Files
orchestra/deploy/build.sh
T
kami 2f7b209b62 Build stamped binaries in a throwaway worktree of HEAD
This checkout is shared with another session. Its uncommitted Go changes must
neither be compiled into a binary stamped with a commit revision nor block a
deploy, and a dirty-tree refusal does both jobs badly. deploy/build.sh now
builds in a detached worktree of the revision it stamps, and the container image
is built the same way rather than from the live checkout.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-26 23:50:02 +04:00

27 lines
1.3 KiB
Bash
Executable File

#!/bin/sh
# Build the coordinator and the worker from one commit, with one stamp, so a
# burn-in run can never pair a new coordinator with an old worker. Both
# binaries then report the same revision at /v1/admin/diagnostics and in the
# worker's registration, which is what makes deployed identity evidence rather
# than assumption.
#
# The build runs in a throwaway git worktree of HEAD, not in the checkout. This
# repository is shared: another session may have uncommitted Go changes in it,
# and those must neither be compiled into a stamped binary nor block a deploy.
#
# Usage: deploy/build.sh [outdir] [revision]
set -eu
repo=$(cd "$(dirname "$0")/.." && pwd)
out=${1:-$repo/build}
rev=$(git -C "$repo" rev-parse "${2:-HEAD}")
built=$(git -C "$repo" show -s --format=%cI "$rev")
tree=$(mktemp -d)
cleanup() { git -C "$repo" worktree remove --force "$tree" >/dev/null 2>&1 || rm -rf "$tree"; }
trap cleanup EXIT
git -C "$repo" worktree add --detach --quiet "$tree" "$rev"
flags="-s -w -X orchestra/internal/buildinfo.Revision=$rev -X orchestra/internal/buildinfo.Time=$built -X orchestra/internal/buildinfo.Dirty=false"
mkdir -p "$out"
(cd "$tree" && go build -trimpath -ldflags="$flags" -o "$out/orchestra" ./cmd/orchestra)
(cd "$tree" && go build -trimpath -ldflags="$flags" -o "$out/orchestra-worker" ./cmd/orchestra-worker)
echo "$rev"