Keep config.yml out of git and the Docker build context (closes #212) #217

Merged
clawbot merged 1 commits from issue-212-ignore-config-yml into next 2026-10-05 01:58:32 +02:00
Collaborator

Implements #212.

README Getting Started has you create config.yml at the repository root with a real signing key, and pixad looks for it in its working directory. Neither .gitignore nor .dockerignore left it out, so it could be committed and, through COPY . ., reach a build-stage layer of the next make docker in that tree.

.gitignore now ignores config.yml next to config.yaml. .dockerignore leaves it out in every directory and in any letter case, next to the config.yaml and config.dev.yml entries from #214. configs/config.example.yml has a different name and is still committed and sent.

Checked as the plan asks: config.yml was planted at the root and two directories deep, a COPY . . image was built with the old and the new file and listed, and everything was then removed.

Disclosures:

  • Judgement call: the .dockerignore entry is written with letter ranges, **/[cC][oO][nN][fF][iI][gG].[yY][mM][lL], not the plan's **/config.yml, as that file's own rule for secrets and the two entries beside it are.
  • No test is committed. The check above is the one the plan asks for.
  • README.md is unchanged: it does not describe what git or the Docker build leave out.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/pixa/issues/212. README Getting Started has you create `config.yml` at the repository root with a real signing key, and `pixad` looks for it in its working directory. Neither `.gitignore` nor `.dockerignore` left it out, so it could be committed and, through `COPY . .`, reach a build-stage layer of the next `make docker` in that tree. `.gitignore` now ignores `config.yml` next to `config.yaml`. `.dockerignore` leaves it out in every directory and in any letter case, next to the `config.yaml` and `config.dev.yml` entries from https://git.eeqj.de/sneak/pixa/pulls/214. `configs/config.example.yml` has a different name and is still committed and sent. Checked as the plan asks: `config.yml` was planted at the root and two directories deep, a `COPY . .` image was built with the old and the new file and listed, and everything was then removed. Disclosures: - Judgement call: the `.dockerignore` entry is written with letter ranges, `**/[cC][oO][nN][fF][iI][gG].[yY][mM][lL]`, not the plan's `**/config.yml`, as that file's own rule for secrets and the two entries beside it are. - No test is committed. The check above is the one the plan asks for. - `README.md` is unchanged: it does not describe what git or the Docker build leave out. Model: opus-5-5
clawbot added the needs-review label 2026-10-05 01:33:28 +02:00
clawbot self-assigned this 2026-10-05 01:33:28 +02:00
clawbot added 1 commit 2026-10-05 01:33:28 +02:00
Getting Started has you create config.yml at the repository root with a
real signing key, but neither .gitignore nor .dockerignore left it out,
so it could be committed and, through COPY . ., reach a build-stage
layer. .gitignore now ignores it next to config.yaml, and .dockerignore
leaves it out in every directory and in any letter case, as it already
does config.yaml and config.dev.yml.

Model: opus-5-5
Author
Collaborator

PASS at f18cf8d90622ed3f87f415c4f0e298c13b4aca0b, rebased onto next at ae7c3f226d8a161b54a233d61f365f0cb48c4379.

Model: opus-5-5

**PASS** at `f18cf8d90622ed3f87f415c4f0e298c13b4aca0b`, rebased onto `next` at `ae7c3f226d8a161b54a233d61f365f0cb48c4379`. Model: opus-5-5
clawbot merged commit f77faf13de into next 2026-10-05 01:58:32 +02:00
clawbot deleted branch issue-212-ignore-config-yml 2026-10-05 01:58:32 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#217