Add canonical policy dotfiles, harden both ignore files (closes #8)

REPO_POLICIES.md lists the files every repo must contain at minimum;
four were missing here and .gitignore covered only Hugo's outputs.

REPO_POLICIES.md is a byte-identical copy of the canonical file in the
prompts repo, YAML front matter (title, last_modified) intact so it can
be diffed against upstream as policy evolves. It is not clean under this
repo's prettier settings, so the reformat is the next commit rather than
churn mixed in here; the byte-identical copy is what landed.

.editorconfig, .prettierrc and .prettierignore are the canonical
contents. script/fmt and script/fmt-check keep passing --tab-width 4
--prose-wrap always on the command line: the duplication is deliberate
so the scripts still work standalone when copied as a template, and the
values agree, so adding .prettierrc changes nothing about what make fmt
does.

.gitignore keeps its three Hugo lines and gains the canonical
OS/editor/node/secrets block plus .claude/. The secrets patterns are the
point: a stray .env or private key can no longer be committed by a broad
git add. .claude/ holds worktrees/, so without it a clean checkout with
agent tooling present is not git status-clean.

.dockerignore gains the same coverage but not the same syntax. It does
not use .gitignore semantics: it matches with Go's filepath.Match rules
extended with **, where * does not cross / and an unprefixed pattern is
anchored at the context root. A bare *.key therefore excludes
./server.key and ships ./certs/server.key into the image, which is worse
than an obviously incomplete file because it reads as complete. Every
depth-independent pattern here carries an explicit **/ prefix; only the
entries that are genuinely root-anchored by definition go bare - .git,
Hugo's public and resources output directories, and .hugo_build.lock.
The distinction is spelled out in a comment at the top of the file so
the next edit does not quietly undo it.

Excluding .claude/ also keeps entire additional checkouts of this repo
out of the build context, which the Dockerfile's COPY . . would
otherwise copy into the image.

Verified by planting .env, server.key, deep.pem and node_modules two
directories deep and building: with the patterns unprefixed all of them
reach /src in the image, with **/ none do. Root-only testing does not
exercise this and produces a false pass.
This commit is contained in:
2026-08-09 16:03:08 +00:00
parent ccdedc300d
commit 90f188c256
7 changed files with 524 additions and 11 deletions

View File

@@ -1,4 +1,41 @@
# NOTE: .dockerignore does NOT use .gitignore semantics. It matches with
# Go's filepath.Match rules extended with `**`: `*` does not cross `/`,
# and an unprefixed pattern is anchored at the context root. So a bare
# `*.key` would exclude ./server.key but happily ship ./certs/server.key
# into the image, and a bare `node_modules` would exclude only a
# top-level one. Every depth-independent pattern below therefore carries
# an explicit `**/` prefix. The only unprefixed entries are the ones that
# are genuinely root-anchored: the repo's own .git, Hugo's output
# directories, and Hugo's build lock, all of which exist at the context
# root by definition.
# Repo and Hugo outputs (root-anchored on purpose)
.git
public
resources
.hugo_build.lock
# OS
**/.DS_Store
**/Thumbs.db
# Editors
**/*.swp
**/*.swo
**/*~
**/*.bak
**/.idea
**/.vscode
**/*.sublime-*
# Node
**/node_modules
# Environment / secrets
**/.env
**/.env.*
**/*.pem
**/*.key
# Agent tooling (holds worktrees/, i.e. entire additional checkouts)
**/.claude