From 00713b86771c650679bf12e52fcfa990df4fc773 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 10:42:09 +0200 Subject: [PATCH] Build with the local docker daemon; add script/build (closes #44) The Makefile exported DOCKER_HOST pointing at one private machine, so every docker call made through make, `make lint` and `make check` included, failed everywhere else. The line is gone: docker uses the local daemon, or a DOCKER_HOST set in the environment. `make build` now calls the new `script/build`, which stamps the version and commit as the Makefile did. A VERSION set in the environment now wins over `git describe`, not only one given as `make build VERSION=x`. build, clean, install and docker-run are phony; install depends on build. The vet target is removed: `script/test` runs `go vet` first. Model: opus-5-5 --- Makefile | 22 ++++++---------------- README.md | 3 +++ TODO.md | 7 +++++++ script/build | 29 +++++++++++++++++++++++++++++ 4 files changed, 45 insertions(+), 16 deletions(-) create mode 100755 script/build diff --git a/Makefile b/Makefile index dd771bd..041b902 100644 --- a/Makefile +++ b/Makefile @@ -1,13 +1,7 @@ export CGO_ENABLED=1 -export DOCKER_HOST := ssh://root@ber1app1.local -# Version information -VERSION := $(shell git describe --tags --always --dirty 2>/dev/null || echo "dev") -GIT_COMMIT := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown") -LDFLAGS := -X 'git.eeqj.de/sneak/secret/internal/cli.Version=$(VERSION)' \ - -X 'git.eeqj.de/sneak/secret/internal/cli.GitCommit=$(GIT_COMMIT)' - -.PHONY: default bootstrap setup test lint fmt fmt-check check docker hooks vet +.PHONY: default bootstrap setup build test lint fmt fmt-check check docker \ + docker-run clean install hooks default: check @@ -17,13 +11,9 @@ bootstrap: setup: @script/setup -build: ./secret - -./secret: ./internal/*/*.go ./pkg/*/*.go ./cmd/*/*.go ./go.* - go build -v -ldflags "$(LDFLAGS)" -o $@ cmd/secret/main.go - -vet: - go vet ./... +# Build ./secret; `make build VERSION=x` stamps x instead of `git describe` +build: + @script/build test: @script/test @@ -49,7 +39,7 @@ docker-run: clean: rm -f ./secret -install: ./secret +install: build cp ./secret $(HOME)/bin/secret fmt-check: diff --git a/README.md b/README.md index 45ac972..2c2bfaa 100644 --- a/README.md +++ b/README.md @@ -506,6 +506,9 @@ them. We provide: `script/bootstrap`, then `script/install-precommit` - `script/projectname` — output the project name (`secret`); used by other scripts such as `script/docker` +- `script/build` — build the `secret` binary into the repo root, stamping + the version (`VERSION` from the environment, else `git describe`) and + the git commit - `script/test` — run `go vet` and the test suite (verbose rerun on failure) - `script/lint` — run `golangci-lint` in docker only: builds diff --git a/TODO.md b/TODO.md index 03c8006..2a8d576 100644 --- a/TODO.md +++ b/TODO.md @@ -25,6 +25,13 @@ Bring the repo into policy compliance in one commit: # Completed Steps +- 2026-10-04: The `Makefile` no longer sets `DOCKER_HOST`, so its docker + targets use the local docker daemon, or whatever `DOCKER_HOST` the + environment sets. `make build` calls the new `script/build`, which + stamps the version (`VERSION` from the environment, else + `git describe`) and the git commit as before. `build`, `clean`, + `install` and `docker-run` are in `.PHONY`; `make install` depends on + `build`. The `vet` target is gone: `script/test` runs `go vet` first. - 2026-10-04: `.gitignore` is the org's standard file, which ignores `.env`, `.env.*`, `*.pem` and `*.key` and editor and OS files, plus this repo's `/secret`, `*.log`, `*.test` and `settings.local.json` diff --git a/script/build b/script/build new file mode 100755 index 0000000..0837fec --- /dev/null +++ b/script/build @@ -0,0 +1,29 @@ +#!/bin/sh +# script/build: build the `secret` binary into the repo root, with its +# version and git commit stamped in (`secret info` shows both). +set -eu + +ROOT="$(cd "$(dirname "$0")/.." && pwd -P)" + +main() { + cd "$ROOT" + # CGO is required (Makefile exports this too) + export CGO_ENABLED=1 + # A VERSION set in the environment wins (`make build VERSION=x`, as + # the Dockerfile does); otherwise `git describe` of this checkout. + version="${VERSION:-}" + if [ -z "$version" ]; then + version="$(git describe --tags --always --dirty 2>/dev/null || + echo dev)" + fi + commit="$(git rev-parse HEAD 2>/dev/null || echo unknown)" + pkg=git.eeqj.de/sneak/secret/internal/cli + # Build the file, not the package `./cmd/secret`: a package build + # also stamps git status into the binary and fails where git cannot + # read the checkout, instead of falling back to `dev`/`unknown`. + go build -v \ + -ldflags "-X '$pkg.Version=$version' -X '$pkg.GitCommit=$commit'" \ + -o secret cmd/secret/main.go +} + +main "$@"