Keep local config files out of the Docker build context (closes #211)
check / check (push) Failing after 2s

config.yaml and config.dev.yml are kept out of git because they can hold
the signing key, but .dockerignore did not leave them out, so a local
copy in the working tree reached the build context and, through
COPY . ., a build-stage layer. .dockerignore now leaves them out in
every directory. configs/config.example.yml is still sent.

Model: opus-5-5
This commit is contained in:
2026-10-04 22:10:14 +00:00
parent ef828f71a5
commit 83fe3c38ee
2 changed files with 10 additions and 0 deletions
+4
View File
@@ -66,3 +66,7 @@
.gitignore
/bin
/data
# Local config files, kept out of git because they can hold the signing key.
**/config.yaml
**/config.dev.yml
+6
View File
@@ -31,6 +31,12 @@ P2: security: per-IP rate limiting on the image routes
# Completed Steps
- 2026-10-04 local config files stay out of the Docker build context (closes
#211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in
every directory, the local config files `.gitignore` keeps out of git because
they can hold the signing key. `configs/config.example.yml` is still sent.
`config.yml`, which Getting Started creates, is in neither file:
https://git.eeqj.de/sneak/pixa/issues/212.
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
file is now the standard one from `sneak/prompts`, whose patterns match in
every directory and, for environment files and private keys, in any letter