Re-vendor the shared files from sneak/prompts at dd4027b (closes #113)
check / check (push) Waiting to run
check / check (push) Waiting to run
The shared files are the sneak/prompts copies at dd4027b, with this repository's own entries after them. make lint and make test each build one phase of the Dockerfile without the cache, and each covers the frontend through a node stage; the builder stage waits on both and takes its version from git describe unless VERSION is given. golangci-lint moves to v2.14.0 with the new .golangci.yml, and one test spells X-Request-ID as canonicalheader asks. prettier formats only JavaScript, CSS, HTML and Markdown, so the shared .golangci.yml stays as fetched. script/fmt and script/fmt-check put ~/.local/bin on PATH, which the shared workflow no longer does. Model: opus-5-5
This commit is contained in:
+95
-74
@@ -2,95 +2,116 @@
|
||||
# passes /api/, /.well-known/healthcheck and /metrics to netwatch-server,
|
||||
# the Go backend, which runs in the same container on loopback only.
|
||||
# bin/entrypoint.sh starts and watches both.
|
||||
|
||||
# Lint stage — fast feedback on formatting and lint issues. The
|
||||
# golangci/golangci-lint image ships Go, gofmt, make and the linter, so
|
||||
# nothing is installed here. The root make lint builds this stage alone.
|
||||
# golangci/golangci-lint:v2.12.2 (2026-08-10)
|
||||
FROM golangci/golangci-lint@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS lint
|
||||
|
||||
WORKDIR /src
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN go mod download
|
||||
COPY backend/ .
|
||||
RUN make fmt-check
|
||||
RUN make lint
|
||||
|
||||
# Backend build stage
|
||||
# golang:1.25-alpine (2026-02-27)
|
||||
FROM golang:1.25-alpine@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder
|
||||
|
||||
# gcc and musl-dev are for make test: its race detector needs cgo, which
|
||||
# Go turns on by itself once a C compiler is present. make build still
|
||||
# sets CGO_ENABLED=0, so the binary stays static.
|
||||
RUN apk add --no-cache gcc git make musl-dev
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
# Force BuildKit to run the lint stage before proceeding. BuildKit runs
|
||||
# stages in parallel by default; without this no-op copy a lint failure
|
||||
# would not gate compilation.
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN go mod download
|
||||
COPY backend/ .
|
||||
|
||||
RUN make test
|
||||
|
||||
# make build is a shim around backend/script/build, the one definition
|
||||
# of the build command:
|
||||
# CGO_ENABLED=0 go build -trimpath -ldflags "-s -w -X main.Version=..."
|
||||
# That script reads VERSION from the environment, so it is handed over
|
||||
# there rather than as a make variable.
|
||||
#
|
||||
# The version is the VERSION build argument when one is given, otherwise
|
||||
# `git describe --tags --always` of the repo's .git: the tag on a tagged
|
||||
# commit, tag-N-gHASH on a commit after one, the short commit when no
|
||||
# tag is reachable. A version that still comes out empty, dev or unknown
|
||||
# fails the build. .git goes to /git, not /src/.git, where go build would
|
||||
# find it and record VCS details of a work tree holding only backend/.
|
||||
COPY .git /git
|
||||
ARG VERSION
|
||||
RUN version="${VERSION:-$(git --git-dir=/git describe --tags --always)}"; \
|
||||
case "$version" in ""|dev|unknown) \
|
||||
echo "version is '$version' although .git is present" >&2; \
|
||||
exit 1 ;; \
|
||||
esac; \
|
||||
VERSION="$version" make build
|
||||
# The lint and test phases are the gates: `make lint` (script/lint)
|
||||
# builds the lint stage alone and `make test` (script/test) the test
|
||||
# stage alone, and the builder stage depends on both, so the image
|
||||
# cannot be built unless they pass. Each covers the frontend as well,
|
||||
# through a copy from a node stage. Inside them each tool is invoked
|
||||
# directly, never through make or script/, whose lint and test are
|
||||
# themselves docker builds.
|
||||
|
||||
# Frontend lint stage — eslint over the JavaScript, as the lint stage
|
||||
# above lints the Go. The root make lint builds this stage alone too.
|
||||
# Frontend lint stage: eslint with the rules in eslint.config.js. The
|
||||
# lint phase below runs it.
|
||||
# node:22-alpine as of 2026-02-22
|
||||
FROM node@sha256:e4bf2a82ad0a4037d28035ae71529873c069b13eb0455466ae0bc13363826e34 AS frontend-lint
|
||||
WORKDIR /app
|
||||
COPY package.json yarn.lock ./
|
||||
RUN yarn install --frozen-lockfile
|
||||
COPY . .
|
||||
RUN script/frontend-lint
|
||||
RUN yarn eslint .
|
||||
|
||||
# Frontend stage
|
||||
# Lint phase: golangci-lint over the backend with backend/.golangci.yml,
|
||||
# and eslint through the copy from frontend-lint at the end. The
|
||||
# golangci/golangci-lint image ships Go and the linter.
|
||||
# golangci/golangci-lint:v2.14.0, 2026-09-24
|
||||
FROM golangci/golangci-lint@sha256:ad862ba6b3798cbe0fd9fd7408d498fd74fbd2623a92406b2fd3898faf0bf98f AS lint
|
||||
WORKDIR /src
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN go mod download
|
||||
COPY backend/ .
|
||||
RUN golangci-lint run --config .golangci.yml ./...
|
||||
# Nothing is wanted from frontend-lint; the copy is what makes this
|
||||
# phase run it.
|
||||
COPY --from=frontend-lint /app/yarn.lock /dev/null
|
||||
|
||||
# Frontend stage: the unit tests in test/unit/, then the production
|
||||
# build into dist/, which the runtime stage serves. The test phase below
|
||||
# runs it. The tests print a dot each; if any fails, they run again with
|
||||
# every test listed, and the step fails even if that run passes.
|
||||
# NODE_OPTIONS chooses the reporter because yarn adds its arguments
|
||||
# after the test files, where node would take a reporter option for one
|
||||
# more file.
|
||||
# node:22-alpine as of 2026-02-22
|
||||
FROM node@sha256:e4bf2a82ad0a4037d28035ae71529873c069b13eb0455466ae0bc13363826e34 AS frontend
|
||||
WORKDIR /app
|
||||
|
||||
# Force BuildKit to run the frontend-lint stage before proceeding, as
|
||||
# the builder stage does with the lint stage: without this no-op copy an
|
||||
# eslint failure would not gate the image.
|
||||
COPY --from=frontend-lint /app/yarn.lock /dev/null
|
||||
|
||||
COPY package.json yarn.lock ./
|
||||
RUN yarn install --frozen-lockfile
|
||||
RUN apk add --no-cache git make
|
||||
# vite.config.js reads the commit for the page's footer with git.
|
||||
RUN apk add --no-cache git
|
||||
COPY . .
|
||||
# make frontend-check runs the frontend tests and format check; its test
|
||||
# step runs the unit tests, then the production yarn build, so this both
|
||||
# produces dist/ and gates the image on test and formatting regressions.
|
||||
# This node stage has neither Go nor Docker; the frontend-lint, lint and
|
||||
# builder stages above gate the rest.
|
||||
RUN make frontend-check
|
||||
RUN NODE_OPTIONS=--test-reporter=dot timeout 90 yarn --silent run test || \
|
||||
{ echo "--- Rerunning with every test listed for details ---"; \
|
||||
NODE_OPTIONS=--test-reporter=spec timeout 90 yarn --silent run test; \
|
||||
exit 1; }
|
||||
RUN yarn build
|
||||
|
||||
# Runtime stage
|
||||
# Test phase: the backend's tests with the race detector and coverage,
|
||||
# and the frontend's through the copy from the frontend stage at the
|
||||
# end. -race needs cgo and so a C compiler, which the Debian Go image
|
||||
# ships and the alpine one does not. -timeout 90s is a backstop above
|
||||
# the 60-second cap on the suite. The rerun with -v only shows details:
|
||||
# the step fails however it ends, because the first run already failed.
|
||||
# golang:1.25.7-trixie, 2026-10-07
|
||||
FROM golang@sha256:2b174ffcf56c7ad0c47d30d2630693265639ddf2a5141149c2da34db921791b4 AS test
|
||||
WORKDIR /src
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN go mod download
|
||||
COPY backend/ .
|
||||
RUN go test -timeout 90s -race -cover ./... || \
|
||||
{ echo "--- Rerunning with -v for details ---"; \
|
||||
go test -timeout 90s -race -v ./...; exit 1; }
|
||||
# Nothing is wanted from the frontend stage; the copy is what makes
|
||||
# this phase run its tests.
|
||||
COPY --from=frontend /app/yarn.lock /dev/null
|
||||
|
||||
# Backend build stage. Nothing is wanted from the two phases; the copies
|
||||
# are what make BuildKit build them first, so this stage cannot run
|
||||
# unless lint and test passed.
|
||||
# golang:1.25-alpine (2026-02-27)
|
||||
FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4ced AS builder
|
||||
COPY --from=lint /src/go.sum /dev/null
|
||||
COPY --from=test /src/go.sum /dev/null
|
||||
RUN apk add --no-cache git
|
||||
# A tar-stream context keeps the sender's file owners, which git refuses.
|
||||
RUN git config --system --add safe.directory /src
|
||||
WORKDIR /src
|
||||
COPY backend/go.mod backend/go.sum backend/
|
||||
RUN cd backend && go mod download
|
||||
COPY . .
|
||||
|
||||
# backend/script/build is the one definition of the build command:
|
||||
# CGO_ENABLED=0 go build -trimpath -ldflags "-s -w -X main.Version=..."
|
||||
# It reads VERSION from the environment.
|
||||
#
|
||||
# The version is the VERSION build argument when one is given, otherwise
|
||||
# `git describe --tags --always` on the .git in the build context: the
|
||||
# tag on a tagged commit, tag-N-gHASH on a commit after one, the short
|
||||
# commit when no tag is reachable. With .git present, a version that is
|
||||
# still empty, dev or unknown fails the build: git is missing or could
|
||||
# not read the checkout.
|
||||
ARG VERSION
|
||||
RUN version="${VERSION:-$(git describe --tags --always)}"; \
|
||||
if [ -e .git ]; then \
|
||||
case "$version" in ""|dev|unknown) \
|
||||
echo "version is '$version' although .git is present" >&2; \
|
||||
exit 1 ;; \
|
||||
esac; \
|
||||
fi; \
|
||||
VERSION="$version" backend/script/build
|
||||
|
||||
# Runtime stage, and the last one: a plain `docker build .` builds it
|
||||
# and the stages it copies from, the two phases included.
|
||||
# nginx:stable-alpine as of 2026-02-22
|
||||
FROM nginx@sha256:15e96e59aa3b0aada3a121296e3bce117721f42d88f5f64217ef4b18f458c6ab
|
||||
|
||||
@@ -106,7 +127,7 @@ RUN rm /etc/nginx/conf.d/default.conf
|
||||
COPY nginx.conf /etc/nginx/templates/netwatch.conf.template
|
||||
COPY security-headers.conf /etc/nginx/security-headers.conf
|
||||
COPY --from=frontend /app/dist /usr/share/nginx/html
|
||||
COPY --from=builder /src/netwatch-server /usr/local/bin/netwatch-server
|
||||
COPY --from=builder /src/backend/netwatch-server /usr/local/bin/netwatch-server
|
||||
COPY bin/entrypoint.sh /usr/local/bin/entrypoint.sh
|
||||
|
||||
# bin/entrypoint.sh creates DATA_DIR at start and gives it and /data to
|
||||
|
||||
Reference in New Issue
Block a user