Repository navigation
fix(docker): stop released images reporting dirty builds - #333
Merged
Merged
Conversation
.dockerignore excluded the whole .claude directory, but .claude/settings.json and the awtrix-berry-app skill are tracked. The build context therefore lacked three tracked files, `git status` inside the build stage saw them as deleted, and Go stamped vcs.modified=true, so /version and `ember version` reported dirty for every release (v0.46.4 at c03f29f included). Exclude only the untracked parts (.claude/worktrees, settings.local.json) so every tracked file reaches the context. A real local edit still stamps dirty. Guard: docker-publish builds an amd64 image first and refuses to push unless `ember version` reports the tagged commit without +dirty (scripts/check-image-vcs.sh); CI runs the same check on every PR, and image-smoke.sh fails on +dirty from a clean checkout.
Owner
Author
Opus reviewNo blocking findings. The root cause is real and the fix is complete for today's tree. Findings below, most severe first. Low
Nit
Verified, no issues
|
Review of #333: RUNBOOK lists the image-vcs CI job and the pre-push check in docker-publish; ARCHITECTURE gotchas say .dockerignore must never exclude a tracked file. Drop cache-from gha in image-vcs: PR runs can't restore a cache only release tags write, so it never hit. Ignore .claude/settings.local.json in the repo .gitignore so contributors without a global rule keep a clean status and image-smoke's dirty check still runs.
Owner
Author
|
Review fixes in b21275a:
actionlint is clean on both workflows. yamllint (relaxed) gives only line-length warnings on lines this PR doesn't touch. shellcheck is clean on both scripts. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #332
What was dirty and why
Every released image reported
"dirty": trueat/version(e.g. v0.46.4 at c03f29f). The binary was fine; the build context wasn't the checkout..dockerignoreexcluded the whole.claudedirectory.awtrix-berry-appskill (SKILL.md,references/awtrix-api.md)..gitinto the build stage and builds with-buildvcs=true. Go runsgit status --porcelain, sees those three files as deleted, and stampsvcs.modified=true.version(ldflags) andrevisionwere correct; onlydirtywas wrong.Fix
.dockerignorenow excludes only the untracked parts of that directory (worktrees,settings.local.json), so every tracked file reaches the context. A real edit in the context still stamps dirty.docker-publish.ymlbuilds an amd64 image (loaded, from the gha cache) before the multi-arch push, andscripts/check-image-vcs.shrefuses to publish unlessember versionshows the tagged$GITHUB_SHAwithout+dirty. It also fails on an unstamped binary (no.gitin the context).image-vcsjob runs the same check on every PR, so a future.dockerignorechange or new tracked file can't regress silently.scripts/image-smoke.shfails on+dirtywhen the host checkout is clean.Also checked, not affected:
release-producers.yml: builds from a clean tag checkout. Output goes todist/, which is gitignored. A local run ofpackage-producers.shleavesgit statusempty, and the producer hasvcs.modified=false. Producers don't expose VCS state anyway.MARKETING_VERSION/CURRENT_PROJECT_VERSIONinproject.yml, not from git. The xcodegen output (*.xcodeproj) is gitignored, and there's no dirty concept to fix.Evidence
Docker daemon not available locally, so reproduced with
go buildin a copy of the checkout filtered by.dockerignore(rsync with the same root-anchored excludes):The new
image-vcsCI job on this PR checks the real Docker build end to end.Checks:
gofmt,go vet ./...,go test ./... -racepass. hadolint (Dockerfile unchanged; only pre-existing DL3018/DL3059/DL3066 findings) andyamllint -d relaxedon both workflows (only pre-existing line-length warnings) report nothing new. shellcheck is clean on both scripts.