From 83fe3c38ee256efa961d87bdf268708020f852e4 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Sun, 4 Oct 2026 22:10:14 +0000 Subject: [PATCH] Keep local config files out of the Docker build context (closes #211) config.yaml and config.dev.yml are kept out of git because they can hold the signing key, but .dockerignore did not leave them out, so a local copy in the working tree reached the build context and, through COPY . ., a build-stage layer. .dockerignore now leaves them out in every directory. configs/config.example.yml is still sent. Model: opus-5-5 --- .dockerignore | 4 ++++ TODO.md | 6 ++++++ 2 files changed, 10 insertions(+) diff --git a/.dockerignore b/.dockerignore index 8790b32..c30b4f7 100644 --- a/.dockerignore +++ b/.dockerignore @@ -66,3 +66,7 @@ .gitignore /bin /data + +# Local config files, kept out of git because they can hold the signing key. +**/config.yaml +**/config.dev.yml diff --git a/TODO.md b/TODO.md index 2a34c53..802565f 100644 --- a/TODO.md +++ b/TODO.md @@ -31,6 +31,12 @@ P2: security: per-IP rate limiting on the image routes # Completed Steps +- 2026-10-04 local config files stay out of the Docker build context (closes + #211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in + every directory, the local config files `.gitignore` keeps out of git because + they can hold the signing key. `configs/config.example.yml` is still sent. + `config.yml`, which Getting Started creates, is in neither file: + https://git.eeqj.de/sneak/pixa/issues/212. - 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the file is now the standard one from `sneak/prompts`, whose patterns match in every directory and, for environment files and private keys, in any letter