From 157bfbdd33d3548479a29940bf2c542bb6e09ac8 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Fri, 2 Oct 2026 02:41:23 +0000 Subject: [PATCH] Stamp the tag or short commit in a plain docker build (closes #166) .dockerignore now lets .git into the build context, without .git/config, which can hold a remote URL with a credential. ARG VERSION has no default: given none, the build stage takes the version from git describe --tags --always, and fails if the context carries .git and no version comes out. pixad now logs its name, version and architecture as its first log line, through the existing Logger.Identify, which nothing called. Model: opus-5-5 --- .dockerignore | 6 +++++- Dockerfile | 25 ++++++++++++++++++------- TODO.md | 7 +++++++ cmd/pixad/main.go | 5 ++++- 4 files changed, 34 insertions(+), 9 deletions(-) diff --git a/.dockerignore b/.dockerignore index 8fa00fc..549cdb4 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,4 +1,8 @@ -.git +# .git is sent without its config. Without a VERSION build argument the +# stage that compiles runs `git describe --tags --always` on .git, which +# does not need .git/config; that file can hold a credential, such as a +# password in a remote URL or the token the CI checkout step stores there. +.git/config .gitignore .DS_Store .env* diff --git a/Dockerfile b/Dockerfile index 76d9bac..91e4731 100644 --- a/Dockerfile +++ b/Dockerfile @@ -43,13 +43,24 @@ COPY . . RUN make test # VERSION is declared here, not earlier: a new value reruns only the -# build, not script/bootstrap or the tests. CGO stays enabled for -# govips; -trimpath keeps build paths out of the binary, and -s -w -# leave out the symbol table and debug information. -ARG VERSION=dev -RUN CGO_ENABLED=1 GOTOOLCHAIN=auto go build -trimpath \ - -ldflags "-s -w -X main.Version=${VERSION}" \ - -o /pixad ./cmd/pixad +# build, not script/bootstrap or the tests. Given none, the version is +# `git describe --tags --always` of the .git in the build context (git +# comes from script/bootstrap): the tag on a tagged commit, tag-N-gHASH +# after one, the short commit when no tag is reachable. A context that +# carries .git and still yields no version fails the build; one without +# .git, as from a source tarball, stamps an empty version. CGO stays +# enabled for govips; -trimpath keeps build paths out of the binary, and +# -s -w leave out the symbol table and debug information. +ARG VERSION +RUN version="${VERSION:-$(git describe --tags --always)}"; \ + if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \ + [ "$version" = unknown ]; }; then \ + echo "the build context carries .git but yields no version" >&2; \ + exit 1; \ + fi; \ + CGO_ENABLED=1 GOTOOLCHAIN=auto go build -trimpath \ + -ldflags "-s -w -X main.Version=${version}" \ + -o /pixad ./cmd/pixad # Runtime stage # alpine:3.21, 2026-02-25 diff --git a/TODO.md b/TODO.md index 637e3a5..ef4bd5c 100644 --- a/TODO.md +++ b/TODO.md @@ -29,6 +29,13 @@ P2: security: referer blacklist # Completed Steps +- 2026-10-02 a plain `docker build .` stamps the tag or short commit, not + `dev` (closes #166): `.dockerignore` lets `.git` into the build context, + without `.git/config`; with no `VERSION` build argument the `Dockerfile` + takes the version from `git describe --tags --always`, and fails the build if + the context carries `.git` and no version comes out; `ARG VERSION` has no + default; pixad logs its version, with its name and architecture, as its first + log line at startup. - 2026-09-29 the container makes `/var/lib/pixa` usable by itself (closes #159): `deploy/docker-entrypoint.sh` creates the directory if it is missing, gives the directory and everything in it to `pixad` when the directory or one diff --git a/cmd/pixad/main.go b/cmd/pixad/main.go index 601c1ee..96442dc 100644 --- a/cmd/pixad/main.go +++ b/cmd/pixad/main.go @@ -56,6 +56,9 @@ func run(_ *cobra.Command, _ []string) { middleware.New, healthcheck.New, ), - fx.Invoke(func(*server.Server) {}), + fx.Invoke( + func(log *logger.Logger) { log.Identify() }, + func(*server.Server) {}, + ), ).Run() } -- 2.54.0