The stage that compiles has git and takes the version from the VERSION build argument when one is given, otherwise from git describe --tags --always (a tag when the commit has one, otherwise the short commit). ARG VERSION has no default.
The build fails if the context carries .git and the version still comes out empty, dev or unknown.
Host-side scripts that already pass --build-arg VERSION=... may keep doing so.
Any buildarch left in the repo goes too (sneak/project-management#19): the architecture is read at run time from runtime.GOARCH.
Definition of done:
A fresh clone, then docker build . with no build arguments, then running the binary: its version output shows the commit's tag or short commit, never dev, unknown or empty.
docker build --build-arg VERSION=x . stamps x; a context with .git from which no version can be derived fails the build.
make check passes; PR to next; independent review; squash.
Model: opus-5-5
Owner's words (chat, 2026-10-02 ~00:00 UTC; the rollout across repos is https://git.eeqj.de/sneak/project-management/issues/21):
> main.Version on sneak/api is set to "dev" instead of the git hash when being built under upaas, fix that
> audit all other repos for that same bug. "docker build ." should pick up the git short rev or tag
Today: `.dockerignore` excludes `.git` and the builder declares `ARG VERSION=dev`, so a plain `docker build .` stamps `dev`.
The convention (canonical text: https://git.eeqj.de/sneak/prompts/issues/69; working examples: https://git.eeqj.de/sneak/upaas/pulls/242, https://git.eeqj.de/sneak/webhooker/pulls/410):
- `.dockerignore` lets `.git` into the build context.
- The stage that compiles has `git` and takes the version from the `VERSION` build argument when one is given, otherwise from `git describe --tags --always` (a tag when the commit has one, otherwise the short commit). `ARG VERSION` has no default.
- The build fails if the context carries `.git` and the version still comes out empty, `dev` or `unknown`.
- Host-side scripts that already pass `--build-arg VERSION=...` may keep doing so.
- Any `buildarch` left in the repo goes too (https://git.eeqj.de/sneak/project-management/issues/19): the architecture is read at run time from `runtime.GOARCH`.
Definition of done:
- A fresh clone, then `docker build .` with no build arguments, then running the binary: its version output shows the commit's tag or short commit, never `dev`, `unknown` or empty.
- `docker build --build-arg VERSION=x .` stamps `x`; a context with `.git` from which no version can be derived fails the build.
- `make check` passes; PR to `next`; independent review; squash.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Owner's words (chat, 2026-10-02 ~00:00 UTC; the rollout across repos is sneak/project-management#21):
Today:
.dockerignoreexcludes.gitand the builder declaresARG VERSION=dev, so a plaindocker build .stampsdev.The convention (canonical text: sneak/prompts#69; working examples: sneak/upaas#242, sneak/webhooker#410):
.dockerignorelets.gitinto the build context.gitand takes the version from theVERSIONbuild argument when one is given, otherwise fromgit describe --tags --always(a tag when the commit has one, otherwise the short commit).ARG VERSIONhas no default..gitand the version still comes out empty,devorunknown.--build-arg VERSION=...may keep doing so.buildarchleft in the repo goes too (sneak/project-management#19): the architecture is read at run time fromruntime.GOARCH.Definition of done:
docker build .with no build arguments, then running the binary: its version output shows the commit's tag or short commit, neverdev,unknownor empty.docker build --build-arg VERSION=x .stampsx; a context with.gitfrom which no version can be derived fails the build.make checkpasses; PR tonext; independent review; squash.Model: opus-5-5