fix(build): make the image build hermetic and drop dead catalogs #38

Merged
nalum merged 2 commits from fix/web-gen-drift into main 2026-08-13 12:15:54 +00:00
Owner

make deploy failed on main: Welcome.tsx uses #36's SealVerdict, but the Docker build shipped whatever TS generation sat on the host's disk (web/src/gen is a gitignored build artifact). CI regenerates before building, so it stayed green while the image build broke.

Hermetic image build — the webbuild stage now generates the clients itself:

  • digest-pinned bufbuild/buf stage supplies the binary
  • new buf.gen.ts.yaml runs only the protoc-gen-es plugin npm ci already installed (no Go toolchain needed in the node stage)
  • web/src/gen is excluded from the build context, so in-image generation is the only source — a fresh clone builds correctly with plain docker build (verified: webbuild stage builds green with no clients in the context)
  • web-build gains the web-gen prerequisite for the local embed path (make build-all); deploy-image needs none

Dead catalogs deleted — web/src/locales/*/messages.js (6 files): compiled lingui output nothing references; the app imports messages.po directly and the Vite plugin compiles at build time. make web-i18n-check still passes.

Release check fixed — the update-feed default still pointed at the old forge (forgejo.lihnet..., 404 since the move); now git.eagraiclainne.ie/api/v1/repos/eagraiclainne/app/releases/latest (verified answering 200).

Old-forge sweep (second commit) — every forgejo.lihnet.mallon.ie pull reference now points at git.eagraiclainne.ie, with the repo path corrected to eagraiclainne/app (release.yml derives the registry from the server URL, so that is where artifacts land since the migration): timoni image default, TrueNAS compose, verified flux OCIRepository (renamed ocirepository-verified.yaml — the -lihnet name no longer described it), flux README, AGENTS.md. timoni mod vet + YAML parse green.

🤖 Generated with Claude Code

`make deploy` failed on main: `Welcome.tsx` uses #36's `SealVerdict`, but the Docker build shipped whatever TS generation sat on the host's disk (`web/src/gen` is a gitignored build artifact). CI regenerates before building, so it stayed green while the image build broke. **Hermetic image build** — the webbuild stage now generates the clients itself: - digest-pinned `bufbuild/buf` stage supplies the binary - new `buf.gen.ts.yaml` runs only the `protoc-gen-es` plugin `npm ci` already installed (no Go toolchain needed in the node stage) - `web/src/gen` is excluded from the build context, so in-image generation is the **only** source — a fresh clone builds correctly with plain `docker build` (verified: webbuild stage builds green with no clients in the context) - `web-build` gains the `web-gen` prerequisite for the local embed path (`make build-all`); `deploy-image` needs none **Dead catalogs deleted** — `web/src/locales/*/messages.js` (6 files): compiled lingui output nothing references; the app imports `messages.po` directly and the Vite plugin compiles at build time. `make web-i18n-check` still passes. **Release check fixed** — the `update-feed` default still pointed at the old forge (`forgejo.lihnet...`, 404 since the move); now `git.eagraiclainne.ie/api/v1/repos/eagraiclainne/app/releases/latest` (verified answering 200). **Old-forge sweep** (second commit) — every `forgejo.lihnet.mallon.ie` pull reference now points at `git.eagraiclainne.ie`, with the repo path corrected to `eagraiclainne/app` (release.yml derives the registry from the server URL, so that is where artifacts land since the migration): timoni image default, TrueNAS compose, verified flux OCIRepository (renamed `ocirepository-verified.yaml` — the `-lihnet` name no longer described it), flux README, AGENTS.md. `timoni mod vet` + YAML parse green. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(web): commit the regenerated TS clients for the seal verdict
Some checks failed
check / go (push) Has been cancelled
check / web (push) Has been cancelled
1f6b39adcf
The archive-seal change (#36) regenerated the Go and Android codegen
but not the tracked TypeScript clients: web/src/gen sits in .gitignore
yet its files are tracked, so ignore rules never applied to them. CI's
web job regenerates before building and stayed green while the Docker
build — which copies the tracked tree verbatim — failed on the missing
SealVerdict export. Committing the regenerated clients unbreaks
make deploy; the .gitignore line is dropped so the next drift shows in
jj st instead of hiding behind an ignore rule that never worked.
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 11:46:25 +00:00
nalum canceled auto merging this pull request when all checks succeed 2026-08-13 11:47:15 +00:00
nalum force-pushed fix/web-gen-drift from 1f6b39adcf
Some checks failed
check / go (push) Has been cancelled
check / web (push) Has been cancelled
to 0392cb5afa
Some checks failed
check / go (push) Has been cancelled
check / web (push) Has been cancelled
2026-08-13 11:48:23 +00:00
Compare
nalum changed title from fix(web): commit the regenerated TS clients for the seal verdict to fix(build): regenerate TS clients before the deploy image build 2026-08-13 11:48:35 +00:00
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 11:48:35 +00:00
nalum canceled auto merging this pull request when all checks succeed 2026-08-13 11:49:10 +00:00
nalum force-pushed fix/web-gen-drift from 0392cb5afa
Some checks failed
check / go (push) Has been cancelled
check / web (push) Has been cancelled
to 8ae0988922
All checks were successful
check / web (push) Successful in 1m41s
check / go (push) Successful in 2m25s
2026-08-13 11:55:33 +00:00
Compare
nalum changed title from fix(build): regenerate TS clients before the deploy image build to fix(build): make the image build hermetic and drop dead catalogs 2026-08-13 11:55:47 +00:00
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 11:55:47 +00:00
nalum canceled auto merging this pull request when all checks succeed 2026-08-13 11:59:14 +00:00
nalum force-pushed fix/web-gen-drift from 8ae0988922
All checks were successful
check / web (push) Successful in 1m41s
check / go (push) Successful in 2m25s
to 16f79be10c
All checks were successful
check / web (push) Successful in 1m30s
check / go (push) Successful in 1m45s
2026-08-13 12:06:50 +00:00
Compare
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 12:07:03 +00:00
nalum canceled auto merging this pull request when all checks succeed 2026-08-13 12:07:53 +00:00
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 12:12:46 +00:00
chore(deploy): point pull references at the new forge
Some checks failed
tag / tag (push) Successful in 2m47s
release / binaries (push) Failing after 1m19s
check / web (push) Successful in 1m34s
check / go (push) Successful in 1m54s
release / docs (push) Successful in 58s
release / image (push) Successful in 3m8s
release / module (push) Successful in 17s
release / manifests (push) Successful in 19s
release / android (push) Successful in 3m52s
release / release (push) Has been skipped
0b675feedb
Release artifacts now land on git.eagraiclainne.ie (release.yml derives
the registry from the server URL), and the repo path moved from
eagraiclainne/eagraiclainne to eagraiclainne/app with the migration.
Every pull-side reference still named forgejo.lihnet.mallon.ie — the
timoni image default, the TrueNAS compose, the verified flux
OCIRepositories and the flux README — answered from a forge the
artifacts no longer reach.
nalum canceled auto merging this pull request when all checks succeed 2026-08-13 12:14:22 +00:00
nalum merged commit 0b675feedb into main 2026-08-13 12:15:54 +00:00
nalum deleted branch fix/web-gen-drift 2026-08-13 12:15:54 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!38
No description provided.