check / check (push) Failing after 1s
Getting Started has you create config.yml at the repository root with a real signing key, but neither .gitignore nor .dockerignore left it out, so it could be committed and, through COPY . ., reach a build-stage layer. .gitignore now ignores it next to config.yaml, and .dockerignore leaves it out in every directory and in any letter case, as it already does config.yaml and config.dev.yml. Model: opus-5-5
74 lines
2.6 KiB
Plaintext
74 lines
2.6 KiB
Plaintext
# .dockerignore does NOT use .gitignore semantics. Docker matches with
|
|
# moby/patternmatcher: filepath.Match plus `**`, so `*` does not cross
|
|
# `/` and an unprefixed pattern is anchored at the context root. Every
|
|
# depth-independent pattern therefore needs `**/`, or `config/.env` and
|
|
# `certs/server.key` still ship while this file reads as solved. Only
|
|
# genuinely root-anchored entries go unprefixed. Never transplant these
|
|
# into .gitignore, where `**/` is wrong.
|
|
#
|
|
# Matching is case-sensitive, so secrets use character ranges rather
|
|
# than an ALL-CAPS twin, which would still miss `Server.Key`.
|
|
#
|
|
# Extend with this repo's own host-built artifacts, written anchored:
|
|
# `/myapp`, never `**/myapp`, which also matches `cmd/myapp/` and
|
|
# deletes the package directory from the context.
|
|
|
|
# Unlike the standard file, which leaves out all of .git, pixa sends
|
|
# .git without its config. Without a VERSION build argument the stage
|
|
# that compiles runs `git describe --tags --always` on .git, which does
|
|
# not need .git/config; that file can hold a credential, such as a
|
|
# password in a remote URL or the token the CI checkout step stores there.
|
|
.git/config
|
|
|
|
# Agent scratch: one full checkout of the repo per in-flight agent.
|
|
# Anchored because it occurs once where agents run at the repo root.
|
|
# KNOWN GAP: a repo running agents in subdirectories still ships
|
|
# `services/api/.claude/` and must add its own anchored entry.
|
|
.claude
|
|
|
|
# Environment files. `*.env` covers bare `.env` and the `prod.env`
|
|
# convention. Re-include a committed template with a negation if the
|
|
# build needs one: `!docs/example.env`.
|
|
**/*.[eE][nN][vV]
|
|
**/.[eE][nN][vV].*
|
|
**/.[eE][nN][vV][rR][cC]
|
|
|
|
# Private keys and the bundles carrying them. Public certificates
|
|
# (*.crt, *.cer) are deliberately absent: they are legitimate inputs.
|
|
**/*.[pP][eE][mM]
|
|
**/*.[kK][eE][yY]
|
|
**/*.[pP]12
|
|
**/*.[pP][fF][xX]
|
|
**/[iI][dD]_[rR][sS][aA]
|
|
**/[iI][dD]_[dD][sS][aA]
|
|
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
|
**/[iI][dD]_[eE][dD]25519
|
|
|
|
# Dependencies: restored inside the image, never copied in.
|
|
**/node_modules
|
|
|
|
# OS metadata.
|
|
**/.DS_Store
|
|
**/Thumbs.db
|
|
|
|
# Editor state: never a build input, and it churns COPY.
|
|
**/*.swp
|
|
**/*.swo
|
|
**/*~
|
|
**/*.bak
|
|
**/.idea
|
|
**/.vscode
|
|
**/*.sublime-*
|
|
|
|
# pixa's own entries. Nothing in the build reads .gitignore. On the
|
|
# host, `make build` writes bin/pixad, and the example config keeps its
|
|
# state directory in data/.
|
|
.gitignore
|
|
/bin
|
|
/data
|
|
|
|
# Local config files, kept out of git because they can hold the signing key.
|
|
**/[cC][oO][nN][fF][iI][gG].[yY][mM][lL]
|
|
**/[cC][oO][nN][fF][iI][gG].[yY][aA][mM][lL]
|
|
**/[cC][oO][nN][fF][iI][gG].[dD][eE][vV].[yY][mM][lL]
|