Compare commits
1
Commits
next
...
b128da7a85
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b128da7a85 |
@@ -6,6 +6,11 @@ WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
# script/cibuild sets CHECK_EPOCH to the current time, so every step below
|
||||
# runs again on each build, an unchanged tree included, while the steps
|
||||
# above stay cached. ARG is per stage: the build stage declares it too.
|
||||
ARG CHECK_EPOCH
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN make fmt-check
|
||||
@@ -25,6 +30,9 @@ WORKDIR /build
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
# As in the lint stage: the steps below run again on each script/cibuild.
|
||||
ARG CHECK_EPOCH
|
||||
|
||||
COPY . .
|
||||
|
||||
RUN make test
|
||||
|
||||
@@ -521,7 +521,8 @@ them. We provide:
|
||||
- `script/docker` — build the Docker image tagged with the project name
|
||||
- `script/cibuild` — CI entrypoint: `docker build --ulimit
|
||||
memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the
|
||||
checks)
|
||||
checks), with a new `CHECK_EPOCH` build argument on every run so the
|
||||
checks run again on an unchanged tree
|
||||
- `script/precommit` — pre-commit checks: `go mod tidy` verification,
|
||||
then `script/check`
|
||||
- `script/install-precommit` — install the git pre-commit hook that
|
||||
|
||||
@@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit:
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: `script/cibuild` runs the checks again on an unchanged
|
||||
tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the
|
||||
current time as the `CHECK_EPOCH` build argument, which both the lint
|
||||
and the build stage of the `Dockerfile` declare after their module
|
||||
download, so every step from `COPY . .` on runs on each build while
|
||||
the base images and module downloads stay cached. Before, a second run
|
||||
on the same tree took every check from the build cache and reported
|
||||
success having run nothing.
|
||||
- 2026-10-04: `secret get` keeps the secret in locked memory until it
|
||||
writes it out (https://git.eeqj.de/sneak/secret/issues/37):
|
||||
`Vault.GetSecret` and `Vault.GetSecretVersion` return a
|
||||
|
||||
+5
-1
@@ -4,13 +4,17 @@
|
||||
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
||||
# that lock large secrets in memory (memguard mlocks them) run; under the
|
||||
# lower limit of a plain `docker build .` they are skipped.
|
||||
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
|
||||
# Dockerfile's check steps run again on an unchanged tree, while its base
|
||||
# images and module downloads stay cached.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
docker build --ulimit memlock=-1:-1 .
|
||||
docker build --ulimit memlock=-1:-1 \
|
||||
--build-arg CHECK_EPOCH="$(date +%s)" .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
Reference in New Issue
Block a user