Derive the image's version from the .git in the build context (closes #366)
check / check (push) Waiting to run
check / check (push) Waiting to run
A plain docker build, as upaas runs it, passed no VERSION build arg and had no .git, so every such image stamped "unknown". .dockerignore now sends .git without its config, which can carry a credential, and every tracked file (an excluded one would read as deleted and mark the version -dirty). The VERSION build arg loses its "unknown" default, so script/version derives the version inside the build; a given VERSION still takes precedence. The builder stage installs git, trusts the copied checkout whoever owns its files, and fails when its context carries .git and the version still comes out "unknown". The CI fingerprint is now the commit being checked. Model: opus-5-5
This commit is contained in:
+3
-3
@@ -2,9 +2,9 @@
|
||||
# script/docker: build the Docker image tagged with the project name.
|
||||
# The tag comes from script/projectname.
|
||||
#
|
||||
# .dockerignore excludes .git/, so the builder stage cannot derive the
|
||||
# version itself. It is resolved here, where the checkout is, and passed
|
||||
# in as a build arg; without it the image would stamp itself "unknown".
|
||||
# The version script/version resolves here goes in as the VERSION build
|
||||
# arg, which takes precedence over what the build would derive from the
|
||||
# .git in its context.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
|
||||
+5
-7
@@ -7,18 +7,16 @@
|
||||
#
|
||||
# Order of precedence:
|
||||
#
|
||||
# 1. $VERSION, if set and non-empty. This is how the value reaches a
|
||||
# build that cannot derive it: .dockerignore excludes .git/, so the
|
||||
# builder stage has no git metadata and the Dockerfile takes the
|
||||
# value as a build arg instead.
|
||||
# 1. $VERSION, if set and non-empty: an explicit value, such as the
|
||||
# Dockerfile's VERSION build arg.
|
||||
# 2. `git describe --tags --always --dirty` against this checkout. At
|
||||
# a clean tagged commit that is exactly the tag; otherwise it
|
||||
# carries the short SHA, the commit distance when a tag is
|
||||
# reachable, and a -dirty suffix for uncommitted changes.
|
||||
# 3. "unknown", for a tree with no git metadata and no $VERSION -- a
|
||||
# source tarball, or `docker build .` with no --build-arg. That
|
||||
# case must not fail the build and must not name a tag the tree may
|
||||
# not be at, so it names nothing.
|
||||
# source tarball, or a `docker build` with no .git in its context
|
||||
# and no VERSION build arg. That case must not fail the build and
|
||||
# must not name a tag the tree may not be at, so it names nothing.
|
||||
#
|
||||
# The git step insists the enclosing repository is this checkout, not
|
||||
# merely some repository above it: an unpacked tarball sitting inside an
|
||||
|
||||
Reference in New Issue
Block a user