check / check (push) Waiting to run
.dockerignore now sends .git, without .git/config, which can hold a credential. The build stage takes the VERSION build argument when one is given, otherwise git describe --tags --always of that .git, and fails if the context carries .git and still yields no version. A plain docker build . used to stamp dev. The CI checkout fetches full history so CI sees the tag and stamps the same value as make build. Model: opus-5-5
35 lines
1.5 KiB
Bash
Executable File
35 lines
1.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/cibuild: run the CI build. The Gitea workflow runs this on
|
|
# push.
|
|
#
|
|
# The Dockerfile runs the gates individually as build steps, not the
|
|
# make check aggregate: the lint stage runs make fmt-check,
|
|
# script/verify-lint-image-pin, golangci-lint config verify and
|
|
# golangci-lint run; the build stage, dropped to an unprivileged user,
|
|
# runs make test and make fmt-check. Neither make lint nor make check
|
|
# appears, because both reach script/lint, which is itself a docker
|
|
# build, and a docker build cannot run inside one. Lint is not skipped
|
|
# by that — the linter is invoked directly in the lint stage, and the
|
|
# build stage's COPY --from=lint makes that stage a prerequisite, so
|
|
# BuildKit must finish it first. Between the two stages everything
|
|
# make check would run has run, which is why a successful build here
|
|
# implies the repo is green.
|
|
#
|
|
# That implication holds only because of CHECK_EPOCH. A COPY layer is
|
|
# invalidated only by changed content, and a rebuild of an unchanged
|
|
# checkout sends the same content, so without a fresh value here Docker
|
|
# serves the gate layers from cache and the build reports a green it
|
|
# never earned. Passing the current epoch invalidates the gate
|
|
# layers on every run while leaving the pinned base images and
|
|
# go mod download cached; see the Dockerfile for the placement.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
docker build --build-arg CHECK_EPOCH="$(date +%s)" .
|
|
}
|
|
|
|
main "$@"
|