Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
74aa5d231d | ||
|
|
79da9c811c | ||
|
|
4dca8e4e56 |
+9
-65
@@ -1,68 +1,12 @@
|
|||||||
# .dockerignore does NOT use .gitignore semantics. Docker matches with
|
# .git is sent without its config. Without a VERSION build argument the
|
||||||
# moby/patternmatcher: filepath.Match plus `**`, so `*` does not cross
|
# stage that compiles runs `git describe --tags --always` on .git, which
|
||||||
# `/` and an unprefixed pattern is anchored at the context root. Every
|
# does not need .git/config; that file can hold a credential, such as a
|
||||||
# depth-independent pattern therefore needs `**/`, or `config/.env` and
|
|
||||||
# `certs/server.key` still ship while this file reads as solved. Only
|
|
||||||
# genuinely root-anchored entries go unprefixed. Never transplant these
|
|
||||||
# into .gitignore, where `**/` is wrong.
|
|
||||||
#
|
|
||||||
# Matching is case-sensitive, so secrets use character ranges rather
|
|
||||||
# than an ALL-CAPS twin, which would still miss `Server.Key`.
|
|
||||||
#
|
|
||||||
# Extend with this repo's own host-built artifacts, written anchored:
|
|
||||||
# `/myapp`, never `**/myapp`, which also matches `cmd/myapp/` and
|
|
||||||
# deletes the package directory from the context.
|
|
||||||
|
|
||||||
# Unlike the standard file, which leaves out all of .git, pixa sends
|
|
||||||
# .git without its config. Without a VERSION build argument the stage
|
|
||||||
# that compiles runs `git describe --tags --always` on .git, which does
|
|
||||||
# not need .git/config; that file can hold a credential, such as a
|
|
||||||
# password in a remote URL or the token the CI checkout step stores there.
|
# password in a remote URL or the token the CI checkout step stores there.
|
||||||
.git/config
|
.git/config
|
||||||
|
|
||||||
# Agent scratch: one full checkout of the repo per in-flight agent.
|
|
||||||
# Anchored because it occurs once where agents run at the repo root.
|
|
||||||
# KNOWN GAP: a repo running agents in subdirectories still ships
|
|
||||||
# `services/api/.claude/` and must add its own anchored entry.
|
|
||||||
.claude
|
|
||||||
|
|
||||||
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
|
||||||
# convention. Re-include a committed template with a negation if the
|
|
||||||
# build needs one: `!docs/example.env`.
|
|
||||||
**/*.[eE][nN][vV]
|
|
||||||
**/.[eE][nN][vV].*
|
|
||||||
**/.[eE][nN][vV][rR][cC]
|
|
||||||
|
|
||||||
# Private keys and the bundles carrying them. Public certificates
|
|
||||||
# (*.crt, *.cer) are deliberately absent: they are legitimate inputs.
|
|
||||||
**/*.[pP][eE][mM]
|
|
||||||
**/*.[kK][eE][yY]
|
|
||||||
**/*.[pP]12
|
|
||||||
**/*.[pP][fF][xX]
|
|
||||||
**/[iI][dD]_[rR][sS][aA]
|
|
||||||
**/[iI][dD]_[dD][sS][aA]
|
|
||||||
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
|
||||||
**/[iI][dD]_[eE][dD]25519
|
|
||||||
|
|
||||||
# Dependencies: restored inside the image, never copied in.
|
|
||||||
**/node_modules
|
|
||||||
|
|
||||||
# OS metadata.
|
|
||||||
**/.DS_Store
|
|
||||||
**/Thumbs.db
|
|
||||||
|
|
||||||
# Editor state: never a build input, and it churns COPY.
|
|
||||||
**/*.swp
|
|
||||||
**/*.swo
|
|
||||||
**/*~
|
|
||||||
**/*.bak
|
|
||||||
**/.idea
|
|
||||||
**/.vscode
|
|
||||||
**/*.sublime-*
|
|
||||||
|
|
||||||
# pixa's own entries. Nothing in the build reads .gitignore. On the
|
|
||||||
# host, `make build` writes bin/pixad, and the example config keeps its
|
|
||||||
# state directory in data/.
|
|
||||||
.gitignore
|
.gitignore
|
||||||
/bin
|
.DS_Store
|
||||||
/data
|
.env*
|
||||||
|
.claude
|
||||||
|
node_modules
|
||||||
|
bin/
|
||||||
|
data/
|
||||||
|
|||||||
@@ -46,12 +46,6 @@ P2: security: per-IP rate limiting on the image routes
|
|||||||
not pixad's limit); `miss` 70 r/s, p50 52 ms, p95 91 ms, p99 122 ms, peak 100
|
not pixad's limit); `miss` 70 r/s, p50 52 ms, p95 91 ms, p99 122 ms, peak 100
|
||||||
MiB, one fetch per request; `herd` 74 r/s, p50 52 ms, p95 69 ms, p99 111 ms,
|
MiB, one fetch per request; `herd` 74 r/s, p50 52 ms, p95 69 ms, p99 111 ms,
|
||||||
peak 60 MiB, 188 fetches for 749 requests.
|
peak 60 MiB, 188 fetches for 749 requests.
|
||||||
- 2026-10-04 `.dockerignore` keeps secrets out at every depth (closes #205): the
|
|
||||||
file is now the standard one from `sneak/prompts`, whose patterns match in
|
|
||||||
every directory and, for environment files and private keys, in any letter
|
|
||||||
case, so a nested `.env` or `server.key` no longer reaches the build context.
|
|
||||||
pixa still sends `.git` without `.git/config` in place of the standard file's
|
|
||||||
`.git` line, and still leaves out `.gitignore`, `/bin` and `/data`.
|
|
||||||
- 2026-10-04 `REPO_POLICIES.md` matches the canonical copy again (closes #196):
|
- 2026-10-04 `REPO_POLICIES.md` matches the canonical copy again (closes #196):
|
||||||
it is replaced, unchanged, by `prompts/REPO_POLICIES.md` from `sneak/prompts`
|
it is replaced, unchanged, by `prompts/REPO_POLICIES.md` from `sneak/prompts`
|
||||||
`main`. The rules it adds that pixa's tree breaks are filed:
|
`main`. The rules it adds that pixa's tree breaks are filed:
|
||||||
|
|||||||
Reference in New Issue
Block a user