Stop the lint and test builds writing an image (closes #123)
check / check (push) Canceled after 0s
check / check (push) Canceled after 0s
script/lint and script/test build their Dockerfile phase with --output type=cacheonly in place of a tag. The phase still runs uncached and a failing step still fails the build, but no image is written: nothing used those images, and writing one out took about 16 seconds of a Go repository's test build. script/cibuild and script/docker keep their tags. REPO_POLICIES.md, both checklists and the README now say the gate builds write no image. Model: opus-5-5
This commit was merged in pull request #124.
This commit is contained in:
@@ -118,9 +118,8 @@ style conventions are in separate documents:
|
||||
and nothing else:
|
||||
|
||||
```sh
|
||||
tag="$(script/projectname)"
|
||||
docker build --no-cache --target lint -t "$tag-lint" .
|
||||
docker build --no-cache --target test -t "$tag-test" .
|
||||
docker build --no-cache --target lint --output type=cacheonly .
|
||||
docker build --no-cache --target test --output type=cacheonly .
|
||||
```
|
||||
|
||||
**A stage that is not the last one in the file is built only when the final
|
||||
@@ -130,12 +129,15 @@ style conventions are in separate documents:
|
||||
plain `docker build .` builds the last stage alone and exits 0 having linted
|
||||
and tested nothing.
|
||||
|
||||
**Every `docker build` in `script/` is tagged**, here and in
|
||||
`script/cibuild` and `script/docker`. An untagged build leaves a dangling
|
||||
image behind on every invocation, on every developer host and every CI
|
||||
runner; a tagged one replaces the previous image. Each script assigns the
|
||||
tag on its own line before the build, so `set -e` stops it where
|
||||
`script/projectname` fails.
|
||||
**The gate builds write no image.** With `--output type=cacheonly` the phase
|
||||
runs and a failing step fails the build, but the result is not exported.
|
||||
Nothing uses those images, and writing one out is slow: a Go test phase's
|
||||
image holds the toolchain and every compiled package. A build given neither
|
||||
`--output` nor `-t` writes an untagged image and leaves it dangling, on
|
||||
every developer host and every CI runner. `script/cibuild` and
|
||||
`script/docker` build the image that ships and tag it, so each build
|
||||
replaces the previous image; each assigns the tag on its own line before the
|
||||
build, so `set -e` stops it where `script/projectname` fails.
|
||||
|
||||
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
||||
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
||||
|
||||
Reference in New Issue
Block a user