# Docker matches this file with moby/patternmatcher: Go filepath.Match # semantics plus a `**` extension, compiled to a regexp. Plain # filepath.Match has no `**` at all. What follows from that: `*` does not # cross `/`, and a pattern without a leading `**/` is anchored at the # build-context root. Every depth-independent pattern therefore needs the # `**/` prefix — without it `config/.env` and `certs/server.key` still # ship while the file reads as solved. # # Root-anchored entries are for paths that occur exactly once, at the # context root. A host-built binary is the usual case, and it must be # written anchored: `/myapp`, never `**/myapp`. The prefixed form also # matches `cmd/myapp/`, which deletes the package directory from the # context. In-repo agent scratch is the other case, for the same reason # — with the caveat recorded at that entry: anchoring is exact only # where agents run at the repo root, and a repo where they do not must # add its own entries. # # Matching is case-sensitive, so `**/*.key` does not match # `certs/SERVER.KEY`, which is reachable on the case-insensitive # filesystems most laptops use. Adding an ALL-CAPS twin per pattern is # not the fix: it still misses `Server.Key` while reading as though case # were handled. Character ranges cover every spelling in one line, so # every secret name below is written that way — including the # extensionless SSH keys and `.envrc`, because on those same # case-insensitive filesystems direnv reads `.ENVRC` and ssh reads # `ID_RSA`. # # `**/*.[eE][nN][vV]` also excludes a committed env template such as # `example.env`. If the build genuinely needs one, re-include it with a # negation after the pattern: `!docs/example.env`. # # Extend this file with the repo's own host-built artifacts (compiled # binaries, test binaries, coverage output); those are per-repo and # belong here because a host build otherwise drops them into the # context. # Repository metadata: exactly one, at the context root. Excluding it # means `git describe` cannot run in any build stage, and it fails # quietly there rather than erroring, so a version embedded that way # comes out empty. Compute the version on the host and pass it in with # `--build-arg VERSION=...`; see the version rule in REPO_POLICIES.md. .git # In-repo agent scratch: a directory holding a full additional checkout # of the repo for each in-flight agent. Anchored because it occurs # exactly once *where agents run at the repo root*, which is the # convention this file assumes; the `**/` form would also match any # nested directory of that name and delete it from the build. # # KNOWN GAP, and it is not hypothetical: the directory is created in the # agent's working directory. If agents in this repo run in # subdirectories — a monorepo with a per-service agent, say — then # `services/api/.claude/` is NOT excluded by the line below and still # reaches the build context and the image, which is the exposure this # entry exists to close. A repo in that shape adds its own anchored # entries (`/services/api/.claude`), or `**/.claude` after confirming no # legitimately named nested directory would be caught. # # Not case-folded, unlike the secret patterns below: tooling creates # this directory in exactly one spelling, so a folded pattern would add # no coverage. .claude # Environment files. `*.env` covers both the bare `.env` name (`*` matches # the empty string) and the `prod.env` convention. **/*.[eE][nN][vV] **/.[eE][nN][vV].* **/.[eE][nN][vV][rR][cC] # Private keys and the bundles that carry them. Public certificates # (*.crt, *.cer) are deliberately absent: they are not secrets and are # sometimes a legitimate build input. **/*.[pP][eE][mM] **/*.[kK][eE][yY] **/*.[pP]12 **/*.[pP][fF][xX] **/[iI][dD]_[rR][sS][aA] **/[iI][dD]_[dD][sS][aA] **/[iI][dD]_[eE][cC][dD][sS][aA] **/[iI][dD]_[eE][dD]25519 # Dependencies: restored inside the image, never copied in. **/node_modules # OS metadata. **/.DS_Store **/Thumbs.db # Editor state. Never a build input, and it churns under a developer's # hands, so it invalidates COPY for reasons unrelated to the source. **/*.swp **/*.swo **/*~ **/*.bak **/.idea **/.vscode **/*.sublime-*