Derive the image's version from the .git in the build context (closes #366)
check / check (push) Successful in 4m36s

A plain docker build, as upaas runs it, passed no VERSION build arg and
had no .git, so every such image stamped "unknown". .dockerignore now
sends .git without its config, which can carry a credential, and every
tracked file (an excluded one would read as deleted and mark the version
-dirty). The VERSION build arg loses its "unknown" default, so
script/version derives the version inside the build; a given VERSION
still takes precedence.

The builder stage installs git, trusts the copied checkout whoever owns
its files, and fails when its context carries .git and the version still
comes out "unknown". The CI fingerprint is now the commit being checked.

Model: opus-5-5
This commit is contained in:
2026-10-02 02:28:33 +00:00
parent bfdbc937c6
commit defccd38f6
8 changed files with 85 additions and 68 deletions
+8 -4
View File
@@ -1,14 +1,18 @@
# .git is sent, without its config, so the build can derive the version it
# stamps into the binary (script/version). The config can hold a remote URL
# carrying a credential, and `git describe` does not need it.
.git/config
# No tracked file may be listed here: git in the build would see it as
# deleted and mark the version -dirty.
#
# .ci-fingerprint is deliberately NOT excluded: it is the CI cache barrier
# that keeps the check stages from replaying a cached pass. See the lint
# stage of the Dockerfile.
.git/
bin/
# Extracted from 3p/ by `make assets` inside the build; a host copy is not
# needed. The tarball in 3p/ must stay in the context.
static/js/alpine.min.js
*.md
LICENSE
.editorconfig
.env
.env.*
*.db