Make the image build multi-stage and cache-proof (closes #4)
All checks were successful
check / check (push) Successful in 23s
All checks were successful
check / check (push) Successful in 23s
The image build reported a green it had not earned. `script/cibuild` is a bare `docker build .`, and with `COPY . .` followed by `RUN make check`, an unchanged tree served that layer from cache: the suite never ran and the build still exited 0, while the script's header comment asserted the opposite. CHECK_EPOCH, passed by `script/cibuild` and `script/docker`, changes the cache key of the check and build layers on every invocation. It is guarded, because an unset ARG is the empty string and therefore a stable key: without the guard a plain `docker build .` — the command the policy names, and the one anyone debugging types — would still get the false green. A missing argument is now a hard failure rather than a silent degradation to the behaviour the epoch was added to prevent. The Dockerfile is now two stages: `fmt-check` and `lint` run first, and the check stage takes a `COPY --from=lint` dependency on them, so a formatting mistake fails the build in seconds instead of racing the suite to the finish. Both stages stay pinned to the same digest. The remaining fixes are one-liners that had made the target unusable: `script/projectname` still printed the pre-rename name, so `make docker` tagged its image after a name this project dropped in May; `script/bootstrap` installed without fetching apt's package lists, which cannot work on a Debian base; and `.dockerignore` had drifted far enough from `.gitignore` to ship a ~100 MB compiled binary and any agent worktree under `.claude/` into the build context. The second of those is a correctness problem, not a size one — vitest globs a copied worktree's tests alongside the real ones and runs the suite twice over. `.gitignore` itself stays in the context, because prettier reads it as a default ignore file and dropping it would change what `make fmt-check` sees.
This commit was merged in pull request #28.
This commit is contained in:
22
README.md
22
README.md
@@ -92,9 +92,9 @@ alpine. We provide:
|
||||
- `script/check` — run all checks: `test`, `lint`, `fmt-check` (our own
|
||||
extension)
|
||||
- `script/docker` — build the Docker image, tagged via `script/projectname`
|
||||
(byte-identical across repos)
|
||||
- `script/cibuild` — cd to the repo root and `docker build .` (what CI runs; the
|
||||
image build runs `make check` and `make build`)
|
||||
- `script/cibuild` — cd to the repo root and run the image build (what CI runs;
|
||||
the build runs `make fmt-check` and `make lint` in a first stage, then
|
||||
`make check` and `make build` in a second)
|
||||
- `script/precommit` — run by the git pre-commit hook (our own extension); runs
|
||||
`script/lint` and `script/fmt-check` but deliberately not the tests, so the
|
||||
TDD red-phase commit can land
|
||||
@@ -103,6 +103,15 @@ alpine. We provide:
|
||||
|
||||
`make hooks` installs the pre-commit hook that runs `script/precommit`.
|
||||
|
||||
Both `script/docker` and `script/cibuild` pass
|
||||
`--build-arg CHECK_EPOCH="$(date +%s)"`. The Dockerfile refuses to build without
|
||||
it. This is deliberate: on an unchanged tree Docker would otherwise serve the
|
||||
`make check` layer from cache, so the suite would never run and the build would
|
||||
still exit 0. A changing epoch invalidates the check and build layers on every
|
||||
invocation while leaving the dependency layers below them cached, and the
|
||||
missing-argument guard means a bare `docker build .` fails loudly instead of
|
||||
quietly reporting a green it did not earn.
|
||||
|
||||
## Rationale
|
||||
|
||||
Ente is one of very few photo services with a credible end-to-end encryption
|
||||
@@ -153,8 +162,9 @@ All work on quak is test-driven. No exceptions.
|
||||
8. The pre-commit hook installed by `make hooks` runs `script/precommit`, which
|
||||
runs the lint and format checks but not the full `make check`. This is
|
||||
deliberate so the TDD red-phase commit (failing tests, no implementation yet)
|
||||
can land. The full `make check` runs as part of `docker build .`, which is
|
||||
what CI executes, so a red branch still cannot reach `main`.
|
||||
can land. The full `make check` runs as part of the image build, which is
|
||||
what CI executes via `script/cibuild`, so a red branch still cannot reach
|
||||
`main`.
|
||||
|
||||
## Design
|
||||
|
||||
@@ -409,7 +419,7 @@ code is non-zero if any files failed.
|
||||
- [x] Retry policy: no retry on 4xx, exponential backoff on 5xx and network
|
||||
errors
|
||||
- [ ] Update the API reference section below to match the current implementation
|
||||
- [ ] `make docker` green
|
||||
- [x] `make docker` green
|
||||
- [ ] Tag `v1.0.0`
|
||||
|
||||
Future (desktop client, separate repo):
|
||||
|
||||
Reference in New Issue
Block a user