I know my way around Git well enough. I’ve even held workshops for other developers, like Choose your own command line Git adventure at Booster Conference. But today I need to fill a couple of gaps. I’m working on migrating a suite of apps from Kustomize to Helm and I need to debug an issue related to “creating the initial deploy tag” where the internal documentation is flying over my head. Seems like a great day to learn what even is a git tag?!

git tag --sort=committerdate | tail -5

This is a command I’ve been using for a couple of years. Before finding this command, I would visit a slack channel where a bot posts a deploy command when my build is done. After getting this git command into my fingers, I can stay in the terminal and write the deploy command myself. The last part of the deploy command has been the git tag. Which I can find right in my shell with this command that lists all the git tags sorted by date, and pipe that list into the tail utility to output the last 5 lines.

So I have been using git tags, multiple times a day for deploying, but I don’t really know what they are. Let’s read up and write some notes.

git tag

Technically, a tag is a named reference that points to a specific commit. It is intended to be permanent. So while a branch moves forward, a tag is fixed. I can think of this as a label on a commit. That’s kinda it. Really not much more to it, but I can practice finding the ones I am looking for with the git tag command. And also understand that there are two different types:

  • lightweight is a pointer to a specific commit and nothing more
  • annotated contains more stuff: message, author, date and is a full object store in git

git fetch

Sooo, why can I see specific tag in the UI on github.com but not in my local repository?!? 🤔 I have run git pull and also git fetch which I kinda know fetches “other stuff” from the remote repo. Hm. Ah. So apparently, git fetch without any further flags will in many cases fetch tags, but not always.

git fetch --tags

Lets try again…

git tag --list "deploy*"

Success! 🎉


git tag commands

  • git tag cheesecake.001 to create a tag
  • git tag --annotate cheesecake.002 -m "Release message cake yay"
    to create an annotated tag that can for example also contain a message
  • git tag --list to look at both of them
  • git cat-file -t cheesecake.001 to see what type of object this is. This is a low level plumbing command that will return commit if the tag is lightweight and will return tag if the tag is annotated 🤹🏻
  • git tag --delete cheesecake.002 to delete that tag

gpgsign

I also learnt more about my git config. My dotfiles repo shows that I configured signing commits back in 2023. The only thing I noticed so far, is getting a nice green “Verified” badge on my commits in the GitHub.com UI. Clicking it shows a popup confirming that the commit was signed with the committer’s verified signature and an SSH Key Fingerprint.

git config commit.gpgsign
true
git config tag.gpgsign
true

This config gave me a bit of a hurdle recently. We have some scripts set up to help work with the migration to Helm, but there was one of the commands I couldn’t get to work on my machine. It was for defining the initial deploy tag, and when I finally figured out why, it was because the script wanted to run git tag deploy/cheese/cake as a lightweight git tag.

git tag type lightweight cannot be signed

The script to define the initial deploy tag wouldn’t work. When I finally figured out why, after learning more about what a git tag is anyway 👆 the reason for the command failing on me, was because my local git config was set up to sign commits. And a lightweight tag cannot be signed. So I need a flag:

  • git tag --no-sign deploy/cheese/cake to create a lightweight tag