1 Commits
Author SHA1 Message Date
sneak 9830ce7943 Build with the local docker daemon; add script/build (closes #44)
check / check (push) Waiting to run
The Makefile exported DOCKER_HOST pointing at one private machine, so
every docker call made through make, `make lint` and `make check`
included, failed everywhere else. The line is gone: docker uses the
local daemon, or a DOCKER_HOST set in the environment.

`make build` now calls the new `script/build`, which stamps the version
and commit as the Makefile did. A VERSION set in the environment now
wins over `git describe`, not only one given as `make build VERSION=x`.
build, clean, install and docker-run are phony; install depends on
build. The vet target is removed: `script/test` runs `go vet` first.

Model: opus-5-5
2026-10-04 06:45:12 +00:00
6 changed files with 53 additions and 55 deletions
+1 -4
View File
@@ -16,9 +16,6 @@ coverage.out
*.swo *.swo
*~ *~
# Dependencies
node_modules
# macOS # macOS
.DS_Store .DS_Store
@@ -26,4 +23,4 @@ node_modules
.claude/ .claude/
# Local settings # Local settings
.claude/settings.local.json .claude/settings.local.json
+7 -29
View File
@@ -1,34 +1,12 @@
# OS
.DS_Store .DS_Store
Thumbs.db **/.DS_Store
# Editors
*.swp
*.swo
*~
*.bak
.idea/
.vscode/
*.sublime-*
# Agent scratch (worktrees of this repo, created and destroyed by
# in-flight tooling). Unanchored: .gitignore patterns already match at
# every depth, so no prefix is wanted here. This is not a .dockerignore
# entry and must not be given a `**/` prefix on the way into one.
.claude/
# Node
node_modules/
# Environment / secrets
.env
.env.*
*.pem
*.key
# This repo. /secret is the built binary, anchored so that it does not
# also match the internal/secret/ package directory.
/secret /secret
*.log *.log
cli.test
vault.test
*.test *.test
settings.local.json settings.local.json
# Stale files
.cursorrules
coverage.out
+6 -16
View File
@@ -1,13 +1,7 @@
export CGO_ENABLED=1 export CGO_ENABLED=1
export DOCKER_HOST := ssh://root@ber1app1.local
# Version information .PHONY: default bootstrap setup build test lint fmt fmt-check check docker \
VERSION := $(shell git describe --tags --always --dirty 2>/dev/null || echo "dev") docker-run clean install hooks
GIT_COMMIT := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown")
LDFLAGS := -X 'git.eeqj.de/sneak/secret/internal/cli.Version=$(VERSION)' \
-X 'git.eeqj.de/sneak/secret/internal/cli.GitCommit=$(GIT_COMMIT)'
.PHONY: default bootstrap setup test lint fmt fmt-check check docker hooks vet
default: check default: check
@@ -17,13 +11,9 @@ bootstrap:
setup: setup:
@script/setup @script/setup
build: ./secret # Build ./secret; `make build VERSION=x` stamps x instead of `git describe`
build:
./secret: ./internal/*/*.go ./pkg/*/*.go ./cmd/*/*.go ./go.* @script/build
go build -v -ldflags "$(LDFLAGS)" -o $@ cmd/secret/main.go
vet:
go vet ./...
test: test:
@script/test @script/test
@@ -49,7 +39,7 @@ docker-run:
clean: clean:
rm -f ./secret rm -f ./secret
install: ./secret install: build
cp ./secret $(HOME)/bin/secret cp ./secret $(HOME)/bin/secret
fmt-check: fmt-check:
+3
View File
@@ -506,6 +506,9 @@ them. We provide:
`script/bootstrap`, then `script/install-precommit` `script/bootstrap`, then `script/install-precommit`
- `script/projectname` — output the project name (`secret`); used by - `script/projectname` — output the project name (`secret`); used by
other scripts such as `script/docker` other scripts such as `script/docker`
- `script/build` — build the `secret` binary into the repo root, stamping
the version (`VERSION` from the environment, else `git describe`) and
the git commit
- `script/test` — run `go vet` and the test suite (verbose rerun on - `script/test` — run `go vet` and the test suite (verbose rerun on
failure) failure)
- `script/lint` — run `golangci-lint` in docker only: builds - `script/lint` — run `golangci-lint` in docker only: builds
+7 -6
View File
@@ -25,12 +25,13 @@ Bring the repo into policy compliance in one commit:
# Completed Steps # Completed Steps
- 2026-10-04: `.gitignore` is the org's standard file, which ignores - 2026-10-04: The `Makefile` no longer sets `DOCKER_HOST`, so its docker
`.env`, `.env.*`, `*.pem` and `*.key` and editor and OS files, plus targets use the local docker daemon, or whatever `DOCKER_HOST` the
this repo's `/secret`, `*.log`, `*.test` and `settings.local.json` environment sets. `make build` calls the new `script/build`, which
(https://git.eeqj.de/sneak/secret/issues/40). `.dockerignore` also stamps the version (`VERSION` from the environment, else
leaves out `node_modules`; `.git` stays in the build context for the `git describe`) and the git commit as before. `build`, `clean`,
version stamp. `install` and `docker-run` are in `.PHONY`; `make install` depends on
`build`. The `vet` target is gone: `script/test` runs `go vet` first.
- 2026-10-04: `secret init` refuses when the default vault exists, and - 2026-10-04: `secret init` refuses when the default vault exists, and
`secret vault create NAME` when `NAME` does, with "vault NAME already `secret vault create NAME` when `NAME` does, with "vault NAME already
exists", before writing anything. The check is in `vault.CreateVault`, exists", before writing anything. The check is in `vault.CreateVault`,
Executable
+29
View File
@@ -0,0 +1,29 @@
#!/bin/sh
# script/build: build the `secret` binary into the repo root, with its
# version and git commit stamped in (`secret info` shows both).
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
# CGO is required (Makefile exports this too)
export CGO_ENABLED=1
# A VERSION set in the environment wins (`make build VERSION=x`, as
# the Dockerfile does); otherwise `git describe` of this checkout.
version="${VERSION:-}"
if [ -z "$version" ]; then
version="$(git describe --tags --always --dirty 2>/dev/null ||
echo dev)"
fi
commit="$(git rev-parse HEAD 2>/dev/null || echo unknown)"
pkg=git.eeqj.de/sneak/secret/internal/cli
# Build the file, not the package `./cmd/secret`: a package build
# also stamps git status into the binary and fails where git cannot
# read the checkout, instead of falling back to `dev`/`unknown`.
go build -v \
-ldflags "-X '$pkg.Version=$version' -X '$pkg.GitCommit=$commit'" \
-o secret cmd/secret/main.go
}
main "$@"