diff --git a/.dockerignore b/.dockerignore index 8790b32..c30b4f7 100644 --- a/.dockerignore +++ b/.dockerignore @@ -66,3 +66,7 @@ .gitignore /bin /data + +# Local config files, kept out of git because they can hold the signing key. +**/config.yaml +**/config.dev.yml diff --git a/TODO.md b/TODO.md index 2a34c53..802565f 100644 --- a/TODO.md +++ b/TODO.md @@ -31,6 +31,12 @@ P2: security: per-IP rate limiting on the image routes # Completed Steps +- 2026-10-04 local config files stay out of the Docker build context (closes + #211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in + every directory, the local config files `.gitignore` keeps out of git because + they can hold the signing key. `configs/config.example.yml` is still sent. + `config.yml`, which Getting Started creates, is in neither file: + https://git.eeqj.de/sneak/pixa/issues/212. - 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the file is now the standard one from `sneak/prompts`, whose patterns match in every directory and, for environment files and private keys, in any letter