From 433eb7b5d9c98aad1239b644f167d20f01928d36 Mon Sep 17 00:00:00 2001 From: Manas Srivastava Date: Tue, 12 May 2026 16:18:39 +0530 Subject: [PATCH] worker: Dockerfile ldflags + smoke-buildinfo target for commit_sha (track 1/8) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Dockerfile: ARG GIT_SHA / BUILD_TIME / VERSION, passed into `go build -ldflags -X instant.dev/common/buildinfo.X=...` so the resulting worker binary stamps its own commit on every log line and /healthz response. - Makefile: docker-build now forwards --build-arg from `make` vars (which default to `git rev-parse --short HEAD` etc). - New `make smoke-buildinfo` target builds cmd/smoke-buildinfo with override values and asserts they appear at runtime — CI regression gate for the ldflag path. Companion change in common (PR #2 adds the buildinfo package). Co-Authored-By: Claude Opus 4.7 (1M context) --- Dockerfile | 9 ++++++++- Makefile | 30 ++++++++++++++++++++++++++++-- cmd/smoke-buildinfo/main.go | 17 +++++++++++++++++ 3 files changed, 53 insertions(+), 3 deletions(-) create mode 100644 cmd/smoke-buildinfo/main.go diff --git a/Dockerfile b/Dockerfile index eb716f5..6e85937 100644 --- a/Dockerfile +++ b/Dockerfile @@ -5,7 +5,14 @@ COPY common/ /common/ COPY worker/go.mod worker/go.sum ./ RUN go mod download COPY worker/ . -RUN CGO_ENABLED=0 go build -o /worker . +# Build-time metadata injected via -ldflags into instant.dev/common/buildinfo. +# Defaults keep the build runnable without --build-arg; CI passes real values. +ARG GIT_SHA=dev +ARG BUILD_TIME=unknown +ARG VERSION=dev +RUN CGO_ENABLED=0 go build \ + -ldflags "-X instant.dev/common/buildinfo.GitSHA=${GIT_SHA} -X instant.dev/common/buildinfo.BuildTime=${BUILD_TIME} -X instant.dev/common/buildinfo.Version=${VERSION}" \ + -o /worker . FROM gcr.io/distroless/static-debian12 COPY --from=builder /worker /worker diff --git a/Makefile b/Makefile index 029d66c..4110928 100644 --- a/Makefile +++ b/Makefile @@ -1,4 +1,11 @@ -.PHONY: build test docker-build run +.PHONY: build test docker-build run smoke-buildinfo + +# Build-time metadata injected into instant.dev/common/buildinfo via -ldflags. +# Override on the make line if needed. GIT_SHA falls back to "dev" when not +# in a git checkout (e.g. CI tarball builds). +GIT_SHA ?= $(shell git rev-parse --short HEAD 2>/dev/null || echo dev) +BUILD_TIME ?= $(shell date -u +%Y-%m-%dT%H:%M:%SZ) +VERSION ?= dev build: go build ./... @@ -7,7 +14,26 @@ test: go test ./... -race -count=1 docker-build: - docker build -f Dockerfile -t instant-worker:local .. + docker build -f Dockerfile -t instant-worker:local \ + --build-arg GIT_SHA=$(GIT_SHA) \ + --build-arg BUILD_TIME=$(BUILD_TIME) \ + --build-arg VERSION=$(VERSION) \ + .. run: go run . + +# Verifies the -ldflags injection wires through to instant.dev/common/buildinfo. +# Builds the smoke helper with override values and asserts they appear at +# runtime. CI runs this on every PR to catch a regression where someone +# breaks the ldflag path. +smoke-buildinfo: + @tmpdir=$$(mktemp -d) && \ + go build -ldflags "-X instant.dev/common/buildinfo.GitSHA=smoke-sha -X instant.dev/common/buildinfo.BuildTime=smoke-time -X instant.dev/common/buildinfo.Version=smoke-ver" \ + -o $$tmpdir/smoke ./cmd/smoke-buildinfo && \ + out=$$($$tmpdir/smoke) && \ + echo "$$out" | grep -q "GitSHA=smoke-sha" || (echo "FAIL: $$out" && exit 1) && \ + echo "$$out" | grep -q "BuildTime=smoke-time" || (echo "FAIL: $$out" && exit 1) && \ + echo "$$out" | grep -q "Version=smoke-ver" || (echo "FAIL: $$out" && exit 1) && \ + echo "smoke-buildinfo: OK ($$out)" && \ + rm -rf $$tmpdir diff --git a/cmd/smoke-buildinfo/main.go b/cmd/smoke-buildinfo/main.go new file mode 100644 index 0000000..d0d8513 --- /dev/null +++ b/cmd/smoke-buildinfo/main.go @@ -0,0 +1,17 @@ +// Command smoke-buildinfo prints the linked-in buildinfo values to stdout. +// +// Used by `make smoke-buildinfo` to verify the -ldflags -X path actually +// flows through to instant.dev/common/buildinfo at link time. The CI +// signal is "did the override land?" — not how the values are formatted. +package main + +import ( + "fmt" + + "instant.dev/common/buildinfo" +) + +func main() { + fmt.Printf("GitSHA=%s BuildTime=%s Version=%s\n", + buildinfo.GitSHA, buildinfo.BuildTime, buildinfo.Version) +}