7805425a

By: Michael Lynch <git@mtlynch.io>

Make Dockerfile CI runner match local execution

Run Kaniko against a temporary git-tracked build context instead of bind-mounting the real checkout into PRoot. This keeps local runs and NixCI on the same execution path and prevents Kaniko stage cleanup from touching the repository.

Use the Alpine Go builder image so PRoot does not need to chmod Debian account-management binaries such as /usr/bin/chage while extracting the builder base image on NixCI.

Suite timing

Time to Start Worker time Duration Time to finish Idle
Config 2s 6s 6s 9s 2s
Eval 7s 1m13s 1m13s 1m20s 0s
Build 13s 6m38s 1m16s 1m30s 0s
Test 3m30s 2m59s 3m01s 6m31s 3m39s
Suite 2s 10m58s 6m29s 6m31s 3m41s

Timeline

0s20s40s1m1m20s3m40s4m4m20s4m40s5m5m20s5m40s6m6m20s