CI can stay green after Upstream moves the pinned tag, because the clone step is cached #25
Labels
No labels
bug
enhancement
needs-info
needs-triage
ready-for-agent
ready-for-human
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
vicoli-oss/docker-forgejo-mcp#25
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
cibuilds on the runner's shared dind daemon, and BuildKit keeps its cache across runs. The Dockerfile's clone-and-verify step (git clone --branch "$UPSTREAM_VERSION", then compareHEADwithUPSTREAM_COMMIT) is cached by its command and build args. So when neither the Pin nor the Dockerfile changes, CI reuses the old layer and never clones again.If Upstream moved the tag of the pinned Upstream Version, CI would stay green, and the next uncached build (a new runner, a pruned cache, the publish workflow) would be the first to fail.
A PR that changes the Pin isn't affected: new build args mean a cache miss, and a mismatch turns the run red (run 6 in #6).
Found by
/code-reviewon #20 / #23.Options
buildstage in CI without the cache (docker buildx build --no-cache-filter build). The Go module and build cache mounts keep it fairly quick, but every run then needs Upstream and the Alpine mirror.git ls-remote "$UPSTREAM_REPO" "refs/tags/$UPSTREAM_VERSION^{}"compared withUPSTREAM_COMMIT, as a cheap CI step ormaketarget.Acceptance criteria
cired on the next run, even with a warm cacheTriage
Decision: option 2. Check the tag outside the build with
git ls-remote.--no-cache-filter build) makes every run depend on network access from inside BuildKit, which is what broke in #22. It is also slow.Implementation notes
make verify-pin: resolve$UPSTREAM_VERSIONon Upstream withgit ls-remoteand compare it withUPSTREAM_COMMIT. Use the peeled refrefs/tags/$UPSTREAM_VERSION^{}and fall back torefs/tags/$UPSTREAM_VERSIONfor lightweight tags. v3.2.0 is annotated: the plain ref is the tag object931a525…and^{}ise30bb7e…, which matches the Pin. On a mismatch, fail with the same message as the Dockerfile check. Also fail if the tag doesn't exist.ci.yml: add a step that runsmake verify-pinbeforeBuild the Image. It runs in the job container, where DNS works.ARG UPSTREAM_REPOin the Dockerfile. Define it once (pin.envor the Makefile) and pass it to the build as a build arg, so the two checks can't drift apart.make verify-pintoo.Verifying
With a warm cache, push a throwaway commit that sets
UPSTREAM_COMMITto a wrong commit, and confirmcigoes red at the verify step before the build runs. Then revert it, as with68e52e5/c76070e.