Keep config.yml out of git and the Docker build context (closes #212)
check / check (push) Failing after 2s

Getting Started has you create config.yml at the repository root with a
real signing key, but neither .gitignore nor .dockerignore left it out,
so it could be committed and, through COPY . ., reach a build-stage
layer. .gitignore now ignores it next to config.yaml, and .dockerignore
leaves it out in every directory and in any letter case, as it already
does config.yaml and config.dev.yml.

Model: opus-5-5
This commit was merged in pull request #217.
This commit is contained in:
2026-10-05 01:58:32 +02:00
parent ae7c3f226d
commit f77faf13de
3 changed files with 7 additions and 0 deletions
+1
View File
@@ -68,5 +68,6 @@
/data
# Local config files, kept out of git because they can hold the signing key.
**/[cC][oO][nN][fF][iI][gG].[yY][mM][lL]
**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]
**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]
+1
View File
@@ -37,5 +37,6 @@ node_modules/
*.sqlite3
# Local dev configs
config.yml
config.yaml
config.dev.yml
+5
View File
@@ -31,6 +31,11 @@ P2: security: per-IP rate limiting on the image routes
# Completed Steps
- 2026-10-04 `config.yml` stays out of git and the Docker build context (closes
#212): `.gitignore` now ignores `config.yml`, the config file Getting Started
creates with the signing key, and `.dockerignore` leaves it out in every
directory and in any letter case, as it already did `config.yaml` and
`config.dev.yml`.
- 2026-10-04 local config files stay out of the Docker build context (closes
#211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in
every directory and in any letter case, the local config files `.gitignore`