diff --git a/.dockerignore b/.dockerignore index 8790b32..6586021 100644 --- a/.dockerignore +++ b/.dockerignore @@ -66,3 +66,7 @@ .gitignore /bin /data + +# Local config files, kept out of git because they can hold the signing key. +**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL] +**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL] diff --git a/TODO.md b/TODO.md index b13608a..01a5186 100644 --- a/TODO.md +++ b/TODO.md @@ -31,6 +31,13 @@ P2: security: per-IP rate limiting on the image routes # Completed Steps +- 2026-10-04 local config files stay out of the Docker build context (closes + #211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in + every directory and in any letter case, the local config files `.gitignore` + keeps out of git because they can hold the signing key. + `configs/config.example.yml` is still sent. `config.yml`, which Getting + Started creates, is in neither file: + https://git.eeqj.de/sneak/pixa/issues/212. - 2026-10-04 `.gitignore` ignores `.claude/` (closes #204): the entry and its comment are copied from the canonical `.gitignore` in `sneak/prompts`, unanchored so it matches at every depth. `.dockerignore` already has