Closes #21. A plain docker build . of a clone, which is how upaas builds, stamped dev: .dockerignore left out .git and the build stage declared ARG VERSION=dev.
.dockerignore sends .git but keeps out .git/config, which can hold a credential and which git describe does not need; the comment is the canonical one from sneak/prompts.
The build stage (its Debian Go image has git) stamps the VERSION build argument when one is given, otherwise git describe --tags --always: the tag on a tagged commit, tag-N-gHASH after one, the short commit when no tag is reachable. If the context carries .git and the version is still empty, dev or unknown, the build fails, as in the canonical step.
script/docker says it is identical in all repos, so it is now the canonical copy: it builds with --no-cache and passes git describe --tags --always --dirty as VERSION.
What the diff does not show:
script/cibuild passes no version, so CI now takes it from .git in the build.
Dockerfile.lint shares .dockerignore, so .git reaches the lint build too.
No buildarch in the repo.
Disclosures:
A context with neither .git nor VERSION (a source tarball) now stamps an empty version instead of dev, as the canonical template does.
Judgement call: this repo's .dockerignore is not a copy of the canonical one, so only the .git/config block comes from it.
docs/REPO_POLICIES.md still shows ARG VERSION=dev; it is the synced canonical copy, left alone.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/simplexcalc/issues/21. A plain `docker build .` of a clone, which is how upaas builds, stamped `dev`: `.dockerignore` left out `.git` and the build stage declared `ARG VERSION=dev`.
- `.dockerignore` sends `.git` but keeps out `.git/config`, which can hold a credential and which `git describe` does not need; the comment is the canonical one from `sneak/prompts`.
- The build stage (its Debian Go image has `git`) stamps the `VERSION` build argument when one is given, otherwise `git describe --tags --always`: the tag on a tagged commit, `tag-N-gHASH` after one, the short commit when no tag is reachable. If the context carries `.git` and the version is still empty, `dev` or `unknown`, the build fails, as in the canonical step.
- `script/docker` says it is identical in all repos, so it is now the canonical copy: it builds with `--no-cache` and passes `git describe --tags --always --dirty` as `VERSION`.
What the diff does not show:
- `script/cibuild` passes no version, so CI now takes it from `.git` in the build.
- `Dockerfile.lint` shares `.dockerignore`, so `.git` reaches the lint build too.
- No `buildarch` in the repo.
Disclosures:
- A context with neither `.git` nor `VERSION` (a source tarball) now stamps an empty version instead of `dev`, as the canonical template does.
- Judgement call: this repo's `.dockerignore` is not a copy of the canonical one, so only the `.git/config` block comes from it.
- `docs/REPO_POLICIES.md` still shows `ARG VERSION=dev`; it is the synced canonical copy, left alone.
Model: opus-5-5
A plain `docker build .` of a clone stamped `dev`: `.dockerignore` left
out `.git` and the build stage declared `ARG VERSION=dev`. `.git` now
reaches the build context without `.git/config`, which can hold a
credential, and the build stage takes the VERSION build argument when
given, otherwise `git describe --tags --always`. A context that carries
`.git` but yields no version fails the build.
`script/docker` is replaced with the current canonical copy, which
passes the version it derives on the host.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #21. A plain
docker build .of a clone, which is how upaas builds, stampeddev:.dockerignoreleft out.gitand the build stage declaredARG VERSION=dev..dockerignoresends.gitbut keeps out.git/config, which can hold a credential and whichgit describedoes not need; the comment is the canonical one fromsneak/prompts.git) stamps theVERSIONbuild argument when one is given, otherwisegit describe --tags --always: the tag on a tagged commit,tag-N-gHASHafter one, the short commit when no tag is reachable. If the context carries.gitand the version is still empty,devorunknown, the build fails, as in the canonical step.script/dockersays it is identical in all repos, so it is now the canonical copy: it builds with--no-cacheand passesgit describe --tags --always --dirtyasVERSION.What the diff does not show:
script/cibuildpasses no version, so CI now takes it from.gitin the build.Dockerfile.lintshares.dockerignore, so.gitreaches the lint build too.buildarchin the repo.Disclosures:
.gitnorVERSION(a source tarball) now stamps an empty version instead ofdev, as the canonical template does..dockerignoreis not a copy of the canonical one, so only the.git/configblock comes from it.docs/REPO_POLICIES.mdstill showsARG VERSION=dev; it is the synced canonical copy, left alone.Model: opus-5-5
Review passed.
Model: opus-5-5