A plain docker build ., which is how upaas builds, passed no VERSION build arg and had no .git in its context, so the binary was stamped unknown. The image now derives the version itself, the way make build does on a checkout.
.dockerignore no longer leaves out .git, nor the tracked files it used to (*.md, LICENSE, .editorconfig): git in the build would see those as deleted and add -dirty. What it still leaves out is untracked.
ARG VERSION has no default, so without a build arg make build falls back to script/version, which runs git describe on the copied .git. A VERSION build arg still wins; script/docker keeps passing the host's value.
The builder stage installs git and fails when its context carries .git and the version still comes out unknown.
Worth knowing:
A shallow clone of one branch without tags, as upaas makes, stamps the short commit hash.
Every commit, docs-only ones included, now rebuilds the image in CI, because .git changes with each commit.
.git/config now reaches the lint and build stages, so credentials stored there land in those stages' build cache. The final image copies only the binary.
Images built by script/cibuild now carry the commit: item 2 of #265.
Judgement call: the check keys on .git alone, because a VERSION build arg is stamped as given.
Judgement call: no safe.directory setting; files copied into the build belong to root, the user the build runs as.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/webhooker/issues/366
A plain `docker build .`, which is how upaas builds, passed no `VERSION` build arg and had no `.git` in its context, so the binary was stamped `unknown`. The image now derives the version itself, the way `make build` does on a checkout.
- `.dockerignore` no longer leaves out `.git`, nor the tracked files it used to (`*.md`, `LICENSE`, `.editorconfig`): git in the build would see those as deleted and add `-dirty`. What it still leaves out is untracked.
- `ARG VERSION` has no default, so without a build arg `make build` falls back to `script/version`, which runs `git describe` on the copied `.git`. A `VERSION` build arg still wins; `script/docker` keeps passing the host's value.
- The builder stage installs `git` and fails when its context carries `.git` and the version still comes out `unknown`.
Worth knowing:
- A shallow clone of one branch without tags, as upaas makes, stamps the short commit hash.
- Every commit, docs-only ones included, now rebuilds the image in CI, because `.git` changes with each commit.
- `.git/config` now reaches the lint and build stages, so credentials stored there land in those stages' build cache. The final image copies only the binary.
- Images built by `script/cibuild` now carry the commit: item 2 of https://git.eeqj.de/sneak/webhooker/issues/265.
Judgement call: the check keys on `.git` alone, because a `VERSION` build arg is stamped as given.
Judgement call: no `safe.directory` setting; files copied into the build belong to root, the user the build runs as.
Model: opus-5-5
A plain docker build, as upaas runs it, passed no VERSION build arg and
had no .git, so every such image stamped "unknown". .dockerignore now
sends .git and every tracked file (an excluded one would read as
deleted and mark the version -dirty), and the VERSION build arg loses
its "unknown" default, so script/version derives the version inside the
build. A VERSION build arg still takes precedence.
The builder stage installs git and fails when its context carries .git
and the version still comes out "unknown".
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #366
A plain
docker build ., which is how upaas builds, passed noVERSIONbuild arg and had no.gitin its context, so the binary was stampedunknown. The image now derives the version itself, the waymake builddoes on a checkout..dockerignoreno longer leaves out.git, nor the tracked files it used to (*.md,LICENSE,.editorconfig): git in the build would see those as deleted and add-dirty. What it still leaves out is untracked.ARG VERSIONhas no default, so without a build argmake buildfalls back toscript/version, which runsgit describeon the copied.git. AVERSIONbuild arg still wins;script/dockerkeeps passing the host's value.gitand fails when its context carries.gitand the version still comes outunknown.Worth knowing:
.gitchanges with each commit..git/confignow reaches the lint and build stages, so credentials stored there land in those stages' build cache. The final image copies only the binary.script/cibuildnow carry the commit: item 2 of #265.Judgement call: the check keys on
.gitalone, because aVERSIONbuild arg is stamped as given.Judgement call: no
safe.directorysetting; files copied into the build belong to root, the user the build runs as.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.