fix, body width tuning, map link update
  • 2026-02-10: added README and footer contribute link
  • 2026-02-10: added Gitea workflow that builds the site and deploys to Cloudflare Pages
  • 2026-02-08: initial Hugo static site for lora.vegas

Future Steps

  • Move the artifact actions to v4 once this Gitea Actions instance serves the v4 artifact protocol; they are pinned on the deprecated v3 line because v4 fails here (#20)
  • Move the deploy container to a pinned node 22 so the wrangler pin can advance past 4.86.0 (#21)
  • Rework README.md into the standard sections: Description, Getting Started, Rationale, Design, TODO, License, Author (currently About, Contributing, Technical Details, License)
  • Replace the "content is provided as-is" README note with the text of the committed LICENSE
  • Expand .gitignore beyond Hugo outputs (OS and editor files)
  • Verify the Cloudflare Pages deploy still works after the workflow changes
  • Keep mesh channel and signal group listings current