Keep secrets out of the Docker build context at every depth (closes #29)
The canonical .dockerignore was three lines while the canonical Dockerfile does `COPY . .`, so a local .env, *.pem or *.key shipped into the build context and could land in an image layer, invisible to every git-based check. Copying .gitignore's patterns across is not the repair: .dockerignore anchors an unprefixed pattern at the context root, so that form protects only the repository root while reading as solved. Every depth-independent pattern here carries `**/`, and secret names are character ranges because matching is case-sensitive and an ALL-CAPS twin still misses `Server.Key`. Public certificates are deliberately left in as a legitimate build input. Verified by enumerating a probe image. Model: opus-5
This commit is contained in:
@@ -52,6 +52,13 @@ Template files can be fetched from:
|
||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/prompts/REPO_POLICIES.md`
|
||||
- [ ] `Dockerfile` and `.dockerignore` — fetch `.dockerignore` from
|
||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.dockerignore`
|
||||
- Extend `.dockerignore` with the repo's own host-built artifacts, giving
|
||||
every depth-independent pattern a `**/` prefix — but write a repo-root
|
||||
binary anchored, `/myapp` and never `**/myapp`, which would also match
|
||||
`cmd/myapp/` and delete the package directory. Do not transplant
|
||||
`.gitignore`'s patterns: `.dockerignore` anchors an unprefixed pattern at
|
||||
the context root, so the copied form leaves `config/.env` in the build
|
||||
context while reading as solved.
|
||||
- All Dockerfiles must run `make check` as a build step
|
||||
- Server: also builds and runs the application
|
||||
- Non-server: brings up dev environment and runs `make check`
|
||||
@@ -108,7 +115,8 @@ are thin shims calling them. Model scripts:
|
||||
- [ ] `make docker` succeeds
|
||||
- [ ] `script/cibuild` succeeds and demonstrably executed the checks — a
|
||||
sub-second build, or `CACHED` on a check layer, means nothing ran
|
||||
- [ ] No secrets in repo
|
||||
- [ ] No secrets in repo, and none in the build context: enumerate a probe image
|
||||
rather than reading `.dockerignore`
|
||||
- [ ] No mutable image/package references
|
||||
- [ ] No unnecessary files in repo root
|
||||
- [ ] All dates written as YYYY-MM-DD
|
||||
|
||||
Reference in New Issue
Block a user