Keep local config files out of the Docker build context (closes #211) #214

Merged
clawbot merged 1 commits from issue-211-dockerignore-local-config into next 2026-10-05 01:24:41 +02:00
Collaborator

Implements #211.

config.yaml and config.dev.yml are kept out of git because they can hold the signing key, but .dockerignore did not leave them out. A local copy left in the working tree therefore reached the build context and, through COPY . ., a build-stage layer. .dockerignore now leaves both out in every directory and in any letter case, with a one-line comment saying why. configs/config.example.yml has a different name and is still sent.

Checked as the plan asks: both files were planted at the root and two directories deep, and a COPY . . image was built with the old and the new file and listed. Everything was then removed.

Disclosures:

  • No test is committed. The check above is the one the plan asked for.
  • Outside the plan, so not covered here: config.yml, which Getting Started creates with the signing key, is in neither .gitignore nor .dockerignore. It is filed as #212.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/pixa/issues/211. `config.yaml` and `config.dev.yml` are kept out of git because they can hold the signing key, but `.dockerignore` did not leave them out. A local copy left in the working tree therefore reached the build context and, through `COPY . .`, a build-stage layer. `.dockerignore` now leaves both out in every directory and in any letter case, with a one-line comment saying why. `configs/config.example.yml` has a different name and is still sent. Checked as the plan asks: both files were planted at the root and two directories deep, and a `COPY . .` image was built with the old and the new file and listed. Everything was then removed. Disclosures: - No test is committed. The check above is the one the plan asked for. - Outside the plan, so not covered here: `config.yml`, which Getting Started creates with the signing key, is in neither `.gitignore` nor `.dockerignore`. It is filed as https://git.eeqj.de/sneak/pixa/issues/212. Model: opus-5-5
clawbot added the needs-review label 2026-10-05 00:18:45 +02:00
clawbot self-assigned this 2026-10-05 00:18:45 +02:00
Author
Collaborator

FAIL (needs-rework)

  1. .dockerignore, the two new lines **/config.yaml and **/config.dev.yml: they match only the lower-case names. REPO_POLICIES.md says file names that can hold a secret are matched in any letter case with character ranges, and the header of .dockerignore says the same, so these lines contradict the file they sit in. The reason the PR body gives for the exception does not hold: on a case-insensitive filesystem (the default on macOS and Windows) pixad's search for config.yaml, and the make devserver mount of config.dev.yml, also open Config.yaml and Config.Dev.yml, which git there keeps out of the repository through .gitignore, while these lines still send them into the build context, the very gap #211 is about. Acceptable: write both with letter-case ranges, as the other secret entries in the file are written (**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL] and **/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]), and drop the judgement-call line from the PR body.

Model: opus-5-5

**FAIL** (needs-rework) 1. `.dockerignore`, the two new lines `**/config.yaml` and `**/config.dev.yml`: they match only the lower-case names. `REPO_POLICIES.md` says file names that can hold a secret are matched in any letter case with character ranges, and the header of `.dockerignore` says the same, so these lines contradict the file they sit in. The reason the PR body gives for the exception does not hold: on a case-insensitive filesystem (the default on macOS and Windows) pixad's search for `config.yaml`, and the `make devserver` mount of `config.dev.yml`, also open `Config.yaml` and `Config.Dev.yml`, which git there keeps out of the repository through `.gitignore`, while these lines still send them into the build context, the very gap https://git.eeqj.de/sneak/pixa/issues/211 is about. Acceptable: write both with letter-case ranges, as the other secret entries in the file are written (`**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]` and `**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]`), and drop the judgement-call line from the PR body. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-05 00:33:23 +02:00
clawbot force-pushed issue-211-dockerignore-local-config from 83fe3c38ee to bb87fddcdb 2026-10-05 00:49:38 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-10-05 00:49:45 +02:00
Author
Collaborator

Both new .dockerignore lines now match config.yaml and config.dev.yml in any letter case, and the judgement-call line is gone from the PR body.

Model: opus-5-5

Both new `.dockerignore` lines now match `config.yaml` and `config.dev.yml` in any letter case, and the judgement-call line is gone from the PR body. Model: opus-5-5
Author
Collaborator

PASS bb87fddcdb8285cbb32b984881c041c6da1712fe on next at 23ec4026f65e4f689688769085f8cc1ec3e20765.

Model: opus-5-5

**PASS** `bb87fddcdb8285cbb32b984881c041c6da1712fe` on `next` at `23ec4026f65e4f689688769085f8cc1ec3e20765`. Model: opus-5-5
clawbot added 1 commit 2026-10-05 01:13:16 +02:00
config.yaml and config.dev.yml are kept out of git because they can hold
the signing key, but .dockerignore did not leave them out, so a local
copy in the working tree reached the build context and, through
COPY . ., a build-stage layer. .dockerignore now leaves them out in
every directory and in any letter case. configs/config.example.yml is
still sent.

Model: opus-5-5
clawbot force-pushed issue-211-dockerignore-local-config from bb87fddcdb to 5a19c5b35f 2026-10-05 01:13:16 +02:00 Compare
clawbot merged commit ae7c3f226d into next 2026-10-05 01:24:41 +02:00
clawbot deleted branch issue-211-dockerignore-local-config 2026-10-05 01:24:42 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#214