Commit Graph
5 Commits
Author SHA1 Message Date
clawbot ae7c3f226d Keep local config files out of the Docker build context (closes #211)
check / check (push) Failing after 2s
config.yaml and config.dev.yml are kept out of git because they can hold
the signing key, but .dockerignore did not leave them out, so a local
copy in the working tree reached the build context and, through
COPY . ., a build-stage layer. .dockerignore now leaves them out in
every directory and in any letter case. configs/config.example.yml is
still sent.

Model: opus-5-5
2026-10-05 01:24:41 +02:00
clawbot ef828f71a5 Keep secrets out of the Docker build context at every depth (closes #205)
check / check (push) Failing after 2s
.dockerignore patterns without a leading **/ match only at the root of
the build context, so a nested .env or private key still reached it and,
through COPY . ., a build-stage layer. The file is now the standard one
from sneak/prompts: every pattern that should match anywhere has **/,
and private keys and environment files are matched in any letter case.

pixa keeps its own differences: .git is still sent without .git/config
in place of the standard .git line, which the version stamp needs, and
.gitignore, /bin and /data stay out.

Model: opus-5-5
2026-10-05 00:07:37 +02:00
clawbot 869b5ba67f Stamp the tag or short commit in a plain docker build (closes #166)
check / check (push) Successful in 4m4s
.dockerignore now lets .git into the build context, without
.git/config, which can hold a remote URL with a credential. ARG VERSION
has no default: given none, the build stage takes the version from
git describe --tags --always, and fails if the context carries .git
and no version comes out. pixad now logs its name, version and
architecture as its first log line, through the existing
Logger.Identify, which nothing called.

Model: opus-5-5
2026-10-02 06:01:40 +02:00
sneak c4fc1e1548 chore: update .dockerignore to policy standards 2026-02-25 18:22:35 +07:00
sneak 4b2d85010e Add two-stage Dockerfile with CGO support
- Build stage: golang:1.24-alpine with vips-dev for CGO image libs
- Runtime stage: alpine:3.21 with vips runtime only
- Pass VERSION build arg for ldflags embedding
- Add 'make docker' target to build image with git version
2026-01-08 15:05:49 -08:00