Compare commits
2
Commits
22e6bda2bb
...
8196ccfeb0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8196ccfeb0 | ||
|
|
cc440118c8 |
@@ -10,3 +10,9 @@ insert_final_newline = true
|
|||||||
|
|
||||||
[Makefile]
|
[Makefile]
|
||||||
indent_style = tab
|
indent_style = tab
|
||||||
|
|
||||||
|
[*.go]
|
||||||
|
indent_style = tab
|
||||||
|
|
||||||
|
# This repository's own sections, such as one for another language it
|
||||||
|
# uses, go below this comment, and a re-vendor keeps them.
|
||||||
|
|||||||
@@ -1,9 +1,16 @@
|
|||||||
name: check
|
name: check
|
||||||
on: [push]
|
on: [push]
|
||||||
|
# Free the shared runner: a new push cancels only the same branch's older run.
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
jobs:
|
jobs:
|
||||||
check:
|
check:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
# actions/checkout v4.2.2, 2026-02-22
|
# actions/checkout v4.2.2, 2026-02-22
|
||||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||||
|
# script/cibuild needs no token, so none is left in .git/config.
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
- run: script/cibuild
|
- run: script/cibuild
|
||||||
|
|||||||
+5
-1
@@ -27,7 +27,7 @@ node_modules/
|
|||||||
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
||||||
# convention. Only the templates `example.env` and `sample.env` are
|
# convention. Only the templates `example.env` and `sample.env` are
|
||||||
# re-included below. A repository that commits any other template adds
|
# re-included below. A repository that commits any other template adds
|
||||||
# its own negation after these lines, for example `!.env.example`.
|
# its own negation at the end of this file, for example `!.env.example`.
|
||||||
*.[eE][nN][vV]
|
*.[eE][nN][vV]
|
||||||
.[eE][nN][vV].*
|
.[eE][nN][vV].*
|
||||||
.[eE][nN][vV][rR][cC]
|
.[eE][nN][vV][rR][cC]
|
||||||
@@ -45,3 +45,7 @@ node_modules/
|
|||||||
[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
|
[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
|
||||||
[iI][dD]_[eE][dD]25519
|
[iI][dD]_[eE][dD]25519
|
||||||
[iI][dD]_[eE][dD]25519_[sS][kK]
|
[iI][dD]_[eE][dD]25519_[sS][kK]
|
||||||
|
|
||||||
|
# This repository's own entries, such as its build outputs, go below
|
||||||
|
# this comment, and a re-vendor keeps them. Anchor a binary built at the
|
||||||
|
# root: `/myapp`, never `myapp`, which also ignores `cmd/myapp/`.
|
||||||
|
|||||||
@@ -21,6 +21,21 @@ fmt-check, and commit.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-06: The canonical `.gitea/workflows/check.yml` now has a `concurrency`
|
||||||
|
block, so a new push cancels the older run on the same branch and no other,
|
||||||
|
and its checkout step sets `persist-credentials: false`, so the job's token is
|
||||||
|
not left in `.git/config` (issue 107). `REPO_POLICIES.md` and both checklists
|
||||||
|
describe the workflow as it now is. Not yet tried on the shared runner, which
|
||||||
|
is out of disk space. Repositories pick this up on their next re-vendor.
|
||||||
|
- 2026-10-06: The canonical `.gitignore` and `.editorconfig` now each end with a
|
||||||
|
comment saying the repository's own entries go below it and a re-vendor keeps
|
||||||
|
them (issue 103, which took in issue 104), as `.dockerignore`'s header already
|
||||||
|
does. `.editorconfig` gains a `[*.go]` section with tabs, since `gofmt`
|
||||||
|
decides Go indentation everywhere. `REPO_POLICIES.md` and both checklists say
|
||||||
|
that each of these two files is the canonical content followed by the
|
||||||
|
repository's own entries, which a re-vendor keeps, and the Go styleguide puts
|
||||||
|
`*.log`, `*.out`, `*.test` and binaries among those entries. Common outputs
|
||||||
|
stay out of the canonical `.gitignore`; each repository lists its own.
|
||||||
- 2026-10-05: `script/cibuild`, `script/docker`, `script/lint` and `script/test`
|
- 2026-10-05: `script/cibuild`, `script/docker`, `script/lint` and `script/test`
|
||||||
now assign the image tag from `script/projectname` on its own line before the
|
now assign the image tag from `script/projectname` on its own line before the
|
||||||
`docker build` (issue 101), so `set -e` stops the script where
|
`docker build` (issue 101), so `set -e` stops the script where
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Code Styleguide — Go
|
title: Code Styleguide — Go
|
||||||
last_modified: 2026-10-04
|
last_modified: 2026-10-06
|
||||||
---
|
---
|
||||||
|
|
||||||
1. Try to hard wrap long lines at 77 characters or less.
|
1. Try to hard wrap long lines at 77 characters or less.
|
||||||
@@ -148,8 +148,9 @@ last_modified: 2026-10-04
|
|||||||
handle HTTP requests. Don't use methods or your top level functions as
|
handle HTTP requests. Don't use methods or your top level functions as
|
||||||
handlers.
|
handlers.
|
||||||
|
|
||||||
1. Provide a .gitignore file that ignores at least `*.log`, `*.out`, and
|
1. The repository's own entries at the end of `.gitignore`, which a re-vendor
|
||||||
`*.test` files, as well as any binaries.
|
keeps, ignore at least `*.log`, `*.out`, and `*.test` files, as well as any
|
||||||
|
binaries.
|
||||||
|
|
||||||
1. Constructors **must** be called `New()`. `modulename.New()` works great if
|
1. Constructors **must** be called `New()`. `modulename.New()` works great if
|
||||||
you name the packages properly. If the constructor creates an instance from
|
you name the packages properly. If the constructor creates an instance from
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Existing Repo Checklist
|
title: Existing Repo Checklist
|
||||||
last_modified: 2026-10-04
|
last_modified: 2026-10-06
|
||||||
---
|
---
|
||||||
|
|
||||||
Use this checklist when beginning work in a repo that may not yet conform to our
|
Use this checklist when beginning work in a repo that may not yet conform to our
|
||||||
@@ -28,13 +28,18 @@ with your task.
|
|||||||
root — never a file or directory named after one agent tool, such as
|
root — never a file or directory named after one agent tool, such as
|
||||||
`CLAUDE.md` or `.claude/`, and never separate memory files. Move what any
|
`CLAUDE.md` or `.claude/`, and never separate memory files. Move what any
|
||||||
such committed file says into `AGENTS.md` and delete it.
|
such committed file says into `AGENTS.md` and delete it.
|
||||||
- [ ] `.gitignore` is comprehensive (OS, editor, agent scratch, language
|
- [ ] `.gitignore` is comprehensive (OS, editor, agent scratch, secrets, the
|
||||||
artifacts, secrets) — fetch from
|
repo's own build outputs) — fetch from
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` if missing.
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` if missing.
|
||||||
An existing repo usually has a hand-written one that is never re-fetched,
|
An existing repo usually has a hand-written one that is never re-fetched,
|
||||||
so check the entries rather than the file's presence.
|
so check the entries rather than the file's presence. The file is the
|
||||||
|
canonical content followed by the repo's own entries, such as its
|
||||||
|
binaries; a re-vendor replaces the canonical part and keeps those entries.
|
||||||
- [ ] `.editorconfig` exists — fetch from
|
- [ ] `.editorconfig` exists — fetch from
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.editorconfig`
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.editorconfig`. The
|
||||||
|
file is the canonical content followed by the repo's own sections, such as
|
||||||
|
one for another language it uses; a re-vendor replaces the canonical part
|
||||||
|
and keeps those sections.
|
||||||
- [ ] `Dockerfile` and `.dockerignore` exist; the Dockerfile carries a `lint`
|
- [ ] `Dockerfile` and `.dockerignore` exist; the Dockerfile carries a `lint`
|
||||||
phase and a `test` phase, and the final stage carries a `COPY --from=` of
|
phase and a `test` phase, and the final stage carries a `COPY --from=` of
|
||||||
a harmless file from each — fetch `.dockerignore` from
|
a harmless file from each — fetch `.dockerignore` from
|
||||||
@@ -91,7 +96,9 @@ with your task.
|
|||||||
`fetch-depth: 0` on the CI checkout step, which clones shallow and fetches
|
`fetch-depth: 0` on the CI checkout step, which clones shallow and fetches
|
||||||
no tags by default.
|
no tags by default.
|
||||||
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on
|
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on
|
||||||
push — reference
|
push, checks out with `persist-credentials: false`, and carries the
|
||||||
|
`concurrency` block that lets a new push cancel only the same branch's
|
||||||
|
older run — reference
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
||||||
- [ ] Language-specific config:
|
- [ ] Language-specific config:
|
||||||
- [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from
|
- [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: New Repo Checklist
|
title: New Repo Checklist
|
||||||
last_modified: 2026-10-04
|
last_modified: 2026-10-06
|
||||||
---
|
---
|
||||||
|
|
||||||
Use this checklist when creating a new repository from scratch. Follow the steps
|
Use this checklist when creating a new repository from scratch. Follow the steps
|
||||||
@@ -34,14 +34,17 @@ Template files can be fetched from:
|
|||||||
## Fetch Template Files
|
## Fetch Template Files
|
||||||
|
|
||||||
- [ ] `.gitignore` — fetch from
|
- [ ] `.gitignore` — fetch from
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore`, extend for
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore`, then add
|
||||||
language-specific artifacts. Extensions are written to `.gitignore`'s own
|
the repo's own build outputs, such as its binaries, at the end of the
|
||||||
semantics, where an unanchored pattern already matches at every depth:
|
file, where a re-vendor keeps them. Extensions are written to
|
||||||
never add a `**/` prefix here, which is a `.dockerignore` form. The
|
`.gitignore`'s own semantics, where an unanchored pattern already matches
|
||||||
canonical file already carries `.claude/` so agent worktrees cannot be
|
at every depth: never add a `**/` prefix here, which is a `.dockerignore`
|
||||||
committed by accident.
|
form. The canonical file already carries `.claude/` so agent worktrees
|
||||||
|
cannot be committed by accident.
|
||||||
- [ ] `.editorconfig` — fetch from
|
- [ ] `.editorconfig` — fetch from
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.editorconfig`
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.editorconfig`, then
|
||||||
|
add the repo's own sections, such as one for another language it uses, at
|
||||||
|
the end of the file, where a re-vendor keeps them.
|
||||||
- [ ] `Makefile` — fetch from
|
- [ ] `Makefile` — fetch from
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/Makefile`, adapt
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/Makefile`, adapt
|
||||||
targets for the project's language and tools
|
targets for the project's language and tools
|
||||||
@@ -103,7 +106,9 @@ Template files can be fetched from:
|
|||||||
- Non-server: the final stage brings up the dev environment
|
- Non-server: the final stage brings up the dev environment
|
||||||
- Image pinned by sha256 hash with version/date comment
|
- Image pinned by sha256 hash with version/date comment
|
||||||
- [ ] Gitea Actions workflow at `.gitea/workflows/check.yml` that runs
|
- [ ] Gitea Actions workflow at `.gitea/workflows/check.yml` that runs
|
||||||
`script/cibuild` on push — reference
|
`script/cibuild` on push, checks out with `persist-credentials: false`,
|
||||||
|
and carries the `concurrency` block that lets a new push cancel only the
|
||||||
|
same branch's older run — reference
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
||||||
- [ ] Language-specific:
|
- [ ] Language-specific:
|
||||||
- [ ] Go: `go mod init sneak.berlin/go/<name>`, `.golangci.yml` (fetch from
|
- [ ] Go: `go mod init sneak.berlin/go/<name>`, `.golangci.yml` (fetch from
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Repository Policies
|
title: Repository Policies
|
||||||
last_modified: 2026-10-04
|
last_modified: 2026-10-06
|
||||||
---
|
---
|
||||||
|
|
||||||
This document covers repository structure, tooling, and workflow standards. Code
|
This document covers repository structure, tooling, and workflow standards. Code
|
||||||
@@ -283,9 +283,15 @@ style conventions are in separate documents:
|
|||||||
refuses an empty build argument drops that refusal and keeps the argument.
|
refuses an empty build argument drops that refusal and keeps the argument.
|
||||||
|
|
||||||
- Every repo should have a Gitea Actions workflow (`.gitea/workflows/`) that
|
- Every repo should have a Gitea Actions workflow (`.gitea/workflows/`) that
|
||||||
runs `script/cibuild` on push, and checks out the repo as its only other step.
|
runs `script/cibuild` on push, and checks out the repo as its only other step,
|
||||||
That script bootstraps, runs the gate phases, and then builds the image, so a
|
with `persist-credentials: false`: `script/cibuild` needs no token, and
|
||||||
successful run means every check passed; a bare `docker build .` does not
|
without it the checkout leaves the job's token in `.git/config` for every
|
||||||
|
later step. Its `concurrency` block groups runs by workflow and branch
|
||||||
|
(`${{ github.workflow }}-${{ github.ref }}`) with `cancel-in-progress: true`,
|
||||||
|
so a new push cancels the older run on the same branch, queued or running, and
|
||||||
|
no other: runs for replaced commits do not hold up the shared runner.
|
||||||
|
`script/cibuild` bootstraps, runs the gate phases, and then builds the image,
|
||||||
|
so a successful run means every check passed; a bare `docker build .` does not
|
||||||
carry the same guarantee, because its gate phases may come from the cache. The
|
carry the same guarantee, because its gate phases may come from the cache. The
|
||||||
image build is uncached and so runs the gate phases a second time. That is the
|
image build is uncached and so runs the gate phases a second time. That is the
|
||||||
price of the rule above, and it is worth paying: the image that ships is built
|
price of the rule above, and it is worth paying: the image that ships is built
|
||||||
@@ -387,9 +393,12 @@ style conventions are in separate documents:
|
|||||||
|
|
||||||
- `.gitignore` should be comprehensive from the start: OS files (`.DS_Store`),
|
- `.gitignore` should be comprehensive from the start: OS files (`.DS_Store`),
|
||||||
editor files (`.swp`, `*~`), in-repo agent scratch directories (`.claude/`),
|
editor files (`.swp`, `*~`), in-repo agent scratch directories (`.claude/`),
|
||||||
language build artifacts, and `node_modules/`. Fetch the standard `.gitignore`
|
`node_modules/`, and the repo's own build outputs. Fetch the standard
|
||||||
from `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` when
|
`.gitignore` from
|
||||||
setting up a new repo. These patterns are written to `.gitignore`'s own
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitignore` when setting up
|
||||||
|
a new repo. A repo's `.gitignore` is the standard file followed by the repo's
|
||||||
|
own entries, such as its binaries; a re-vendor replaces the standard part and
|
||||||
|
keeps those entries. These patterns are written to `.gitignore`'s own
|
||||||
semantics, in which an unanchored pattern already matches at every depth; they
|
semantics, in which an unanchored pattern already matches at every depth; they
|
||||||
are not a `.dockerignore` and must not be transplanted into one unmodified.
|
are not a `.dockerignore` and must not be transplanted into one unmodified.
|
||||||
|
|
||||||
@@ -641,7 +650,11 @@ style conventions are in separate documents:
|
|||||||
Never edit existing migrations after release.
|
Never edit existing migrations after release.
|
||||||
|
|
||||||
- All repos should have an `.editorconfig` enforcing the project's indentation
|
- All repos should have an `.editorconfig` enforcing the project's indentation
|
||||||
settings.
|
settings: the standard file from
|
||||||
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.editorconfig`, which sets
|
||||||
|
tabs for `Makefile` and Go files, followed by the repo's own sections, such as
|
||||||
|
one for another language it uses. A re-vendor replaces the standard part and
|
||||||
|
keeps those sections.
|
||||||
|
|
||||||
- Avoid putting files in the repo root unless necessary. Root should contain
|
- Avoid putting files in the repo root unless necessary. Root should contain
|
||||||
only project-level config files (`README.md`, `AGENTS.md`, `Makefile`,
|
only project-level config files (`README.md`, `AGENTS.md`, `Makefile`,
|
||||||
|
|||||||
Reference in New Issue
Block a user