.dockerignore keeps secrets out only at the repository root #205

Closed
opened 2026-10-04 22:29:51 +02:00 by clawbot · 2 comments
Collaborator

The canonical REPO_POLICIES.md, re-vendored under #196, now says a .dockerignore pattern without a leading **/ matches only at the root of the build context, and that secret patterns need character ranges such as **/*.[kK][eE][yY], because matching is case-sensitive. The canonical file is .dockerignore in sneak/prompts.

pixa's .dockerignore:

  • .env*, node_modules and .DS_Store have no **/, so a file such as configs/.env still reaches the build context and, through COPY . ., an image layer.
  • It has no pattern for private keys at all (*.pem, *.key, *.p12, *.pfx, id_rsa and the other SSH key names), although .gitignore ignores *.pem and *.key.

Not part of this: pixa sends .git into the build context, without .git/config, on purpose (#166), so the canonical file's .git line does not apply.

The policy asks for the result to be checked by planting files at the root and at least two directories deep, building an image that does COPY . ., and listing what landed in it.

Model: opus-5-5

The canonical `REPO_POLICIES.md`, re-vendored under https://git.eeqj.de/sneak/pixa/issues/196, now says a `.dockerignore` pattern without a leading `**/` matches only at the root of the build context, and that secret patterns need character ranges such as `**/*.[kK][eE][yY]`, because matching is case-sensitive. The canonical file is `.dockerignore` in `sneak/prompts`. pixa's `.dockerignore`: - `.env*`, `node_modules` and `.DS_Store` have no `**/`, so a file such as `configs/.env` still reaches the build context and, through `COPY . .`, an image layer. - It has no pattern for private keys at all (`*.pem`, `*.key`, `*.p12`, `*.pfx`, `id_rsa` and the other SSH key names), although `.gitignore` ignores `*.pem` and `*.key`. Not part of this: pixa sends `.git` into the build context, without `.git/config`, on purpose (https://git.eeqj.de/sneak/pixa/issues/166), so the canonical file's `.git` line does not apply. The policy asks for the result to be checked by planting files at the root and at least two directories deep, building an image that does `COPY . .`, and listing what landed in it. Model: opus-5-5
clawbot self-assigned this 2026-10-04 22:29:51 +02:00
Author
Collaborator

Plan, checked against next at 708a9be:

  • Bring .dockerignore in line with the canonical one in sneak/prompts: every pattern that should match anywhere gets **/ (.env*, node_modules, .DS_Store and the rest), and add its private key patterns with character ranges (**/*.[pP][eE][mM], **/*.[kK][eE][yY], .p12, .pfx, the SSH key names), as it writes them.
  • Keep pixa's deliberate difference: .git stays in the build context (without .git/config), per #166; the canonical file's .git line does not apply. Keep any other pixa-specific line, with its reason.
  • Check as the policy asks: plant files matching each secret pattern at the root and at least two directories deep, build an image that does COPY . ., list what landed in it, and remove the image and the planted files. One line in the PR saying it was done; no listing.

Model: opus-5-5

Plan, checked against `next` at `708a9be`: - Bring `.dockerignore` in line with the canonical one in `sneak/prompts`: every pattern that should match anywhere gets `**/` (`.env*`, `node_modules`, `.DS_Store` and the rest), and add its private key patterns with character ranges (`**/*.[pP][eE][mM]`, `**/*.[kK][eE][yY]`, `.p12`, `.pfx`, the SSH key names), as it writes them. - Keep pixa's deliberate difference: `.git` stays in the build context (without `.git/config`), per https://git.eeqj.de/sneak/pixa/issues/166; the canonical file's `.git` line does not apply. Keep any other pixa-specific line, with its reason. - Check as the policy asks: plant files matching each secret pattern at the root and at least two directories deep, build an image that does `COPY . .`, list what landed in it, and remove the image and the planted files. One line in the PR saying it was done; no listing. Model: opus-5-5
Author
Collaborator

#210 makes .dockerignore the standard file from sneak/prompts, so environment files and private keys stay out of the build context at every depth and in any letter case. pixa keeps sending .git without .git/config, and keeps leaving out .gitignore, /bin and /data.

Model: opus-5-5

https://git.eeqj.de/sneak/pixa/pulls/210 makes `.dockerignore` the standard file from `sneak/prompts`, so environment files and private keys stay out of the build context at every depth and in any letter case. pixa keeps sending `.git` without `.git/config`, and keeps leaving out `.gitignore`, `/bin` and `/data`. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#205