Compare commits
1
Commits
next
...
b128da7a85
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b128da7a85 |
@@ -6,6 +6,11 @@ WORKDIR /src
|
|||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|
||||||
|
# script/cibuild sets CHECK_EPOCH to the current time, so every step below
|
||||||
|
# runs again on each build, an unchanged tree included, while the steps
|
||||||
|
# above stay cached. ARG is per stage: the build stage declares it too.
|
||||||
|
ARG CHECK_EPOCH
|
||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
RUN make fmt-check
|
RUN make fmt-check
|
||||||
@@ -25,6 +30,9 @@ WORKDIR /build
|
|||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
|
|
||||||
|
# As in the lint stage: the steps below run again on each script/cibuild.
|
||||||
|
ARG CHECK_EPOCH
|
||||||
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
RUN make test
|
RUN make test
|
||||||
|
|||||||
@@ -521,7 +521,8 @@ them. We provide:
|
|||||||
- `script/docker` — build the Docker image tagged with the project name
|
- `script/docker` — build the Docker image tagged with the project name
|
||||||
- `script/cibuild` — CI entrypoint: `docker build --ulimit
|
- `script/cibuild` — CI entrypoint: `docker build --ulimit
|
||||||
memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the
|
memlock=-1:-1 .` (memguard needs mlock; the Dockerfile runs the
|
||||||
checks)
|
checks), with a new `CHECK_EPOCH` build argument on every run so the
|
||||||
|
checks run again on an unchanged tree
|
||||||
- `script/precommit` — pre-commit checks: `go mod tidy` verification,
|
- `script/precommit` — pre-commit checks: `go mod tidy` verification,
|
||||||
then `script/check`
|
then `script/check`
|
||||||
- `script/install-precommit` — install the git pre-commit hook that
|
- `script/install-precommit` — install the git pre-commit hook that
|
||||||
|
|||||||
@@ -25,6 +25,14 @@ Bring the repo into policy compliance in one commit:
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-04: `script/cibuild` runs the checks again on an unchanged
|
||||||
|
tree (https://git.eeqj.de/sneak/secret/issues/54). It passes the
|
||||||
|
current time as the `CHECK_EPOCH` build argument, which both the lint
|
||||||
|
and the build stage of the `Dockerfile` declare after their module
|
||||||
|
download, so every step from `COPY . .` on runs on each build while
|
||||||
|
the base images and module downloads stay cached. Before, a second run
|
||||||
|
on the same tree took every check from the build cache and reported
|
||||||
|
success having run nothing.
|
||||||
- 2026-10-04: `secret get` keeps the secret in locked memory until it
|
- 2026-10-04: `secret get` keeps the secret in locked memory until it
|
||||||
writes it out (https://git.eeqj.de/sneak/secret/issues/37):
|
writes it out (https://git.eeqj.de/sneak/secret/issues/37):
|
||||||
`Vault.GetSecret` and `Vault.GetSecretVersion` return a
|
`Vault.GetSecret` and `Vault.GetSecretVersion` return a
|
||||||
|
|||||||
+5
-1
@@ -4,13 +4,17 @@
|
|||||||
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
||||||
# that lock large secrets in memory (memguard mlocks them) run; under the
|
# that lock large secrets in memory (memguard mlocks them) run; under the
|
||||||
# lower limit of a plain `docker build .` they are skipped.
|
# lower limit of a plain `docker build .` they are skipped.
|
||||||
|
# A cached build checks nothing: a new CHECK_EPOCH on every run makes the
|
||||||
|
# Dockerfile's check steps run again on an unchanged tree, while its base
|
||||||
|
# images and module downloads stay cached.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
docker build --ulimit memlock=-1:-1 .
|
docker build --ulimit memlock=-1:-1 \
|
||||||
|
--build-arg CHECK_EPOCH="$(date +%s)" .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user