From 30e13d73bbb7ce8a8e1bb62fa4373c44208f3d31 Mon Sep 17 00:00:00 2001 From: sneak Date: Sun, 4 Oct 2026 09:04:57 +0000 Subject: [PATCH] Say which Dockerfile stages run script/bootstrap (closes #90) The bullet in `prompts/REPO_POLICIES.md` that requires a `Dockerfile` said every Dockerfile installs its prerequisites by running `script/bootstrap`, while the canonical Go `Dockerfile` never runs it: its gate phases use their pinned images as they are and its build stage installs `git` inline. The bullet now says the gate phases and the build stage take their tools from their pinned base images and install only what those images lack, and that the development environment stage, the final stage of a non-server repo, runs `script/bootstrap`. The new repo checklist says the same. Model: opus-5-5 --- TODO.md | 6 ++++++ prompts/NEW_REPO_CHECKLIST.md | 4 ++-- prompts/REPO_POLICIES.md | 10 ++++++---- 3 files changed, 14 insertions(+), 6 deletions(-) diff --git a/TODO.md b/TODO.md index 0b5c245..34f4cac 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,12 @@ fmt-check, and commit. # Completed Steps +- 2026-10-04: `REPO_POLICIES.md` now says which `Dockerfile` stages run + `script/bootstrap` (issue 90). The gate phases and the build stage take their + tools from their pinned base images and install only what those images lack, + as the canonical Go `Dockerfile` does. The development environment stage, the + final stage of a non-server repo, runs `script/bootstrap`. The new repo + checklist says the same. - 2026-10-04: Fixed the server lifecycle example in `prompts/GO_HTTP_SERVER_CONVENTIONS.md` (issue 86). Only fx handles SIGINT and SIGTERM, and `Run()` in `main` exits with the shutdown's exit code. A listen diff --git a/prompts/NEW_REPO_CHECKLIST.md b/prompts/NEW_REPO_CHECKLIST.md index c229df2..0763f6a 100644 --- a/prompts/NEW_REPO_CHECKLIST.md +++ b/prompts/NEW_REPO_CHECKLIST.md @@ -119,8 +119,8 @@ are thin shims calling them. Model scripts: - [ ] `script/bootstrap` / `make bootstrap` — installs all dependencies, idempotently, assuming nothing (pkg manager detection nix/apt/brew/apk; node used if present, else pinned version via nvm from a hash-verified - archive; pinned yarn via corepack); Dockerfile runs it instead of inline - installs + archive; pinned yarn via corepack); a non-server repo's development + environment stage runs it instead of inline installs - [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`, then `install-precommit`, plus repo-specific init - [ ] `script/test` / `make test` — `docker build --no-cache --target test .`, diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index c66b459..216dbf9 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -104,10 +104,12 @@ style conventions are in separate documents: `lint` phase and a `test` phase, with the final stage depending on both so the image cannot be built unless they pass. For non-server repos the final stage brings up a development environment; for server repos it is the runtime image. - Dockerfiles install development prerequisites by running `script/bootstrap` - rather than duplicating installs inline; COPY `script/` and the dependency - manifests (`package.json` + `yarn.lock`, `go.mod` + `go.sum`, etc.) before - running it. + The gate phases and the build stage take their tools from their pinned base + images and install only what those images lack, as the canonical Go + `Dockerfile` below does. The development environment stage installs + development prerequisites by running `script/bootstrap` rather than + duplicating its installs inline; COPY `script/` and the dependency manifests + (`package.json` + `yarn.lock`, `go.mod` + `go.sum`, etc.) before running it. - **Linting and testing run in Docker, as phases of the `Dockerfile`.** There is no separate lint file. `script/lint` and `script/test` each build one phase