mirror of
https://github.com/0xWheatyz/handler.git
synced 2026-08-30 03:31:36 +00:00
gate: define the build-image pre-push task (daemonless Dockerfile check)
The git-push gate (handler.hooks.gate -> verify.run_build) shells `mise run build-image`, but .mise.toml never defined that task, so every agent push was hard-blocked with "no task build-image found". Define it. The agent sandbox and control image ship no container daemon or builder (by design — no Docker socket, no --privileged), so a real image build can't run at push time. Use hadolint as a daemonless soundness check on both Dockerfiles, with .hadolint.yaml pinning the failure threshold to errors so genuine Dockerfile mistakes block the push while the deliberate, commented style choices (unpinned apt/npm/go) don't. The authoritative end-to-end multi-arch build-and-push stays in CI (.github/workflows/docker*.yml) on every PR to main. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,9 @@
|
||||
# Config for the daemonless `mise run build-image` pre-push gate (see .mise.toml).
|
||||
# Only genuine Dockerfile errors (bad syntax / invalid instructions) should block a push;
|
||||
# the deliberate, commented choices in the Dockerfiles are not defects:
|
||||
# DL3008 — apt packages are intentionally unpinned (rolling base image).
|
||||
# DL3016 — `npm install -g @anthropic-ai/claude-code` tracks the latest Claude Code CLI.
|
||||
# DL3062 — `go install ...@latest` is deliberate (forge tracks its latest release).
|
||||
# DL4006 — the piped NodeSource/mise setup runs under the default shell on purpose.
|
||||
# The authoritative end-to-end multi-arch build runs in CI (.github/workflows/docker*.yml).
|
||||
failure-threshold: error
|
||||
+15
-2
@@ -1,7 +1,10 @@
|
||||
# Handler dogfoods its own gate: this repo defines the canonical `test` task the
|
||||
# control layer's Stop hook enforces. Any project Handler manages carries one of these.
|
||||
# Handler dogfoods its own gate: this repo defines the canonical `test` and `build-image`
|
||||
# tasks the control layer enforces (the Stop hook runs `test`; the git-push gate runs
|
||||
# `test` then `build-image`). Any project Handler manages carries these.
|
||||
[tools]
|
||||
python = "3.11"
|
||||
# Backs the daemonless `build-image` gate below (see that task).
|
||||
hadolint = "2.14.0"
|
||||
|
||||
[tasks.test]
|
||||
description = "Run the test suite"
|
||||
@@ -14,3 +17,13 @@ run = "ruff check ."
|
||||
[tasks.verify]
|
||||
description = "Lint then test"
|
||||
depends = ["lint", "test"]
|
||||
|
||||
# The pre-push gate (handler.hooks.gate -> verify.run_build) shells `mise run build-image`
|
||||
# to prove the Dockerfiles are sound before a push. The agent sandbox and control image
|
||||
# ship no container daemon/builder (by design — no Docker socket, no --privileged), so this
|
||||
# is a daemonless soundness check via hadolint rather than a real image build. The
|
||||
# authoritative end-to-end multi-arch build-and-push runs in CI (.github/workflows/docker*.yml)
|
||||
# on every PR to main. Failure threshold is pinned to errors in .hadolint.yaml.
|
||||
[tasks.build-image]
|
||||
description = "Validate the Dockerfiles are sound (daemonless pre-push gate)"
|
||||
run = "hadolint Dockerfile Dockerfile.control"
|
||||
|
||||
Reference in New Issue
Block a user