Compare commits
6
Commits
f9ea5a74e9
..
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c55a0cb2f0 | ||
|
|
1d9b046b91 | ||
|
|
0b20f18734 | ||
|
|
a04a76d59c | ||
|
|
b3508a4361 | ||
|
|
8fe0709414 |
@@ -7,10 +7,14 @@ concurrency:
|
|||||||
jobs:
|
jobs:
|
||||||
check:
|
check:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
# Free the shared runner from a hung build.
|
||||||
|
timeout-minutes: 20
|
||||||
steps:
|
steps:
|
||||||
# actions/checkout v4.2.2, 2026-02-22
|
# actions/checkout v4.2.2, 2026-02-22
|
||||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
||||||
# script/cibuild needs no token, so none is left in .git/config.
|
# script/cibuild needs no token, so none is left in .git/config.
|
||||||
with:
|
with:
|
||||||
persist-credentials: false
|
persist-credentials: false
|
||||||
|
# All history and tags, so git describe finds the version tag.
|
||||||
|
fetch-depth: 0
|
||||||
- run: script/cibuild
|
- run: script/cibuild
|
||||||
|
|||||||
@@ -116,10 +116,14 @@ alpine. We provide:
|
|||||||
`script/bootstrap`, then `script/install-precommit`
|
`script/bootstrap`, then `script/install-precommit`
|
||||||
- `script/projectname` — output the project name (our own extension); used by
|
- `script/projectname` — output the project name (our own extension); used by
|
||||||
`script/docker` for the image tag
|
`script/docker` for the image tag
|
||||||
- `script/test` — `docker build --no-cache --target test -t prompts-test .`,
|
- `script/test` —
|
||||||
building the `test` phase of the `Dockerfile` (no tests defined here)
|
`docker build --no-cache --target test --output type=cacheonly .`, building
|
||||||
- `script/lint` — `docker build --no-cache --target lint -t prompts-lint .`,
|
the `test` phase of the `Dockerfile` without writing an image (no tests
|
||||||
building the `lint` phase, which runs prettier over the markdown files
|
defined here)
|
||||||
|
- `script/lint` —
|
||||||
|
`docker build --no-cache --target lint --output type=cacheonly .`, building
|
||||||
|
the `lint` phase, which runs prettier over the markdown files, without writing
|
||||||
|
an image
|
||||||
- `script/fmt` — format all markdown files with prettier (writes; native, not in
|
- `script/fmt` — format all markdown files with prettier (writes; native, not in
|
||||||
a container)
|
a container)
|
||||||
- `script/fmt-check` — check formatting (read-only; native)
|
- `script/fmt-check` — check formatting (read-only; native)
|
||||||
|
|||||||
@@ -21,6 +21,43 @@ fmt-check, and commit.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-07: The `script/cibuild` item in `NEW_REPO_CHECKLIST.md` now matches
|
||||||
|
the canonical `script/cibuild` (issue 125). Its image build carries the tag,
|
||||||
|
`-t "$tag"`, and the item says that `$version` comes from
|
||||||
|
`git describe --tags --always --dirty` (`unknown` if empty) and `$tag` from
|
||||||
|
`script/projectname`, each assigned on its own line before the build. A
|
||||||
|
repository written from the checklist got an untagged build, which leaves a
|
||||||
|
dangling image behind on every run, and was never told where `$version` comes
|
||||||
|
from. The other `docker build` commands the checklists and `REPO_POLICIES.md`
|
||||||
|
give for `script/` already matched their scripts.
|
||||||
|
- 2026-10-07: `script/lint` and `script/test` now build with
|
||||||
|
`--output type=cacheonly` in place of a tag (issue 123), so they still run
|
||||||
|
their phase uncached and fail on a failing step but write no image. Nothing
|
||||||
|
used those images, and writing one out cost about 16 seconds of a Go
|
||||||
|
repository's test build. `script/cibuild` and `script/docker` keep their tags.
|
||||||
|
`REPO_POLICIES.md`, both checklists and the README no longer say the gate
|
||||||
|
builds are tagged. Not yet tried on the shared runner. Repositories pick this
|
||||||
|
up on their next re-vendor.
|
||||||
|
- 2026-10-07: The canonical `.gitea/workflows/check.yml` now sets
|
||||||
|
`timeout-minutes: 20` on its `check` job (issue 120), so a hung build frees
|
||||||
|
the shared runner instead of holding it until the runner's own limit.
|
||||||
|
`script/cibuild` runs three Docker builds, each held to the 5-minute Docker
|
||||||
|
build limit, plus the bootstrap; if that limit changes (issue 113), the value
|
||||||
|
follows it. `REPO_POLICIES.md` and both checklists name the limit among what
|
||||||
|
the workflow sets. Not yet tried on the shared runner. Repositories pick this
|
||||||
|
up on their next re-vendor.
|
||||||
|
- 2026-10-07: The canonical `package.json` now has `"private": true` in place of
|
||||||
|
`"license": "MIT"` (issue 119), so a repository that copies it no longer
|
||||||
|
declares MIT whatever its own licence is. yarn does not print "No license
|
||||||
|
field" for a private package. This repository's own licence is unchanged.
|
||||||
|
- 2026-10-06: The canonical `.gitea/workflows/check.yml` now sets
|
||||||
|
`fetch-depth: 0` on its checkout step (issue 110), so CI fetches the history
|
||||||
|
and tags that `git describe --tags --always` needs, and a tagged repository
|
||||||
|
stamps the same version in CI as in a local build. `REPO_POLICIES.md` and both
|
||||||
|
checklists name `fetch-depth: 0` among what the workflow does, next to
|
||||||
|
`persist-credentials: false` and the `concurrency` block, instead of asking
|
||||||
|
each tagged repository to add it. Not yet tried on the shared runner, which is
|
||||||
|
out of disk space. Repositories pick this up on their next re-vendor.
|
||||||
- 2026-10-06: The canonical `script/bootstrap` now runs `apt-get update` once,
|
- 2026-10-06: The canonical `script/bootstrap` now runs `apt-get update` once,
|
||||||
before the first `apt-get install` of a run (issue 115). The Gitea runner
|
before the first `apt-get install` of a run (issue 115). The Gitea runner
|
||||||
image starts with empty package lists, so installing anything it lacks, such
|
image starts with empty package lists, so installing anything it lacks, such
|
||||||
|
|||||||
+1
-1
@@ -1,5 +1,5 @@
|
|||||||
{
|
{
|
||||||
"license": "MIT",
|
"private": true,
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"prettier": "3.8.1"
|
"prettier": "3.8.1"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Existing Repo Checklist
|
title: Existing Repo Checklist
|
||||||
last_modified: 2026-10-06
|
last_modified: 2026-10-07
|
||||||
---
|
---
|
||||||
|
|
||||||
Use this checklist when beginning work in a repo that may not yet conform to our
|
Use this checklist when beginning work in a repo that may not yet conform to our
|
||||||
@@ -96,13 +96,16 @@ with your task.
|
|||||||
directory outside the build context, so the build cannot read the version
|
directory outside the build context, so the build cannot read the version
|
||||||
and a plain `docker build .` fails; pass the version with
|
and a plain `docker build .` fails; pass the version with
|
||||||
`--build-arg VERSION=...`. `script/docker` and `script/cibuild` already
|
`--build-arg VERSION=...`. `script/docker` and `script/cibuild` already
|
||||||
pass the version they compute on the host; it takes precedence. A
|
pass the version they compute on the host; it takes precedence. The
|
||||||
tag-derived version additionally needs `fetch-depth: 0` on the CI checkout
|
canonical `.gitea/workflows/check.yml` sets `fetch-depth: 0` on its
|
||||||
step, which clones shallow and fetches no tags by default.
|
checkout step, which otherwise clones shallow and fetches no tags, so a CI
|
||||||
|
build finds the tag too.
|
||||||
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on
|
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on
|
||||||
push, checks out with `persist-credentials: false`, and carries the
|
push, checks out with `persist-credentials: false` and with
|
||||||
`concurrency` block that lets a new push cancel only the same branch's
|
`fetch-depth: 0` (which fetches the tags `git describe` needs), carries
|
||||||
older run — reference
|
the `concurrency` block that lets a new push cancel only the same branch's
|
||||||
|
older run, and sets `timeout-minutes: 20` on the `check` job so a hung
|
||||||
|
build frees the shared runner — reference
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
||||||
- [ ] Language-specific config:
|
- [ ] Language-specific config:
|
||||||
- [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from
|
- [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from
|
||||||
@@ -129,16 +132,19 @@ with your task.
|
|||||||
`script/install-precommit`, shimmed by `make hooks`) runs it
|
`script/install-precommit`, shimmed by `make hooks`) runs it
|
||||||
- [ ] README has an **Entrypoints** section documenting the `script/`
|
- [ ] README has an **Entrypoints** section documenting the `script/`
|
||||||
entrypoints and linking the standard
|
entrypoints and linking the standard
|
||||||
- [ ] `script/lint` and `script/test` build their phase by name
|
- [ ] `script/lint` and `script/test` each run
|
||||||
(`docker build --no-cache --target <phase> -t <name>-<phase> .`), and no
|
`docker build --no-cache --target <phase> --output type=cacheonly .`,
|
||||||
host invocation anywhere in the repo can produce a lint verdict — grep for
|
which builds their phase by name and writes no image, and no host
|
||||||
the linter's own name across `script/`, the `Makefile` and CI config, not
|
invocation anywhere in the repo can produce a lint verdict — grep for the
|
||||||
just `script/lint`. A second path is likeliest here: a `make lint-fast`,
|
linter's own name across `script/`, the `Makefile` and CI config, not just
|
||||||
an older host-versus-container branch, or a CI step calling the binary
|
`script/lint`. A second path is likeliest here: a `make lint-fast`, an
|
||||||
|
older host-versus-container branch, or a CI step calling the binary
|
||||||
directly. `script/fmt` and `script/fmt-check` are expected hits and stay
|
directly. `script/fmt` and `script/fmt-check` are expected hits and stay
|
||||||
on the host.
|
on the host.
|
||||||
- [ ] Every `docker build` in `script/` is tagged — an untagged one leaves a
|
- [ ] No `docker build` in `script/` leaves a dangling image behind:
|
||||||
dangling image behind on every run, on every host and CI runner
|
`script/lint` and `script/test` write no image, and `script/docker` and
|
||||||
|
`script/cibuild` tag theirs. A build that writes an untagged image leaves
|
||||||
|
one behind on every run, on every host and CI runner.
|
||||||
- [ ] `script/cibuild` runs `script/bootstrap` before `script/check`, and builds
|
- [ ] `script/cibuild` runs `script/bootstrap` before `script/check`, and builds
|
||||||
the image with `--no-cache`. Without the bootstrap the CI run dies in
|
the image with `--no-cache`. Without the bootstrap the CI run dies in
|
||||||
`script/fmt-check`, which runs the formatter on the host and finds nothing
|
`script/fmt-check`, which runs the formatter on the host and finds nothing
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: New Repo Checklist
|
title: New Repo Checklist
|
||||||
last_modified: 2026-10-06
|
last_modified: 2026-10-07
|
||||||
---
|
---
|
||||||
|
|
||||||
Use this checklist when creating a new repository from scratch. Follow the steps
|
Use this checklist when creating a new repository from scratch. Follow the steps
|
||||||
@@ -112,9 +112,11 @@ Template files can be fetched from:
|
|||||||
- Non-server: the final stage brings up the dev environment
|
- Non-server: the final stage brings up the dev environment
|
||||||
- Image pinned by sha256 hash with version/date comment
|
- Image pinned by sha256 hash with version/date comment
|
||||||
- [ ] Gitea Actions workflow at `.gitea/workflows/check.yml` that runs
|
- [ ] Gitea Actions workflow at `.gitea/workflows/check.yml` that runs
|
||||||
`script/cibuild` on push, checks out with `persist-credentials: false`,
|
`script/cibuild` on push, checks out with `persist-credentials: false` and
|
||||||
and carries the `concurrency` block that lets a new push cancel only the
|
with `fetch-depth: 0` (which fetches the tags `git describe` needs),
|
||||||
same branch's older run — reference
|
carries the `concurrency` block that lets a new push cancel only the same
|
||||||
|
branch's older run, and sets `timeout-minutes: 20` on the `check` job so a
|
||||||
|
hung build frees the shared runner — reference
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml`
|
||||||
- [ ] Language-specific:
|
- [ ] Language-specific:
|
||||||
- [ ] Go: `go mod init sneak.berlin/go/<name>`, `.golangci.yml` (fetch from
|
- [ ] Go: `go mod init sneak.berlin/go/<name>`, `.golangci.yml` (fetch from
|
||||||
@@ -141,11 +143,14 @@ are thin shims calling them. Model scripts:
|
|||||||
it
|
it
|
||||||
- [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`,
|
- [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`,
|
||||||
then `install-precommit`, plus repo-specific init
|
then `install-precommit`, plus repo-specific init
|
||||||
- [ ] `script/test` / `make test` — `docker build --no-cache --target test .`,
|
- [ ] `script/test` / `make test` —
|
||||||
tagged; the phase runs real tests, not a no-op (90-second timeout,
|
`docker build --no-cache --target test --output type=cacheonly .`, which
|
||||||
60-second hard cap on wall time)
|
writes no image; the phase runs real tests, not a no-op (90-second
|
||||||
- [ ] `script/lint` / `make lint` — `docker build --no-cache --target lint .`,
|
timeout, 60-second hard cap on wall time)
|
||||||
tagged. No lint verdict may come from a host invocation of the linter.
|
- [ ] `script/lint` / `make lint` —
|
||||||
|
`docker build --no-cache --target lint --output type=cacheonly .`, which
|
||||||
|
writes no image. No lint verdict may come from a host invocation of the
|
||||||
|
linter.
|
||||||
- [ ] `script/fmt` / `make fmt` — formats code (writes; native, never in a
|
- [ ] `script/fmt` / `make fmt` — formats code (writes; native, never in a
|
||||||
container)
|
container)
|
||||||
- [ ] `script/fmt-check` / `make fmt-check` — checks formatting (read-only;
|
- [ ] `script/fmt-check` / `make fmt-check` — checks formatting (read-only;
|
||||||
@@ -159,16 +164,20 @@ are thin shims calling them. Model scripts:
|
|||||||
version as a build arg
|
version as a build arg
|
||||||
- [ ] `script/cibuild` — cd to repo root, run `script/bootstrap`, run
|
- [ ] `script/cibuild` — cd to repo root, run `script/bootstrap`, run
|
||||||
`script/check`, then
|
`script/check`, then
|
||||||
`docker build --no-cache --build-arg VERSION="$version" .` (what CI runs).
|
`docker build --no-cache --build-arg VERSION="$version" -t "$tag" .` (what
|
||||||
The bootstrap is required: CI checks out and runs this alone, and
|
CI runs), with `$version` from `git describe --tags --always --dirty`
|
||||||
`script/fmt-check` runs the formatter on the host.
|
(`unknown` if empty) and `$tag` from `script/projectname`, each assigned
|
||||||
|
on its own line before the build. The bootstrap is required: CI checks out
|
||||||
|
and runs this alone, and `script/fmt-check` runs the formatter on the
|
||||||
|
host.
|
||||||
- [ ] `script/fmt` and `script/fmt-check` source nvm for the pinned node version
|
- [ ] `script/fmt` and `script/fmt-check` source nvm for the pinned node version
|
||||||
before invoking `yarn`, as `script/bootstrap`'s own install step does.
|
before invoking `yarn`, as `script/bootstrap`'s own install step does.
|
||||||
`script/bootstrap` leaves the node and yarn it installs off the `PATH` of
|
`script/bootstrap` leaves the node and yarn it installs off the `PATH` of
|
||||||
the shell that called it, so a bare `yarn` exits 127 on a runner carrying
|
the shell that called it, so a bare `yarn` exits 127 on a runner carrying
|
||||||
nothing but docker and git.
|
nothing but docker and git.
|
||||||
- [ ] Every `docker build` in `script/` is tagged, so no invocation leaves a
|
- [ ] No `docker build` in `script/` leaves a dangling image behind:
|
||||||
dangling image behind
|
`script/lint` and `script/test` write no image, and `script/docker` and
|
||||||
|
`script/cibuild` tag theirs
|
||||||
- [ ] `script/precommit` — called by the pre-commit hook; runs `script/check`
|
- [ ] `script/precommit` — called by the pre-commit hook; runs `script/check`
|
||||||
- [ ] `script/install-precommit` — installs the pre-commit hook that runs
|
- [ ] `script/install-precommit` — installs the pre-commit hook that runs
|
||||||
`script/precommit`
|
`script/precommit`
|
||||||
|
|||||||
+28
-19
@@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
title: Repository Policies
|
title: Repository Policies
|
||||||
last_modified: 2026-10-06
|
last_modified: 2026-10-07
|
||||||
---
|
---
|
||||||
|
|
||||||
This document covers repository structure, tooling, and workflow standards. Code
|
This document covers repository structure, tooling, and workflow standards. Code
|
||||||
@@ -118,9 +118,8 @@ style conventions are in separate documents:
|
|||||||
and nothing else:
|
and nothing else:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
tag="$(script/projectname)"
|
docker build --no-cache --target lint --output type=cacheonly .
|
||||||
docker build --no-cache --target lint -t "$tag-lint" .
|
docker build --no-cache --target test --output type=cacheonly .
|
||||||
docker build --no-cache --target test -t "$tag-test" .
|
|
||||||
```
|
```
|
||||||
|
|
||||||
**A stage that is not the last one in the file is built only when the final
|
**A stage that is not the last one in the file is built only when the final
|
||||||
@@ -130,12 +129,15 @@ style conventions are in separate documents:
|
|||||||
plain `docker build .` builds the last stage alone and exits 0 having linted
|
plain `docker build .` builds the last stage alone and exits 0 having linted
|
||||||
and tested nothing.
|
and tested nothing.
|
||||||
|
|
||||||
**Every `docker build` in `script/` is tagged**, here and in
|
**The gate builds write no image.** With `--output type=cacheonly` the phase
|
||||||
`script/cibuild` and `script/docker`. An untagged build leaves a dangling
|
runs and a failing step fails the build, but the result is not exported.
|
||||||
image behind on every invocation, on every developer host and every CI
|
Nothing uses those images, and writing one out is slow: a Go test phase's
|
||||||
runner; a tagged one replaces the previous image. Each script assigns the
|
image holds the toolchain and every compiled package. A build given neither
|
||||||
tag on its own line before the build, so `set -e` stops it where
|
`--output` nor `-t` writes an untagged image and leaves it dangling, on
|
||||||
`script/projectname` fails.
|
every developer host and every CI runner. `script/cibuild` and
|
||||||
|
`script/docker` build the image that ships and tag it, so each build
|
||||||
|
replaces the previous image; each assigns the tag on its own line before the
|
||||||
|
build, so `set -e` stops it where `script/projectname` fails.
|
||||||
|
|
||||||
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
||||||
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
||||||
@@ -292,7 +294,10 @@ style conventions are in separate documents:
|
|||||||
runs `script/cibuild` on push, and checks out the repo as its only other step,
|
runs `script/cibuild` on push, and checks out the repo as its only other step,
|
||||||
with `persist-credentials: false`: `script/cibuild` needs no token, and
|
with `persist-credentials: false`: `script/cibuild` needs no token, and
|
||||||
without it the checkout leaves the job's token in `.git/config` for every
|
without it the checkout leaves the job's token in `.git/config` for every
|
||||||
later step. Its `concurrency` block groups runs by workflow and branch
|
later step. The checkout step also sets `fetch-depth: 0`, which fetches the
|
||||||
|
tags `git describe` needs: by default it clones shallow with no tags, and a
|
||||||
|
tagged repository's CI build would stamp a bare short commit id. The
|
||||||
|
workflow's `concurrency` block groups runs by workflow and branch
|
||||||
(`${{ github.workflow }}-${{ github.ref }}`) with `cancel-in-progress: true`,
|
(`${{ github.workflow }}-${{ github.ref }}`) with `cancel-in-progress: true`,
|
||||||
so a new push cancels the older run on the same branch, queued or running, and
|
so a new push cancels the older run on the same branch, queued or running, and
|
||||||
no other: runs for replaced commits do not hold up the shared runner.
|
no other: runs for replaced commits do not hold up the shared runner.
|
||||||
@@ -301,12 +306,16 @@ style conventions are in separate documents:
|
|||||||
carry the same guarantee, because its gate phases may come from the cache. The
|
carry the same guarantee, because its gate phases may come from the cache. The
|
||||||
image build is uncached and so runs the gate phases a second time. That is the
|
image build is uncached and so runs the gate phases a second time. That is the
|
||||||
price of the rule above, and it is worth paying: the image that ships is built
|
price of the rule above, and it is worth paying: the image that ships is built
|
||||||
from a run of its own gates rather than from a cache entry. A separate
|
from a run of its own gates rather than from a cache entry. The `check` job
|
||||||
workflow limited to `main` by a `branches` list under `on: push` cannot be
|
sets `timeout-minutes: 20`, so a hung build frees the shared runner after 20
|
||||||
checked by review: to try a change to it, add the feature branch to that list
|
minutes. That allows for the three Docker builds described above (the test
|
||||||
and push, then remove the branch from the list again before merging. Keep any
|
phase, the lint phase, then the image), each held to the 5-minute Docker build
|
||||||
job in it that publishes behind `if: github.ref_name == 'main'`, so the run
|
limit below, plus the bootstrap. A separate workflow limited to `main` by a
|
||||||
from the feature branch publishes nothing.
|
`branches` list under `on: push` cannot be checked by review: to try a change
|
||||||
|
to it, add the feature branch to that list and push, then remove the branch
|
||||||
|
from the list again before merging. Keep any job in it that publishes behind
|
||||||
|
`if: github.ref_name == 'main'`, so the run from the feature branch publishes
|
||||||
|
nothing.
|
||||||
|
|
||||||
- Use platform-standard formatters: `black` for Python, `prettier` for
|
- Use platform-standard formatters: `black` for Python, `prettier` for
|
||||||
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
|
JS/CSS/Markdown/HTML, `go fmt` for Go. Always use default configuration with
|
||||||
@@ -472,8 +481,8 @@ style conventions are in separate documents:
|
|||||||
there because `ARG` is stage-scoped; passing `VERSION` to a repo whose
|
there because `ARG` is stage-scoped; passing `VERSION` to a repo whose
|
||||||
Dockerfile declares no such `ARG` is ignored and costs nothing, which is why
|
Dockerfile declares no such `ARG` is ignored and costs nothing, which is why
|
||||||
the scripts stay byte-identical. One consequence for CI: the standard
|
the scripts stay byte-identical. One consequence for CI: the standard
|
||||||
checkout action clones shallow and fetches no tags, so a repo that embeds a
|
checkout action clones shallow and fetches no tags, so the canonical
|
||||||
tag-derived version must set `fetch-depth: 0` on its checkout step.
|
`.gitea/workflows/check.yml` sets `fetch-depth: 0` on its checkout step.
|
||||||
|
|
||||||
- **Verify `.dockerignore` by enumerating the image, not by reading the
|
- **Verify `.dockerignore` by enumerating the image, not by reading the
|
||||||
patterns.** Plant files at the root _and_ at least two directories deep, build
|
patterns.** Plant files at the root _and_ at least two directories deep, build
|
||||||
|
|||||||
+3
-7
@@ -6,8 +6,8 @@
|
|||||||
#
|
#
|
||||||
# The phase is not the last stage in the file, so it is built only when
|
# The phase is not the last stage in the file, so it is built only when
|
||||||
# --target names it. --no-cache because a cached lint layer is a lint
|
# --target names it. --no-cache because a cached lint layer is a lint
|
||||||
# that did not run. The tag makes each build replace the previous image
|
# that did not run. --output type=cacheonly writes no image, since
|
||||||
# instead of leaving a dangling one behind.
|
# nothing uses one.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
@@ -15,13 +15,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
# The tag gets its own line: a failing command substitution inside
|
|
||||||
# an argument does not trip `set -e`, so the inline form degrades
|
|
||||||
# silently to an empty constant.
|
|
||||||
tag="$("$SCRIPT_DIR/projectname")"
|
|
||||||
docker build --no-cache \
|
docker build --no-cache \
|
||||||
--target lint \
|
--target lint \
|
||||||
-t "$tag-lint" .
|
--output type=cacheonly .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
+3
-7
@@ -2,8 +2,8 @@
|
|||||||
# script/test: run the test suite. Testing is a phase of the Dockerfile
|
# script/test: run the test suite. Testing is a phase of the Dockerfile
|
||||||
# and this builds that phase alone, on the same terms as script/lint:
|
# and this builds that phase alone, on the same terms as script/lint:
|
||||||
# --target because a phase that is not the last stage is built only when
|
# --target because a phase that is not the last stage is built only when
|
||||||
# named, --no-cache because a cached test layer is a test that did not
|
# named, and --no-cache because a cached test layer is a test that did
|
||||||
# run, and a tag so each build replaces the previous image.
|
# not run. --output type=cacheonly writes no image, since nothing uses one.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
@@ -11,13 +11,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
# The tag gets its own line: a failing command substitution inside
|
|
||||||
# an argument does not trip `set -e`, so the inline form degrades
|
|
||||||
# silently to an empty constant.
|
|
||||||
tag="$("$SCRIPT_DIR/projectname")"
|
|
||||||
docker build --no-cache \
|
docker build --no-cache \
|
||||||
--target test \
|
--target test \
|
||||||
-t "$tag-test" .
|
--output type=cacheonly .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user