Keep secrets out of the Docker build context at every depth (closes #205) #210

Merged
clawbot merged 1 commits from issue-205-dockerignore-every-depth into next 2026-10-05 00:07:37 +02:00
Collaborator

Implements #205.

.dockerignore patterns without a leading **/ match only at the root of the build context, so a nested .env, node_modules or private key still reached the context and, through COPY . ., a build-stage layer; there was no private key pattern at all. The file is now the standard .dockerignore from sneak/prompts, header comment included: every pattern that should match anywhere starts with **/, and environment files and private keys (.pem, .key, .p12, .pfx, the SSH key names) are matched in any letter case. It also brings in the standard OS and editor entries.

pixa's own differences, each with its reason in the file:

  • .git is still sent without .git/config, in place of the standard .git line, as decided in #166.
  • .gitignore, /bin and /data stay out. bin/ and data/ are written /bin and /data, as the standard file asks for a repo's own entries; they match the same paths as before.

Checked as the policy asks: files for every pattern planted at the root and two directories deep, a COPY . . image built with the old and the new file and listed, then removed.

Disclosures:

  • No test is committed; the check above is the one the plan asked for.
  • REPO_POLICIES.md in pixa is still the old copy (its re-vendoring is #196); this change follows the canonical file.
  • Not covered, outside this issue: the local configs .gitignore names, config.yaml and config.dev.yml, can hold the signing key and still reach the build context at the root.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/pixa/issues/205. `.dockerignore` patterns without a leading `**/` match only at the root of the build context, so a nested `.env`, `node_modules` or private key still reached the context and, through `COPY . .`, a build-stage layer; there was no private key pattern at all. The file is now the standard `.dockerignore` from `sneak/prompts`, header comment included: every pattern that should match anywhere starts with `**/`, and environment files and private keys (`.pem`, `.key`, `.p12`, `.pfx`, the SSH key names) are matched in any letter case. It also brings in the standard OS and editor entries. pixa's own differences, each with its reason in the file: - `.git` is still sent without `.git/config`, in place of the standard `.git` line, as decided in https://git.eeqj.de/sneak/pixa/issues/166. - `.gitignore`, `/bin` and `/data` stay out. `bin/` and `data/` are written `/bin` and `/data`, as the standard file asks for a repo's own entries; they match the same paths as before. Checked as the policy asks: files for every pattern planted at the root and two directories deep, a `COPY . .` image built with the old and the new file and listed, then removed. Disclosures: - No test is committed; the check above is the one the plan asked for. - `REPO_POLICIES.md` in pixa is still the old copy (its re-vendoring is https://git.eeqj.de/sneak/pixa/issues/196); this change follows the canonical file. - Not covered, outside this issue: the local configs `.gitignore` names, `config.yaml` and `config.dev.yml`, can hold the signing key and still reach the build context at the root. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 23:33:53 +02:00
clawbot self-assigned this 2026-10-04 23:33:53 +02:00
Author
Collaborator

PASS at 101714f9f0588d993a54fb2257c7a20b3cb9705b, rebased onto next at cca2e3f926d380baeb11244991c3fd220ef231ff.

Model: opus-5-5

**PASS** at `101714f9f0588d993a54fb2257c7a20b3cb9705b`, rebased onto `next` at `cca2e3f926d380baeb11244991c3fd220ef231ff`. Model: opus-5-5
clawbot added 1 commit 2026-10-05 00:05:34 +02:00
.dockerignore patterns without a leading **/ match only at the root of
the build context, so a nested .env or private key still reached it and,
through COPY . ., a build-stage layer. The file is now the standard one
from sneak/prompts: every pattern that should match anywhere has **/,
and private keys and environment files are matched in any letter case.

pixa keeps its own differences: .git is still sent without .git/config
in place of the standard .git line, which the version stamp needs, and
.gitignore, /bin and /data stay out.

Model: opus-5-5
clawbot force-pushed issue-205-dockerignore-every-depth from 101714f9f0 to 4f1eef92ba 2026-10-05 00:05:34 +02:00 Compare
clawbot merged commit ef828f71a5 into next 2026-10-05 00:07:37 +02:00
clawbot deleted branch issue-205-dockerignore-every-depth 2026-10-05 00:07:38 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#210