Keep secrets out of the Docker build context at every depth (closes #205)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
.dockerignore patterns without a leading **/ match only at the root of the build context, so a nested .env or private key still reached it and, through COPY . ., a build-stage layer. The file is now the standard one from sneak/prompts: every pattern that should match anywhere has **/, and private keys and environment files are matched in any letter case. pixa keeps its own differences: .git is still sent without .git/config in place of the standard .git line, which the version stamp needs, and .gitignore, /bin and /data stay out. Model: opus-5-5
This commit was merged in pull request #210.
This commit is contained in:
+65
-9
@@ -1,12 +1,68 @@
|
|||||||
# .git is sent without its config. Without a VERSION build argument the
|
# .dockerignore does NOT use .gitignore semantics. Docker matches with
|
||||||
# stage that compiles runs `git describe --tags --always` on .git, which
|
# moby/patternmatcher: filepath.Match plus `**`, so `*` does not cross
|
||||||
# does not need .git/config; that file can hold a credential, such as a
|
# `/` and an unprefixed pattern is anchored at the context root. Every
|
||||||
|
# depth-independent pattern therefore needs `**/`, or `config/.env` and
|
||||||
|
# `certs/server.key` still ship while this file reads as solved. Only
|
||||||
|
# genuinely root-anchored entries go unprefixed. Never transplant these
|
||||||
|
# into .gitignore, where `**/` is wrong.
|
||||||
|
#
|
||||||
|
# Matching is case-sensitive, so secrets use character ranges rather
|
||||||
|
# than an ALL-CAPS twin, which would still miss `Server.Key`.
|
||||||
|
#
|
||||||
|
# Extend with this repo's own host-built artifacts, written anchored:
|
||||||
|
# `/myapp`, never `**/myapp`, which also matches `cmd/myapp/` and
|
||||||
|
# deletes the package directory from the context.
|
||||||
|
|
||||||
|
# Unlike the standard file, which leaves out all of .git, pixa sends
|
||||||
|
# .git without its config. Without a VERSION build argument the stage
|
||||||
|
# that compiles runs `git describe --tags --always` on .git, which does
|
||||||
|
# not need .git/config; that file can hold a credential, such as a
|
||||||
# password in a remote URL or the token the CI checkout step stores there.
|
# password in a remote URL or the token the CI checkout step stores there.
|
||||||
.git/config
|
.git/config
|
||||||
.gitignore
|
|
||||||
.DS_Store
|
# Agent scratch: one full checkout of the repo per in-flight agent.
|
||||||
.env*
|
# Anchored because it occurs once where agents run at the repo root.
|
||||||
|
# KNOWN GAP: a repo running agents in subdirectories still ships
|
||||||
|
# `services/api/.claude/` and must add its own anchored entry.
|
||||||
.claude
|
.claude
|
||||||
node_modules
|
|
||||||
bin/
|
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
||||||
data/
|
# convention. Re-include a committed template with a negation if the
|
||||||
|
# build needs one: `!docs/example.env`.
|
||||||
|
**/*.[eE][nN][vV]
|
||||||
|
**/.[eE][nN][vV].*
|
||||||
|
**/.[eE][nN][vV][rR][cC]
|
||||||
|
|
||||||
|
# Private keys and the bundles carrying them. Public certificates
|
||||||
|
# (*.crt, *.cer) are deliberately absent: they are legitimate inputs.
|
||||||
|
**/*.[pP][eE][mM]
|
||||||
|
**/*.[kK][eE][yY]
|
||||||
|
**/*.[pP]12
|
||||||
|
**/*.[pP][fF][xX]
|
||||||
|
**/[iI][dD]_[rR][sS][aA]
|
||||||
|
**/[iI][dD]_[dD][sS][aA]
|
||||||
|
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
||||||
|
**/[iI][dD]_[eE][dD]25519
|
||||||
|
|
||||||
|
# Dependencies: restored inside the image, never copied in.
|
||||||
|
**/node_modules
|
||||||
|
|
||||||
|
# OS metadata.
|
||||||
|
**/.DS_Store
|
||||||
|
**/Thumbs.db
|
||||||
|
|
||||||
|
# Editor state: never a build input, and it churns COPY.
|
||||||
|
**/*.swp
|
||||||
|
**/*.swo
|
||||||
|
**/*~
|
||||||
|
**/*.bak
|
||||||
|
**/.idea
|
||||||
|
**/.vscode
|
||||||
|
**/*.sublime-*
|
||||||
|
|
||||||
|
# pixa's own entries. Nothing in the build reads .gitignore. On the
|
||||||
|
# host, `make build` writes bin/pixad, and the example config keeps its
|
||||||
|
# state directory in data/.
|
||||||
|
.gitignore
|
||||||
|
/bin
|
||||||
|
/data
|
||||||
|
|||||||
@@ -31,6 +31,12 @@ P2: security: per-IP rate limiting on the image routes
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
|
||||||
|
file is now the standard one from `sneak/prompts`, whose patterns match in
|
||||||
|
every directory and, for environment files and private keys, in any letter
|
||||||
|
case, so a nested `.env` or `server.key` no longer reaches the build context.
|
||||||
|
pixa still sends `.git` without `.git/config` in place of the standard file's
|
||||||
|
`.git` line, and still leaves out `.gitignore`, `/bin` and `/data`.
|
||||||
- 2026-10-04 `REPO_POLICIES.md` matches the canonical copy again (closes #196):
|
- 2026-10-04 `REPO_POLICIES.md` matches the canonical copy again (closes #196):
|
||||||
it is replaced, unchanged, by `prompts/REPO_POLICIES.md` from `sneak/prompts`
|
it is replaced, unchanged, by `prompts/REPO_POLICIES.md` from `sneak/prompts`
|
||||||
`main`. The rules it adds that pixa's tree breaks are filed:
|
`main`. The rules it adds that pixa's tree breaks are filed:
|
||||||
|
|||||||
Reference in New Issue
Block a user