Compare commits
1 Commits
533fc61817
...
b8d21d1592
| Author | SHA1 | Date | |
|---|---|---|---|
| b8d21d1592 |
@@ -2,48 +2,21 @@
|
|||||||
# does not cross `/`, and a pattern without a leading `**/` is anchored
|
# does not cross `/`, and a pattern without a leading `**/` is anchored
|
||||||
# at the build-context root. Every depth-independent pattern therefore
|
# at the build-context root. Every depth-independent pattern therefore
|
||||||
# needs the `**/` prefix — without it `config/.env` and
|
# needs the `**/` prefix — without it `config/.env` and
|
||||||
# `certs/server.key` still ship while the file reads as solved.
|
# `certs/server.key` still ship while the file reads as solved. Entries
|
||||||
#
|
# that are genuinely root-anchored stay unprefixed. Extend this file
|
||||||
# Root-anchored entries are for paths that occur exactly once, at the
|
# with the repo's own host-built artifacts (compiled binaries, test
|
||||||
# context root. A host-built binary is the usual case, and it must be
|
# binaries, coverage output); those are per-repo and belong here because
|
||||||
# written anchored: `/myapp`, never `**/myapp`. The prefixed form also
|
# a host build otherwise drops them into the context.
|
||||||
# matches `cmd/myapp/`, which deletes the package directory from the
|
|
||||||
# context.
|
|
||||||
#
|
|
||||||
# Matching is case-sensitive, so `**/*.key` does not match
|
|
||||||
# `certs/SERVER.KEY`. The secret-material extensions below use character
|
|
||||||
# classes, which cover every capitalisation in one line — a doubled
|
|
||||||
# ALL-CAPS pattern would still miss `Server.Key` while reading as though
|
|
||||||
# case were handled. Names that only ever exist in one spelling because
|
|
||||||
# a tool writes them (`.env`, `.envrc`, `id_rsa`) stay literal.
|
|
||||||
#
|
|
||||||
# Extend this file with the repo's own host-built artifacts (compiled
|
|
||||||
# binaries, test binaries, coverage output); those are per-repo and
|
|
||||||
# belong here because a host build otherwise drops them into the
|
|
||||||
# context.
|
|
||||||
|
|
||||||
# Repository metadata: exactly one, at the context root.
|
# Repository metadata: exactly one, at the context root.
|
||||||
.git
|
.git
|
||||||
|
|
||||||
# Environment files. `*.env` covers the `prod.env` / `local.env`
|
# Environment and secrets. These are the reason the prefixes matter: a
|
||||||
# convention; the `.env` and `.env.*` spellings are listed explicitly
|
# developer's local copy is invisible to every git-based check.
|
||||||
# because they are what most tooling writes.
|
|
||||||
**/.env
|
**/.env
|
||||||
**/.env.*
|
**/.env.*
|
||||||
**/*.[eE][nN][vV]
|
**/*.pem
|
||||||
**/.envrc
|
**/*.key
|
||||||
|
|
||||||
# Private keys and the bundles that carry them. Public certificates
|
|
||||||
# (*.crt, *.cer) are deliberately absent: they are not secrets and are
|
|
||||||
# sometimes a legitimate build input.
|
|
||||||
**/*.[pP][eE][mM]
|
|
||||||
**/*.[kK][eE][yY]
|
|
||||||
**/*.[pP]12
|
|
||||||
**/*.[pP][fF][xX]
|
|
||||||
**/id_rsa
|
|
||||||
**/id_dsa
|
|
||||||
**/id_ecdsa
|
|
||||||
**/id_ed25519
|
|
||||||
|
|
||||||
# Dependencies: restored inside the image, never copied in.
|
# Dependencies: restored inside the image, never copied in.
|
||||||
**/node_modules
|
**/node_modules
|
||||||
|
|||||||
12
TODO.md
12
TODO.md
@@ -28,14 +28,10 @@ fmt-check, and commit.
|
|||||||
`filepath.Match` semantics — `**/`-prefixed so they hold at every depth, which
|
`filepath.Match` semantics — `**/`-prefixed so they hold at every depth, which
|
||||||
also fixes nested `node_modules` — rather than transplanted from `.gitignore`,
|
also fixes nested `node_modules` — rather than transplanted from `.gitignore`,
|
||||||
whose unprefixed form protects only the repository root while reading as
|
whose unprefixed form protects only the repository root while reading as
|
||||||
solved. Coverage extends past the `.env`/`.pem`/`.key` trio to the `prod.env`
|
solved. `REPO_POLICIES.md` and both repo checklists now state that asymmetry
|
||||||
convention, `.envrc`, PKCS#12 bundles and extensionless SSH keys, with
|
and require verification by enumerating the image rather than by reading the
|
||||||
capitalisation handled by character classes because matching is case-sensitive
|
patterns. Verified with a probe image before, against the naive unprefixed
|
||||||
and an ALL-CAPS twin per pattern still misses `Server.Key`. `REPO_POLICIES.md`
|
form, and after.
|
||||||
and both repo checklists now state that asymmetry and require verification by
|
|
||||||
enumerating the image rather than by reading the patterns. Verified with a
|
|
||||||
probe image before, against three naive forms (unprefixed, lowercase-only,
|
|
||||||
ALL-CAPS-doubled), and after.
|
|
||||||
- 2026-08-09: Made the pinned golangci-lint actually propagate: REPO_POLICIES.md
|
- 2026-08-09: Made the pinned golangci-lint actually propagate: REPO_POLICIES.md
|
||||||
now carries the canonical `script/bootstrap` snippet for Go repos, which
|
now carries the canonical `script/bootstrap` snippet for Go repos, which
|
||||||
installs when the installed version does not match the pin (the old
|
installs when the installed version does not match the pin (the old
|
||||||
|
|||||||
@@ -37,11 +37,6 @@ with your task.
|
|||||||
`CHECK_EPOCH` rule in `REPO_POLICIES.md`. Without them the check layer is
|
`CHECK_EPOCH` rule in `REPO_POLICIES.md`. Without them the check layer is
|
||||||
served from cache on an unchanged tree and the build reports a green it
|
served from cache on an unchanged tree and the build reports a green it
|
||||||
never ran.
|
never ran.
|
||||||
- [ ] `.dockerignore` excludes the repo's own host-built artifacts (compiled
|
|
||||||
binaries, test binaries, coverage output), written root-anchored —
|
|
||||||
`/myapp`, never `**/myapp`, which would also match `cmd/myapp/`. An
|
|
||||||
existing repo is where such a binary is likeliest to already be sitting in
|
|
||||||
the build context, invisible to git.
|
|
||||||
- [ ] Every depth-independent pattern in `.dockerignore` carries a `**/` prefix;
|
- [ ] Every depth-independent pattern in `.dockerignore` carries a `**/` prefix;
|
||||||
only genuinely root-anchored entries such as `.git` are unprefixed, and
|
only genuinely root-anchored entries such as `.git` are unprefixed, and
|
||||||
`.gitignore`'s patterns have not been transplanted unmodified.
|
`.gitignore`'s patterns have not been transplanted unmodified.
|
||||||
|
|||||||
@@ -53,9 +53,7 @@ Template files can be fetched from:
|
|||||||
- [ ] `Dockerfile` and `.dockerignore` — fetch `.dockerignore` from
|
- [ ] `Dockerfile` and `.dockerignore` — fetch `.dockerignore` from
|
||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.dockerignore`
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.dockerignore`
|
||||||
- Extend `.dockerignore` with the repo's own host-built artifacts, giving
|
- Extend `.dockerignore` with the repo's own host-built artifacts, giving
|
||||||
every depth-independent pattern a `**/` prefix — but write a repo-root
|
every depth-independent pattern a `**/` prefix. Do not transplant
|
||||||
binary anchored, `/myapp` and never `**/myapp`, which would also match
|
|
||||||
`cmd/myapp/` and delete the package directory. Do not transplant
|
|
||||||
`.gitignore`'s patterns: `.dockerignore` anchors an unprefixed pattern at
|
`.gitignore`'s patterns: `.dockerignore` anchors an unprefixed pattern at
|
||||||
the context root, so the copied form leaves `config/.env` in the build
|
the context root, so the copied form leaves `config/.env` in the build
|
||||||
context while reading as solved. See the `.dockerignore` rule in
|
context while reading as solved. See the `.dockerignore` rule in
|
||||||
|
|||||||
@@ -354,20 +354,7 @@ style conventions are in separate documents:
|
|||||||
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.dockerignore` and extend
|
`https://git.eeqj.de/sneak/prompts/raw/branch/main/.dockerignore` and extend
|
||||||
it with the repo's own host-built artifacts — a host `make build` that leaves
|
it with the repo's own host-built artifacts — a host `make build` that leaves
|
||||||
a compiled binary in the repo root puts that binary in the build context,
|
a compiled binary in the repo root puts that binary in the build context,
|
||||||
where `.gitignore` hides it from every git-based check. Write that binary
|
where `.gitignore` hides it from every git-based check.
|
||||||
anchored, `/myapp` and never `**/myapp`: the prefixed form also matches
|
|
||||||
`cmd/myapp/` and deletes the package directory from the context.
|
|
||||||
|
|
||||||
- **`.dockerignore` matching is case-sensitive, so cover capitalisation with
|
|
||||||
character classes rather than by doubling patterns.** `**/*.key` does not
|
|
||||||
match `certs/SERVER.KEY`, which is reachable on the case-insensitive
|
|
||||||
filesystems most laptops use. Adding an ALL-CAPS twin for each pattern is not
|
|
||||||
the fix: it still misses `Server.Key` and `Ca.Pem` while reading as though
|
|
||||||
case were handled — the same manufactured confidence as the root-anchored
|
|
||||||
form. `filepath.Match` supports character ranges, so one line covers every
|
|
||||||
spelling: `**/*.[kK][eE][yY]`, `**/*.[pP][eE][mM]`. Apply this to
|
|
||||||
secret-material extensions; names that exist in exactly one spelling because a
|
|
||||||
tool writes them (`.env`, `.envrc`, `id_rsa`) stay literal.
|
|
||||||
|
|
||||||
- **Verify `.dockerignore` by enumerating the image, not by reading the
|
- **Verify `.dockerignore` by enumerating the image, not by reading the
|
||||||
patterns.** Plant files at the root _and_ at least two directories deep, build
|
patterns.** Plant files at the root _and_ at least two directories deep, build
|
||||||
|
|||||||
Reference in New Issue
Block a user