Local config files that can hold the signing key still reach the Docker build context #211

Closed
opened 2026-10-04 23:41:48 +02:00 by clawbot · 1 comment
Collaborator

Found by the work on #210 (#205). Checked against next at cca2e3f.

.gitignore keeps local config files out of git (for example config.yaml and config.dev.yml), because they can hold the signing key. .dockerignore does not exclude them, so a local config left in a working tree reaches the Docker build context and, through COPY . ., a build-stage layer of an image built from that tree.

Plan: every local config file name .gitignore excludes for that reason is excluded in .dockerignore too, at any depth (**/), with a one-line comment saying why; configs/config.example.yml (the public example) stays in. Check it as #205 did: plant such files at the root and two directories deep, build a COPY . . image, list it, remove everything.

Model: opus-5-5

Found by the work on https://git.eeqj.de/sneak/pixa/pulls/210 (https://git.eeqj.de/sneak/pixa/issues/205). Checked against `next` at `cca2e3f`. `.gitignore` keeps local config files out of git (for example `config.yaml` and `config.dev.yml`), because they can hold the signing key. `.dockerignore` does not exclude them, so a local config left in a working tree reaches the Docker build context and, through `COPY . .`, a build-stage layer of an image built from that tree. Plan: every local config file name `.gitignore` excludes for that reason is excluded in `.dockerignore` too, at any depth (`**/`), with a one-line comment saying why; `configs/config.example.yml` (the public example) stays in. Check it as https://git.eeqj.de/sneak/pixa/issues/205 did: plant such files at the root and two directories deep, build a `COPY . .` image, list it, remove everything. Model: opus-5-5
Author
Collaborator

Built in #214: .dockerignore now leaves out config.yaml and config.dev.yml in every directory. config.yml, which Getting Started creates, is in neither .gitignore nor .dockerignore; that is filed as #212.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/pixa/pulls/214: `.dockerignore` now leaves out `config.yaml` and `config.dev.yml` in every directory. `config.yml`, which Getting Started creates, is in neither `.gitignore` nor `.dockerignore`; that is filed as https://git.eeqj.de/sneak/pixa/issues/212. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#211