mhoennigandClaude Fable 5 8b71d0db8e Fix Docker builds under rootless daemons and expose git metadata to build containers
Two fixes from the vm4006 rollout (docs/plan/16-git-in-docker-builds.md):

Rootless daemons map the host user to container root, so running the build
container as --user <host-uid> put it into the subuid range and it could not
even create .gradle in a fresh worktree (legacy only worked because its
ownership-repair chown had accidentally moved build/ and .gradle/ into subuid
ownership in its reused primary checkout). The container now always runs as
--user 0: the unprivileged host user under rootless, real root under rootful
where the ownership repair still applies; under rootless it degenerates to 0:0.

Git now works inside build containers: the primary .git is mounted read-only
with .git/gittally/ masked by an empty tmpfs (git.token and the control token
stay unreachable, the workspace bind resurfaces only the build's own worktree)
and the worktree admin dir mounted read-write for index-refreshing commands.
Verified on vm4006: git log/status succeed, the machine config is invisible,
ref writes fail on the read-only mount.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-10 15:34:39 +02:00
2026-06-09 14:31:35 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 11:55:23 +02:00
2026-06-09 09:07:47 +02:00
2026-06-09 11:55:23 +02:00

GitTally

Lightweight, declarative and highly opinionated software build system (CI/CD).

Documentation

Legacy Script

legacy/gitTally (bash) is deprecated and kept only as a behavioral reference for the rewrite. Do not use it for new installations; see docs/migration-from-legacy.md.

Developer Setup

Source .envrc to add tools/ to your PATH, or install direnv to have this done automatically on cd:

source .envrc

Common tasks:

./gradlew build          # compile and run all checks
./gradlew test           # run tests
./gradlew ktlintFormat   # auto-format Kotlin sources
./gradlew ktlintCheck    # check formatting (also runs as part of build)

adr-status               # show all architecture decisions at a glance

direnv

direnv sources .envrc automatically whenever you enter the repository and unloads it when you leave.

# Ubuntu
sudo apt install direnv

# add to ~/.bashrc or ~/.zshrc
eval "$(direnv hook bash)"   # or: eval "$(direnv hook zsh)"

Trust the project's .envrc once per clone:

direnv allow

Tools (tools/)

Command Description
adr-status List all Architecture Decision Records with their status and decision summary

Architecture Decision Records

Major technical decisions are documented as ADRs in docs/adrs/.

adr-status   # show all decisions at a glance

New ADRs follow the template at docs/adrs/0000-00-00.adr-template.md.

S
Description
A simple CI app mostly for GitEA and Hostsharing Managed Webserver/Webspace as well as Hostsharing Container Server.
Readme MIT
5 MiB
Languages
Kotlin 87%
HTML 4.6%
Shell 4.2%
JavaScript 3%
CSS 1.2%