2 Commits
Author SHA1 Message Date
clawbot bb87fddcdb Keep local config files out of the Docker build context (closes #211)
check / check (push) Failing after 3s
config.yaml and config.dev.yml are kept out of git because they can hold
the signing key, but .dockerignore did not leave them out, so a local
copy in the working tree reached the build context and, through
COPY . ., a build-stage layer. .dockerignore now leaves them out in
every directory and in any letter case. configs/config.example.yml is
still sent.

Model: opus-5-5
2026-10-04 22:44:05 +00:00
clawbot 23ec4026f6 Ignore .claude/ in .gitignore (closes #204)
check / check (push) Failing after 2s
REPO_POLICIES.md says in-repo agent scratch belongs in both .gitignore and
.dockerignore. .dockerignore already has .claude; .gitignore now has the
.claude/ entry and its comment exactly as the canonical .gitignore in
sneak/prompts has them, unanchored so it matches at every depth.

Model: opus-5-5
2026-10-05 00:41:42 +02:00
3 changed files with 21 additions and 0 deletions
+4
View File
@@ -66,3 +66,7 @@
.gitignore .gitignore
/bin /bin
/data /data
# Local config files, kept out of git because they can hold the signing key.
**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]
**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]
+6
View File
@@ -11,6 +11,12 @@ Thumbs.db
.vscode/ .vscode/
*.sublime-* *.sublime-*
# Agent scratch (worktrees of this repo, created and destroyed by
# in-flight tooling). Unanchored: .gitignore patterns already match at
# every depth, so no prefix is wanted here. This is not a .dockerignore
# entry and must not be given a `**/` prefix on the way into one.
.claude/
# Environment / secrets # Environment / secrets
.env .env
.env.* .env.*
+11
View File
@@ -31,6 +31,17 @@ P2: security: per-IP rate limiting on the image routes
# Completed Steps # Completed Steps
- 2026-10-04 local config files stay out of the Docker build context (closes
#211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in
every directory and in any letter case, the local config files `.gitignore`
keeps out of git because they can hold the signing key.
`configs/config.example.yml` is still sent. `config.yml`, which Getting
Started creates, is in neither file:
https://git.eeqj.de/sneak/pixa/issues/212.
- 2026-10-04 `.gitignore` ignores `.claude/` (closes #204): the entry and its
comment are copied from the canonical `.gitignore` in `sneak/prompts`,
unanchored so it matches at every depth. `.dockerignore` already has
`.claude`.
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the - 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
file is now the standard one from `sneak/prompts`, whose patterns match in file is now the standard one from `sneak/prompts`, whose patterns match in
every directory and, for environment files and private keys, in any letter every directory and, for environment files and private keys, in any letter