2 Commits
Author SHA1 Message Date
clawbot bb87fddcdb Keep local config files out of the Docker build context (closes #211)
check / check (push) Failing after 3s
config.yaml and config.dev.yml are kept out of git because they can hold
the signing key, but .dockerignore did not leave them out, so a local
copy in the working tree reached the build context and, through
COPY . ., a build-stage layer. .dockerignore now leaves them out in
every directory and in any letter case. configs/config.example.yml is
still sent.

Model: opus-5-5
2026-10-04 22:44:05 +00:00
clawbot 23ec4026f6 Ignore .claude/ in .gitignore (closes #204)
check / check (push) Failing after 2s
REPO_POLICIES.md says in-repo agent scratch belongs in both .gitignore and
.dockerignore. .dockerignore already has .claude; .gitignore now has the
.claude/ entry and its comment exactly as the canonical .gitignore in
sneak/prompts has them, unanchored so it matches at every depth.

Model: opus-5-5
2026-10-05 00:41:42 +02:00
3 changed files with 16 additions and 5 deletions
+2 -2
View File
@@ -68,5 +68,5 @@
/data
# Local config files, kept out of git because they can hold the signing key.
**/config.yaml
**/config.dev.yml
**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]
**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]
+6
View File
@@ -11,6 +11,12 @@ Thumbs.db
.vscode/
*.sublime-*
# Agent scratch (worktrees of this repo, created and destroyed by
# in-flight tooling). Unanchored: .gitignore patterns already match at
# every depth, so no prefix is wanted here. This is not a .dockerignore
# entry and must not be given a `**/` prefix on the way into one.
.claude/
# Environment / secrets
.env
.env.*
+8 -3
View File
@@ -33,10 +33,15 @@ P2: security: per-IP rate limiting on the image routes
- 2026-10-04 local config files stay out of the Docker build context (closes
#211): `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in
every directory, the local config files `.gitignore` keeps out of git because
they can hold the signing key. `configs/config.example.yml` is still sent.
`config.yml`, which Getting Started creates, is in neither file:
every directory and in any letter case, the local config files `.gitignore`
keeps out of git because they can hold the signing key.
`configs/config.example.yml` is still sent. `config.yml`, which Getting
Started creates, is in neither file:
https://git.eeqj.de/sneak/pixa/issues/212.
- 2026-10-04 `.gitignore` ignores `.claude/` (closes #204): the entry and its
comment are copied from the canonical `.gitignore` in `sneak/prompts`,
unanchored so it matches at every depth. `.dockerignore` already has
`.claude`.
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
file is now the standard one from `sneak/prompts`, whose patterns match in
every directory and, for environment files and private keys, in any letter