Keep local config files out of the Docker build context (closes #211)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
config.yaml and config.dev.yml are kept out of git because they can hold the signing key, but .dockerignore did not leave them out, so a local copy in the working tree reached the build context and, through COPY . ., a build-stage layer. .dockerignore now leaves them out in every directory. configs/config.example.yml is still sent. Model: opus-5-5
This commit is contained in:
@@ -66,3 +66,7 @@
|
|||||||
.gitignore
|
.gitignore
|
||||||
/bin
|
/bin
|
||||||
/data
|
/data
|
||||||
|
|
||||||
|
# Local config files, kept out of git because they can hold the signing key.
|
||||||
|
**/config.yaml
|
||||||
|
**/config.dev.yml
|
||||||
|
|||||||
@@ -31,6 +31,12 @@ P2: security: per-IP rate limiting on the image routes
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-04 local config files stay out of the Docker build context (closes
|
||||||
|
#211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in
|
||||||
|
every directory, the local config files `.gitignore` keeps out of git because
|
||||||
|
they can hold the signing key. `configs/config.example.yml` is still sent.
|
||||||
|
`config.yml`, which Getting Started creates, is in neither file:
|
||||||
|
https://git.eeqj.de/sneak/pixa/issues/212.
|
||||||
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
|
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
|
||||||
file is now the standard one from `sneak/prompts`, whose patterns match in
|
file is now the standard one from `sneak/prompts`, whose patterns match in
|
||||||
every directory and, for environment files and private keys, in any letter
|
every directory and, for environment files and private keys, in any letter
|
||||||
|
|||||||
Reference in New Issue
Block a user