Stop the lint and test builds writing an image (closes #123) #124
@@ -116,10 +116,14 @@ alpine. We provide:
|
|||||||
`script/bootstrap`, then `script/install-precommit`
|
`script/bootstrap`, then `script/install-precommit`
|
||||||
- `script/projectname` — output the project name (our own extension); used by
|
- `script/projectname` — output the project name (our own extension); used by
|
||||||
`script/docker` for the image tag
|
`script/docker` for the image tag
|
||||||
- `script/test` — `docker build --no-cache --target test -t prompts-test .`,
|
- `script/test` —
|
||||||
building the `test` phase of the `Dockerfile` (no tests defined here)
|
`docker build --no-cache --target test --output type=cacheonly .`, building
|
||||||
- `script/lint` — `docker build --no-cache --target lint -t prompts-lint .`,
|
the `test` phase of the `Dockerfile` without writing an image (no tests
|
||||||
building the `lint` phase, which runs prettier over the markdown files
|
defined here)
|
||||||
|
- `script/lint` —
|
||||||
|
`docker build --no-cache --target lint --output type=cacheonly .`, building
|
||||||
|
the `lint` phase, which runs prettier over the markdown files, without writing
|
||||||
|
an image
|
||||||
- `script/fmt` — format all markdown files with prettier (writes; native, not in
|
- `script/fmt` — format all markdown files with prettier (writes; native, not in
|
||||||
a container)
|
a container)
|
||||||
- `script/fmt-check` — check formatting (read-only; native)
|
- `script/fmt-check` — check formatting (read-only; native)
|
||||||
|
|||||||
@@ -21,6 +21,14 @@ fmt-check, and commit.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-07: `script/lint` and `script/test` now build with
|
||||||
|
`--output type=cacheonly` in place of a tag (issue 123), so they still run
|
||||||
|
their phase uncached and fail on a failing step but write no image. Nothing
|
||||||
|
used those images, and writing one out cost about 16 seconds of a Go
|
||||||
|
repository's test build. `script/cibuild` and `script/docker` keep their tags.
|
||||||
|
`REPO_POLICIES.md`, both checklists and the README no longer say the gate
|
||||||
|
builds are tagged. Not yet tried on the shared runner. Repositories pick this
|
||||||
|
up on their next re-vendor.
|
||||||
- 2026-10-07: The canonical `.gitea/workflows/check.yml` now sets
|
- 2026-10-07: The canonical `.gitea/workflows/check.yml` now sets
|
||||||
`timeout-minutes: 20` on its `check` job (issue 120), so a hung build frees
|
`timeout-minutes: 20` on its `check` job (issue 120), so a hung build frees
|
||||||
the shared runner instead of holding it until the runner's own limit.
|
the shared runner instead of holding it until the runner's own limit.
|
||||||
|
|||||||
@@ -132,16 +132,19 @@ with your task.
|
|||||||
`script/install-precommit`, shimmed by `make hooks`) runs it
|
`script/install-precommit`, shimmed by `make hooks`) runs it
|
||||||
- [ ] README has an **Entrypoints** section documenting the `script/`
|
- [ ] README has an **Entrypoints** section documenting the `script/`
|
||||||
entrypoints and linking the standard
|
entrypoints and linking the standard
|
||||||
- [ ] `script/lint` and `script/test` build their phase by name
|
- [ ] `script/lint` and `script/test` each run
|
||||||
(`docker build --no-cache --target <phase> -t <name>-<phase> .`), and no
|
`docker build --no-cache --target <phase> --output type=cacheonly .`,
|
||||||
host invocation anywhere in the repo can produce a lint verdict — grep for
|
which builds their phase by name and writes no image, and no host
|
||||||
the linter's own name across `script/`, the `Makefile` and CI config, not
|
invocation anywhere in the repo can produce a lint verdict — grep for the
|
||||||
just `script/lint`. A second path is likeliest here: a `make lint-fast`,
|
linter's own name across `script/`, the `Makefile` and CI config, not just
|
||||||
an older host-versus-container branch, or a CI step calling the binary
|
`script/lint`. A second path is likeliest here: a `make lint-fast`, an
|
||||||
|
older host-versus-container branch, or a CI step calling the binary
|
||||||
directly. `script/fmt` and `script/fmt-check` are expected hits and stay
|
directly. `script/fmt` and `script/fmt-check` are expected hits and stay
|
||||||
on the host.
|
on the host.
|
||||||
- [ ] Every `docker build` in `script/` is tagged — an untagged one leaves a
|
- [ ] No `docker build` in `script/` leaves a dangling image behind:
|
||||||
dangling image behind on every run, on every host and CI runner
|
`script/lint` and `script/test` write no image, and `script/docker` and
|
||||||
|
`script/cibuild` tag theirs. A build that writes an untagged image leaves
|
||||||
|
one behind on every run, on every host and CI runner.
|
||||||
- [ ] `script/cibuild` runs `script/bootstrap` before `script/check`, and builds
|
- [ ] `script/cibuild` runs `script/bootstrap` before `script/check`, and builds
|
||||||
the image with `--no-cache`. Without the bootstrap the CI run dies in
|
the image with `--no-cache`. Without the bootstrap the CI run dies in
|
||||||
`script/fmt-check`, which runs the formatter on the host and finds nothing
|
`script/fmt-check`, which runs the formatter on the host and finds nothing
|
||||||
|
|||||||
@@ -143,11 +143,14 @@ are thin shims calling them. Model scripts:
|
|||||||
it
|
it
|
||||||
- [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`,
|
- [ ] `script/setup` / `make setup` — readies a fresh clone: runs `bootstrap`,
|
||||||
then `install-precommit`, plus repo-specific init
|
then `install-precommit`, plus repo-specific init
|
||||||
- [ ] `script/test` / `make test` — `docker build --no-cache --target test .`,
|
- [ ] `script/test` / `make test` —
|
||||||
tagged; the phase runs real tests, not a no-op (90-second timeout,
|
`docker build --no-cache --target test --output type=cacheonly .`, which
|
||||||
60-second hard cap on wall time)
|
writes no image; the phase runs real tests, not a no-op (90-second
|
||||||
- [ ] `script/lint` / `make lint` — `docker build --no-cache --target lint .`,
|
timeout, 60-second hard cap on wall time)
|
||||||
tagged. No lint verdict may come from a host invocation of the linter.
|
- [ ] `script/lint` / `make lint` —
|
||||||
|
`docker build --no-cache --target lint --output type=cacheonly .`, which
|
||||||
|
writes no image. No lint verdict may come from a host invocation of the
|
||||||
|
linter.
|
||||||
- [ ] `script/fmt` / `make fmt` — formats code (writes; native, never in a
|
- [ ] `script/fmt` / `make fmt` — formats code (writes; native, never in a
|
||||||
container)
|
container)
|
||||||
- [ ] `script/fmt-check` / `make fmt-check` — checks formatting (read-only;
|
- [ ] `script/fmt-check` / `make fmt-check` — checks formatting (read-only;
|
||||||
@@ -169,8 +172,9 @@ are thin shims calling them. Model scripts:
|
|||||||
`script/bootstrap` leaves the node and yarn it installs off the `PATH` of
|
`script/bootstrap` leaves the node and yarn it installs off the `PATH` of
|
||||||
the shell that called it, so a bare `yarn` exits 127 on a runner carrying
|
the shell that called it, so a bare `yarn` exits 127 on a runner carrying
|
||||||
nothing but docker and git.
|
nothing but docker and git.
|
||||||
- [ ] Every `docker build` in `script/` is tagged, so no invocation leaves a
|
- [ ] No `docker build` in `script/` leaves a dangling image behind:
|
||||||
dangling image behind
|
`script/lint` and `script/test` write no image, and `script/docker` and
|
||||||
|
`script/cibuild` tag theirs
|
||||||
- [ ] `script/precommit` — called by the pre-commit hook; runs `script/check`
|
- [ ] `script/precommit` — called by the pre-commit hook; runs `script/check`
|
||||||
- [ ] `script/install-precommit` — installs the pre-commit hook that runs
|
- [ ] `script/install-precommit` — installs the pre-commit hook that runs
|
||||||
`script/precommit`
|
`script/precommit`
|
||||||
|
|||||||
@@ -118,9 +118,8 @@ style conventions are in separate documents:
|
|||||||
and nothing else:
|
and nothing else:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
tag="$(script/projectname)"
|
docker build --no-cache --target lint --output type=cacheonly .
|
||||||
docker build --no-cache --target lint -t "$tag-lint" .
|
docker build --no-cache --target test --output type=cacheonly .
|
||||||
docker build --no-cache --target test -t "$tag-test" .
|
|
||||||
```
|
```
|
||||||
|
|
||||||
**A stage that is not the last one in the file is built only when the final
|
**A stage that is not the last one in the file is built only when the final
|
||||||
@@ -130,12 +129,15 @@ style conventions are in separate documents:
|
|||||||
plain `docker build .` builds the last stage alone and exits 0 having linted
|
plain `docker build .` builds the last stage alone and exits 0 having linted
|
||||||
and tested nothing.
|
and tested nothing.
|
||||||
|
|
||||||
**Every `docker build` in `script/` is tagged**, here and in
|
**The gate builds write no image.** With `--output type=cacheonly` the phase
|
||||||
`script/cibuild` and `script/docker`. An untagged build leaves a dangling
|
runs and a failing step fails the build, but the result is not exported.
|
||||||
image behind on every invocation, on every developer host and every CI
|
Nothing uses those images, and writing one out is slow: a Go test phase's
|
||||||
runner; a tagged one replaces the previous image. Each script assigns the
|
image holds the toolchain and every compiled package. A build given neither
|
||||||
tag on its own line before the build, so `set -e` stops it where
|
`--output` nor `-t` writes an untagged image and leaves it dangling, on
|
||||||
`script/projectname` fails.
|
every developer host and every CI runner. `script/cibuild` and
|
||||||
|
`script/docker` build the image that ships and tag it, so each build
|
||||||
|
replaces the previous image; each assigns the tag on its own line before the
|
||||||
|
build, so `set -e` stops it where `script/projectname` fails.
|
||||||
|
|
||||||
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
Inside a phase the tool is invoked directly — `golangci-lint`, `go test`,
|
||||||
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
`eslint`, `prettier` — never through `make lint` or `script/test`, which are
|
||||||
|
|||||||
+3
-7
@@ -6,8 +6,8 @@
|
|||||||
#
|
#
|
||||||
# The phase is not the last stage in the file, so it is built only when
|
# The phase is not the last stage in the file, so it is built only when
|
||||||
# --target names it. --no-cache because a cached lint layer is a lint
|
# --target names it. --no-cache because a cached lint layer is a lint
|
||||||
# that did not run. The tag makes each build replace the previous image
|
# that did not run. --output type=cacheonly writes no image, since
|
||||||
# instead of leaving a dangling one behind.
|
# nothing uses one.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
@@ -15,13 +15,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
# The tag gets its own line: a failing command substitution inside
|
|
||||||
# an argument does not trip `set -e`, so the inline form degrades
|
|
||||||
# silently to an empty constant.
|
|
||||||
tag="$("$SCRIPT_DIR/projectname")"
|
|
||||||
docker build --no-cache \
|
docker build --no-cache \
|
||||||
--target lint \
|
--target lint \
|
||||||
-t "$tag-lint" .
|
--output type=cacheonly .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
+3
-7
@@ -2,8 +2,8 @@
|
|||||||
# script/test: run the test suite. Testing is a phase of the Dockerfile
|
# script/test: run the test suite. Testing is a phase of the Dockerfile
|
||||||
# and this builds that phase alone, on the same terms as script/lint:
|
# and this builds that phase alone, on the same terms as script/lint:
|
||||||
# --target because a phase that is not the last stage is built only when
|
# --target because a phase that is not the last stage is built only when
|
||||||
# named, --no-cache because a cached test layer is a test that did not
|
# named, and --no-cache because a cached test layer is a test that did
|
||||||
# run, and a tag so each build replaces the previous image.
|
# not run. --output type=cacheonly writes no image, since nothing uses one.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
@@ -11,13 +11,9 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
# The tag gets its own line: a failing command substitution inside
|
|
||||||
# an argument does not trip `set -e`, so the inline form degrades
|
|
||||||
# silently to an empty constant.
|
|
||||||
tag="$("$SCRIPT_DIR/projectname")"
|
|
||||||
docker build --no-cache \
|
docker build --no-cache \
|
||||||
--target test \
|
--target test \
|
||||||
-t "$tag-test" .
|
--output type=cacheonly .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user