# Docker matches this file with moby/patternmatcher: Go filepath.Match # semantics plus a `**` extension, compiled to a regexp. Plain # filepath.Match has no `**` at all. What follows from that: `*` does not # cross `/`, and a pattern without a leading `**/` is anchored at the # build-context root. Every depth-independent pattern therefore needs the # `**/` prefix — without it `config/.env` and `certs/server.key` still # ship while the file reads as solved. # # Root-anchored entries are for paths that occur exactly once, at the # context root. A host-built binary is the usual case, and it must be # written anchored: `/myapp`, never `**/myapp`. The prefixed form also # matches `cmd/myapp/`, which deletes the package directory from the # context. In-repo agent scratch is the other case, for the same reason. # # Matching is case-sensitive, so `**/*.key` does not match # `certs/SERVER.KEY`, which is reachable on the case-insensitive # filesystems most laptops use. Adding an ALL-CAPS twin per pattern is # not the fix: it still misses `Server.Key` while reading as though case # were handled. Character ranges cover every spelling in one line, so # every secret name below is written that way — including the # extensionless SSH keys and `.envrc`, because on those same # case-insensitive filesystems direnv reads `.ENVRC` and ssh reads # `ID_RSA`. # # `**/*.[eE][nN][vV]` also excludes a committed env template such as # `example.env`. If the build genuinely needs one, re-include it with a # negation after the pattern: `!docs/example.env`. # # Extend this file with the repo's own host-built artifacts (compiled # binaries, test binaries, coverage output); those are per-repo and # belong here because a host build otherwise drops them into the # context. # Repository metadata: exactly one, at the context root. Excluding it # means `git describe` cannot run in any build stage, and it fails # quietly there rather than erroring, so a version embedded that way # comes out empty. Compute the version on the host and pass it in with # `--build-arg VERSION=...`; see the version rule in REPO_POLICIES.md. .git # In-repo agent scratch: one directory at the context root, holding a # full additional checkout of the repo for each in-flight agent. Written # anchored because it occurs exactly once — the `**/` form would also # match a nested directory of that name. Not case-folded, unlike the # secret patterns below: tooling creates this in exactly one spelling, # and a miss costs build-context bloat rather than exposure. .claude # Environment files. `*.env` covers both the bare `.env` name (`*` matches # the empty string) and the `prod.env` convention. **/*.[eE][nN][vV] **/.[eE][nN][vV].* **/.[eE][nN][vV][rR][cC] # Private keys and the bundles that carry them. Public certificates # (*.crt, *.cer) are deliberately absent: they are not secrets and are # sometimes a legitimate build input. **/*.[pP][eE][mM] **/*.[kK][eE][yY] **/*.[pP]12 **/*.[pP][fF][xX] **/[iI][dD]_[rR][sS][aA] **/[iI][dD]_[dD][sS][aA] **/[iI][dD]_[eE][cC][dD][sS][aA] **/[iI][dD]_[eE][dD]25519 # Dependencies: restored inside the image, never copied in. **/node_modules # OS metadata. **/.DS_Store **/Thumbs.db # Editor state. Never a build input, and it churns under a developer's # hands, so it invalidates COPY for reasons unrelated to the source. **/*.swp **/*.swo **/*~ **/*.bak **/.idea **/.vscode **/*.sublime-*