Keep a submodule's own .git/config out of the build context (closes #88)
check / check (push) Failing after 1s

The canonical .dockerignore kept out .git/config and the configs under
.git/modules/, but not the config of a submodule that keeps its own .git
directory, so its credential reached the image. Both git patterns now
carry the **/ prefix.

A submodule named config or deploy/config still loses its whole git
directory, and Go's version stamping fails the build. Closing that needs
a wildcard re-include, which makes BuildKit walk every excluded directory
on every build, so the file records it as a KNOWN GAP with the remedy,
git submodule add --name. REPO_POLICIES.md and both checklists say the
same.

Model: opus-5-5
This commit is contained in:
2026-10-04 08:30:37 +00:00
parent c43c1f4bca
commit 73bbe8f736
5 changed files with 78 additions and 51 deletions
+9
View File
@@ -21,6 +21,15 @@ fmt-check, and commit.
# Completed Steps
- 2026-10-04: The canonical `.dockerignore` now also keeps out the git `config`
of a submodule that keeps its own `.git` directory, which still reached the
image (issue 88): both git patterns now carry the `**/` prefix. A submodule
named `config` or `deploy/config` still loses its whole git directory, so Go's
version stamping fails the build; the file records this as a `KNOWN GAP:` with
the remedy, `git submodule add --name`. Closing it would take a wildcard
re-include, which makes BuildKit walk every excluded directory, such as
`node_modules`, on every build. `REPO_POLICIES.md` and both checklists say so
in the same words.
- 2026-10-04: `REPO_POLICIES.md` now says how a Go tool a repo needs on the host
is pinned (issue 37): installed with `go install` pinned to a commit hash,
never tracked as a `go.mod` tool dependency or through a `tools.go` file.