Let a plain docker build pass and stamp the git version (closes #57)
check / check (push) Failing after 20s

The size tests skip a case whose secret needs more locked memory than
RLIMIT_MEMLOCK allows: memguard panics otherwise, and a plain
`docker build .` runs under an 8 MiB limit. script/cibuild still runs
every case.

The build stage stamps the VERSION build argument, else
`git describe --tags --always`, and fails when .git is present but
yields no version. `make build` stamps `git describe` too instead of
the fixed 0.1.0. .dockerignore keeps .git/config out; script/docker is
now the canonical copy.

Model: opus-5-5
This commit is contained in:
2026-10-02 10:21:22 +00:00
parent 41cea400a7
commit b4eed47511
8 changed files with 74 additions and 7 deletions
+14 -1
View File
@@ -27,7 +27,20 @@ RUN go mod download
COPY . .
RUN make test
RUN make build
# The version stamped into the binary: the VERSION build argument when one
# is given, otherwise `git describe --tags --always` of the .git the build
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
# one, the short commit when no tag is reachable. A context that carries .git
# and still yields no version fails the build.
ARG VERSION
RUN version="${VERSION:-$(git describe --tags --always)}"; \
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
[ "$version" = unknown ]; }; then \
echo "no version could be derived although the build context carries .git" >&2; \
exit 1; \
fi; \
make build VERSION="${version:-dev}"
# Runtime stage
# alpine 3.23 (2026-03-10)