7805425a

By: Michael Lynch <git@mtlynch.io>

Make Dockerfile CI runner match local execution

Run Kaniko against a temporary git-tracked build context instead of bind-mounting the real checkout into PRoot. This keeps local runs and NixCI on the same execution path and prevents Kaniko stage cleanup from touching the repository.

Use the Alpine Go builder image so PRoot does not need to chmod Debian account-management binaries such as /usr/bin/chage while extracting the builder base image on NixCI.

Suite timing

Time to Start Worker time Duration Time to finish Idle
Config 2s 17s 17s 19s 2s
Eval 7s 1m24s 1m24s 1m31s 0s
Build 23s 2m01s 47s 1m10s 0s
Test 39s 3m02s 3m04s 3m44s 41s
Suite 2s 6m45s 3m42s 3m44s 44s

Timeline

0s20s40s1m1m20s1m40s2m2m20s2m40s3m3m20s3m40s