main.Version on sneak/api is set to "dev" instead of the git hash when being built under upaas, fix that
audit all other repos for that same bug. "docker build ." should pick up the git short rev or tag
The canonical documents prescribe the bug: the .dockerignore excludes .git, the Dockerfile example declares ARG VERSION=dev, and the policy says no stage may call git describe. upaas builds a clone with no build arguments, so every image built that way says dev. These documents change first; every other repo follows them.
The stage that compiles has git (the Debian Go image has it; an alpine one needs apk add --no-cache git) and takes the version from the VERSION build argument when one is given, otherwise from git describe --tags --always (a tag when the commit has one, otherwise the short commit). ARG VERSION has no default.
The build fails if the context carries .git and the version still comes out empty, dev or unknown.
script/docker and script/cibuild may keep passing the version they compute on the host; it takes precedence.
What to change, on a branch cut from next, PR to next:
.dockerignore: drop .git and the comment above it; say in one comment why .git is sent.
prompts/REPO_POLICIES.md: the Dockerfile example's builder stage, its "Key points" bullet on ARG VERSION=dev, and the bullet "Excluding .git means git describe cannot run inside any build stage" are rewritten to the convention. The shallow-clone note on tag-derived versions stays.
prompts/NEW_REPO_CHECKLIST.md and prompts/EXISTING_REPO_CHECKLIST.md: the version bullets say the same.
prompts/CODE_STYLEGUIDE_GO.md and prompts/GO_HTTP_SERVER_CONVENTIONS.md: the Makefile comments that say .dockerignore excludes .git match the convention.
This repo's own Dockerfile, script/docker and script/cibuild: comments that say .dockerignore excludes .git match.
Definition of done:
No document or template in this repo says .git is excluded from the build context, declares ARG VERSION=dev, or forbids git describe in a build stage; each place that covers the version describes the convention above, in the same words where they repeat.
make check passes; independent review; squash to next.
Model: opus-5-5
Owner's words (chat, 2026-10-02 ~00:00 UTC; the rollout across repos is https://git.eeqj.de/sneak/project-management/issues/21):
> main.Version on sneak/api is set to "dev" instead of the git hash when being built under upaas, fix that
> audit all other repos for that same bug. "docker build ." should pick up the git short rev or tag
The canonical documents prescribe the bug: the `.dockerignore` excludes `.git`, the Dockerfile example declares `ARG VERSION=dev`, and the policy says no stage may call `git describe`. upaas builds a clone with no build arguments, so every image built that way says `dev`. These documents change first; every other repo follows them.
The convention (already in https://git.eeqj.de/sneak/upaas/pulls/242 and https://git.eeqj.de/sneak/webhooker/pulls/410):
- `.dockerignore` lets `.git` into the build context.
- The stage that compiles has `git` (the Debian Go image has it; an alpine one needs `apk add --no-cache git`) and takes the version from the `VERSION` build argument when one is given, otherwise from `git describe --tags --always` (a tag when the commit has one, otherwise the short commit). `ARG VERSION` has no default.
- The build fails if the context carries `.git` and the version still comes out empty, `dev` or `unknown`.
- `script/docker` and `script/cibuild` may keep passing the version they compute on the host; it takes precedence.
What to change, on a branch cut from `next`, PR to `next`:
- `.dockerignore`: drop `.git` and the comment above it; say in one comment why `.git` is sent.
- `prompts/REPO_POLICIES.md`: the Dockerfile example's builder stage, its "Key points" bullet on `ARG VERSION=dev`, and the bullet "Excluding `.git` means `git describe` cannot run inside any build stage" are rewritten to the convention. The shallow-clone note on tag-derived versions stays.
- `prompts/NEW_REPO_CHECKLIST.md` and `prompts/EXISTING_REPO_CHECKLIST.md`: the version bullets say the same.
- `prompts/CODE_STYLEGUIDE_GO.md` and `prompts/GO_HTTP_SERVER_CONVENTIONS.md`: the Makefile comments that say `.dockerignore` excludes `.git` match the convention.
- This repo's own `Dockerfile`, `script/docker` and `script/cibuild`: comments that say `.dockerignore` excludes `.git` match.
Definition of done:
- No document or template in this repo says `.git` is excluded from the build context, declares `ARG VERSION=dev`, or forbids `git describe` in a build stage; each place that covers the version describes the convention above, in the same words where they repeat.
- `make check` passes; independent review; squash to `next`.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Owner's words (chat, 2026-10-02 ~00:00 UTC; the rollout across repos is sneak/project-management#21):
The canonical documents prescribe the bug: the
.dockerignoreexcludes.git, the Dockerfile example declaresARG VERSION=dev, and the policy says no stage may callgit describe. upaas builds a clone with no build arguments, so every image built that way saysdev. These documents change first; every other repo follows them.The convention (already in sneak/upaas#242 and sneak/webhooker#410):
.dockerignorelets.gitinto the build context.git(the Debian Go image has it; an alpine one needsapk add --no-cache git) and takes the version from theVERSIONbuild argument when one is given, otherwise fromgit describe --tags --always(a tag when the commit has one, otherwise the short commit).ARG VERSIONhas no default..gitand the version still comes out empty,devorunknown.script/dockerandscript/cibuildmay keep passing the version they compute on the host; it takes precedence.What to change, on a branch cut from
next, PR tonext:.dockerignore: drop.gitand the comment above it; say in one comment why.gitis sent.prompts/REPO_POLICIES.md: the Dockerfile example's builder stage, its "Key points" bullet onARG VERSION=dev, and the bullet "Excluding.gitmeansgit describecannot run inside any build stage" are rewritten to the convention. The shallow-clone note on tag-derived versions stays.prompts/NEW_REPO_CHECKLIST.mdandprompts/EXISTING_REPO_CHECKLIST.md: the version bullets say the same.prompts/CODE_STYLEGUIDE_GO.mdandprompts/GO_HTTP_SERVER_CONVENTIONS.md: the Makefile comments that say.dockerignoreexcludes.gitmatch the convention.Dockerfile,script/dockerandscript/cibuild: comments that say.dockerignoreexcludes.gitmatch.Definition of done:
.gitis excluded from the build context, declaresARG VERSION=dev, or forbidsgit describein a build stage; each place that covers the version describes the convention above, in the same words where they repeat.make checkpasses; independent review; squash tonext.Model: opus-5-5