From ae7c3f226d8a161b54a233d61f365f0cb48c4379 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Mon, 5 Oct 2026 01:24:41 +0200 Subject: [PATCH] Keep local config files out of the Docker build context (closes #211) config.yaml and config.dev.yml are kept out of git because they can hold the signing key, but .dockerignore did not leave them out, so a local copy in the working tree reached the build context and, through COPY . ., a build-stage layer. .dockerignore now leaves them out in every directory and in any letter case. configs/config.example.yml is still sent. Model: opus-5-5 --- .dockerignore | 4 ++++ TODO.md | 7 +++++++ 2 files changed, 11 insertions(+) diff --git a/.dockerignore b/.dockerignore index 8790b32..6586021 100644 --- a/.dockerignore +++ b/.dockerignore @@ -66,3 +66,7 @@ .gitignore /bin /data + +# Local config files, kept out of git because they can hold the signing key. +**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL] +**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL] diff --git a/TODO.md b/TODO.md index f725367..fefbc63 100644 --- a/TODO.md +++ b/TODO.md @@ -31,6 +31,13 @@ P2: security: per-IP rate limiting on the image routes # Completed Steps +- 2026-10-04 local config files stay out of the Docker build context (closes + #211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in + every directory and in any letter case, the local config files `.gitignore` + keeps out of git because they can hold the signing key. + `configs/config.example.yml` is still sent. `config.yml`, which Getting + Started creates, is in neither file: + https://git.eeqj.de/sneak/pixa/issues/212. - 2026-10-04 `cmd/pixad/main.go` is one call into `internal/` (closes #206): what it did (the command line and its `--config` flag, setting `PIXA_CONFIG_PATH`, ignoring `SIGPIPE`, starting the fx app) is now `Run` in