Fetch templates over HTTP instead of shelling out to git
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

The runtime image is distroless and has no git binary, so every sync
failed and bootapi silently served the stale embedded templates.

- fetch the branch tarball (<repo>/archive/<branch>.tar.gz) and extract
  it into an in-memory FS; no checkout, no writable volume
- digest the extracted tree, not the archive bytes, so a recompressed
  identical archive is not a change
- skip entries that would escape the tree
- log the source commit from Gitea's immutable Link header
This commit is contained in:
2026-09-26 18:59:07 +10:00
parent ca86d9cedc
commit a414918350
7 changed files with 351 additions and 166 deletions
+5 -7
View File
@@ -9,7 +9,6 @@ import (
"log/slog"
"os"
"os/signal"
"path/filepath"
"syscall"
"git.unkin.net/unkin/bootapi/internal/config"
@@ -133,10 +132,10 @@ func runValidate(dir string) int {
return 0
}
// buildEngine constructs the render Engine and, when a templates git repo is
// configured, a Syncer that reloads it periodically. Precedence: git repo →
// local override dir → embedded defaults only. Git/dir failures degrade to the
// embedded defaults rather than failing startup.
// buildEngine constructs the render Engine and, when a templates repo is
// configured, a Syncer that reloads it periodically. Precedence: templates repo
// → local override dir → embedded defaults only. Fetch/dir failures degrade to
// the embedded defaults rather than failing startup.
func buildEngine(ctx context.Context, cfg *config.Config, rcfg render.RenderConfig) (*render.Engine, *gitsync.Syncer, error) {
switch {
case cfg.TemplateGitURL != "":
@@ -145,11 +144,10 @@ func buildEngine(ctx context.Context, cfg *config.Config, rcfg render.RenderConf
Branch: cfg.TemplateGitBranch,
Token: cfg.TemplateGitToken,
Interval: cfg.TemplateGitInterval,
WorkDir: filepath.Join(os.TempDir(), "bootapi-templates"),
}, templates.FS)
set, gerr := syncer.Bootstrap(ctx)
if gerr != nil {
slog.Warn("template git bootstrap degraded to embedded defaults", "err", gerr)
slog.Warn("template bootstrap degraded to embedded defaults", "err", gerr)
}
engine := render.NewEngine(rcfg, set)
syncer.SetEngine(engine)