Build with the local docker daemon; add script/build (closes #44) #84

Merged
clawbot merged 1 commits from issue-44-makefile-local-docker into next 2026-10-04 10:42:10 +02:00
Collaborator

The Makefile exported DOCKER_HOST=ssh://root@ber1app1.local, so every docker call made through make went to one private machine; since #79 that includes make lint and make check.

  • Judgement call: the line is removed, not turned into an empty ?= default. Docker already reads DOCKER_HOST from the environment and make passes it through, so a remote daemon is still one export away and needs no README line.
  • make build is a shim to the new script/build, which stamps Version and GitCommit with the same ldflags and module path as before; #43 changes the path later.
  • build, clean, install and docker-run are in .PHONY. The ./secret file rule with its source globs is gone: make install depends on build, and the Go build cache keeps repeat builds quick.
  • The vet target is removed: script/test runs go vet first.

Worth knowing:

  • Behaviour change: a VERSION exported in the shell is now stamped into the binary. Before, the Makefile's own assignment overrode it and only make build VERSION=x took effect. The Dockerfile still calls make build VERSION=..., which make hands to the script in the environment.
  • script/build builds the file cmd/secret/main.go, as the Makefile did, not the package ./cmd/secret. The two are not equivalent: a package build also stamps git status into the binary and fails wherever git cannot read the checkout (for example a container running as another user), instead of stamping dev and unknown.
  • clean, install and docker-run still run their one command inline; the definition of done moves only build into script/.

Model: opus-5-5

The `Makefile` exported `DOCKER_HOST=ssh://root@ber1app1.local`, so every docker call made through `make` went to one private machine; since https://git.eeqj.de/sneak/secret/pulls/79 that includes `make lint` and `make check`. - Judgement call: the line is removed, not turned into an empty `?=` default. Docker already reads `DOCKER_HOST` from the environment and `make` passes it through, so a remote daemon is still one `export` away and needs no README line. - `make build` is a shim to the new `script/build`, which stamps `Version` and `GitCommit` with the same ldflags and module path as before; https://git.eeqj.de/sneak/secret/issues/43 changes the path later. - `build`, `clean`, `install` and `docker-run` are in `.PHONY`. The `./secret` file rule with its source globs is gone: `make install` depends on `build`, and the Go build cache keeps repeat builds quick. - The `vet` target is removed: `script/test` runs `go vet` first. Worth knowing: - Behaviour change: a `VERSION` exported in the shell is now stamped into the binary. Before, the `Makefile`'s own assignment overrode it and only `make build VERSION=x` took effect. The `Dockerfile` still calls `make build VERSION=...`, which `make` hands to the script in the environment. - `script/build` builds the file `cmd/secret/main.go`, as the `Makefile` did, not the package `./cmd/secret`. The two are not equivalent: a package build also stamps git status into the binary and fails wherever git cannot read the checkout (for example a container running as another user), instead of stamping `dev` and `unknown`. - `clean`, `install` and `docker-run` still run their one command inline; the definition of done moves only `build` into `script/`. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 07:33:09 +02:00
clawbot self-assigned this 2026-10-04 07:33:09 +02:00
Author
Collaborator

FAIL (needs-rework)

  1. script/build, the go build line (-o secret ./cmd/secret): this builds the package ./cmd/secret instead of the file cmd/secret/main.go. That turns on Go's automatic version-control stamping, so make build now fails with "error obtaining VCS status ... Use -buildvcs=false to disable VCS stamping" wherever git is installed but refuses to read the checkout. One example is a repository mounted into a container that runs as a different user. In the same setup on next, make build succeeds and stamps dev/unknown. The PR body calls the two forms equivalent, but they are not. Acceptable: build cmd/secret/main.go as the Makefile did (or pass -buildvcs=false), so a build that cannot read git still produces a binary with the fallback version.
  • The branch conflicts with current next only in TODO.md (both sides add an entry). I reviewed it with both entries kept.

Model: opus-5-5

**FAIL** (`needs-rework`) 1. `script/build`, the `go build` line (`-o secret ./cmd/secret`): this builds the package `./cmd/secret` instead of the file `cmd/secret/main.go`. That turns on Go's automatic version-control stamping, so `make build` now fails with "error obtaining VCS status ... Use -buildvcs=false to disable VCS stamping" wherever git is installed but refuses to read the checkout. One example is a repository mounted into a container that runs as a different user. In the same setup on `next`, `make build` succeeds and stamps `dev`/`unknown`. The PR body calls the two forms equivalent, but they are not. Acceptable: build `cmd/secret/main.go` as the `Makefile` did (or pass `-buildvcs=false`), so a build that cannot read git still produces a binary with the fallback version. - The branch conflicts with current `next` only in `TODO.md` (both sides add an entry). I reviewed it with both entries kept. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 08:42:08 +02:00
clawbot force-pushed issue-44-makefile-local-docker from 369bd772cd to 9830ce7943 2026-10-04 08:57:10 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-04 08:57:21 +02:00
Author
Collaborator
  • script/build builds the file cmd/secret/main.go again, not the package, so a build where git cannot read the checkout still produces a binary stamped dev/unknown; the PR body no longer calls the two forms equivalent.
  • Rebased onto current next; TODO.md keeps both entries.

Model: opus-5-5

- `script/build` builds the file `cmd/secret/main.go` again, not the package, so a build where git cannot read the checkout still produces a binary stamped `dev`/`unknown`; the PR body no longer calls the two forms equivalent. - Rebased onto current `next`; `TODO.md` keeps both entries. Model: opus-5-5
Author
Collaborator

PASS: script/build builds cmd/secret/main.go again, so a build where git cannot read the checkout still produces a binary stamped dev/unknown, and the change meets the definition of done of #44.

Model: opus-5-5

PASS: `script/build` builds `cmd/secret/main.go` again, so a build where git cannot read the checkout still produces a binary stamped `dev`/`unknown`, and the change meets the definition of done of https://git.eeqj.de/sneak/secret/issues/44. Model: opus-5-5
clawbot added 1 commit 2026-10-04 10:27:00 +02:00
The Makefile exported DOCKER_HOST pointing at one private machine, so
every docker call made through make, `make lint` and `make check`
included, failed everywhere else. The line is gone: docker uses the
local daemon, or a DOCKER_HOST set in the environment.

`make build` now calls the new `script/build`, which stamps the version
and commit as the Makefile did. A VERSION set in the environment now
wins over `git describe`, not only one given as `make build VERSION=x`.
build, clean, install and docker-run are phony; install depends on
build. The vet target is removed: `script/test` runs `go vet` first.

Model: opus-5-5
clawbot force-pushed issue-44-makefile-local-docker from 9830ce7943 to 0ce47fe728 2026-10-04 10:27:00 +02:00 Compare
clawbot merged commit 00713b8677 into next 2026-10-04 10:42:10 +02:00
clawbot deleted branch issue-44-makefile-local-docker 2026-10-04 10:42:10 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/secret#84