Stamp the tag or short commit in a plain docker build (closes #166) #167

Merged
clawbot merged 1 commits from issue-166-docker-build-version into next 2026-10-02 06:01:42 +02:00
Collaborator

A plain docker build . of a clone now stamps the commit's tag or short commit into pixad instead of dev, for #166.

  • .dockerignore lets .git into the build context, without .git/config: a clone's remote URL can carry a credential, and git describe does not need the file.
  • The build stage's ARG VERSION has no default. Given no VERSION build argument, the version is git describe --tags --always (no --dirty) of the .git in the context. The build fails if the context carries .git and the version comes out empty, dev or unknown. make docker-versioned and make docker-test still pass the host's version.
  • git is already installed in the build stage by script/bootstrap.
  • pixad now logs its name, version and architecture as its first log line, through the existing Logger.Identify, which nothing called.

The Makefile's VERSION already used git describe --tags --always --dirty; unchanged. No buildarch remains.

Disclosures:

  • Judgement call: calling Identify() goes beyond the build files; without it no startup log line carries the version, which the issue's definition of done reads.
  • A context with neither .git nor VERSION, such as a source tarball, now stamps an empty version instead of dev.
  • REPO_POLICIES.md's example Dockerfile still shows ARG VERSION=dev; it is shared policy text, left as is.
  • No automated test covers the Dockerfile step.
  • make check cannot run its tests on this host, which lacks libvips.

Model: opus-5-5

A plain `docker build .` of a clone now stamps the commit's tag or short commit into pixad instead of `dev`, for https://git.eeqj.de/sneak/pixa/issues/166. - `.dockerignore` lets `.git` into the build context, without `.git/config`: a clone's remote URL can carry a credential, and `git describe` does not need the file. - The build stage's `ARG VERSION` has no default. Given no `VERSION` build argument, the version is `git describe --tags --always` (no `--dirty`) of the `.git` in the context. The build fails if the context carries `.git` and the version comes out empty, `dev` or `unknown`. `make docker-versioned` and `make docker-test` still pass the host's version. - git is already installed in the build stage by `script/bootstrap`. - pixad now logs its name, version and architecture as its first log line, through the existing `Logger.Identify`, which nothing called. The Makefile's `VERSION` already used `git describe --tags --always --dirty`; unchanged. No `buildarch` remains. Disclosures: - Judgement call: calling `Identify()` goes beyond the build files; without it no startup log line carries the version, which the issue's definition of done reads. - A context with neither `.git` nor `VERSION`, such as a source tarball, now stamps an empty version instead of `dev`. - `REPO_POLICIES.md`'s example Dockerfile still shows `ARG VERSION=dev`; it is shared policy text, left as is. - No automated test covers the Dockerfile step. - `make check` cannot run its tests on this host, which lacks libvips. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 05:02:23 +02:00
clawbot self-assigned this 2026-10-02 05:02:23 +02:00
Author
Collaborator
  • .dockerignore, line 1: the comment says .git is sent without its config but not why. Leaving out .git/config is what keeps a credential (a password in a clone's remote URL, or the token the CI checkout step stores there) out of the build stage's layers; without the reason, a later edit can drop the line. Acceptable: the comment says the config can hold a credential and git describe does not need it, as the canonical .dockerignore on sneak/prompts next does.

Model: opus-5-5

- `.dockerignore`, line 1: the comment says `.git` is sent without its config but not why. Leaving out `.git/config` is what keeps a credential (a password in a clone's remote URL, or the token the CI checkout step stores there) out of the build stage's layers; without the reason, a later edit can drop the line. Acceptable: the comment says the config can hold a credential and `git describe` does not need it, as the canonical `.dockerignore` on `sneak/prompts` `next` does. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-02 05:35:50 +02:00
clawbot added 1 commit 2026-10-02 05:37:35 +02:00
.dockerignore now lets .git into the build context, without
.git/config, which can hold a remote URL with a credential. ARG VERSION
has no default: given none, the build stage takes the version from
git describe --tags --always, and fails if the context carries .git
and no version comes out. pixad now logs its name, version and
architecture as its first log line, through the existing
Logger.Identify, which nothing called.

Model: opus-5-5
clawbot force-pushed issue-166-docker-build-version from ba5102092f to 157bfbdd33 2026-10-02 05:37:35 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-02 05:50:18 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 869b5ba67f into next 2026-10-02 06:01:42 +02:00
clawbot deleted branch issue-166-docker-build-version 2026-10-02 06:01:42 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#167