# .dockerignore does NOT use .gitignore semantics. Docker matches with # moby/patternmatcher: filepath.Match plus `**`, so `*` does not cross # `/` and an unprefixed pattern is anchored at the context root. Every # depth-independent pattern therefore needs `**/`, or `config/.env` and # `certs/server.key` still ship while this file reads as solved. Only # genuinely root-anchored entries go unprefixed. Never transplant these # into .gitignore, where `**/` is wrong. # # Matching is case-sensitive, so secrets use character ranges rather # than an ALL-CAPS twin, which would still miss `Server.Key`. # # Extend with this repo's own host-built artifacts, written anchored: # `/myapp`, never `**/myapp`, which also matches `cmd/myapp/` and # deletes the package directory from the context. # .git is sent without its config. Without a VERSION build argument the # stage that compiles runs `git describe --tags --always` on .git, which # does not need .git/config; that file can hold a credential, such as a # password in a remote URL or the token the CI checkout step stores there. # Each submodule keeps a config with the same exposure in its git directory # under .git/modules/, nested again for a submodule's own submodules, or in # its own .git directory when it keeps one. # KNOWN GAP: a submodule whose name has a `config` segment (`config`, # `deploy/config`, `config/lib`) loses its whole git directory, because # `**/.git/modules/**/config` also matches that segment's directory # under .git/modules/. Go's version stamping then fails the build; # nothing leaks. Name such a submodule without that segment: # `git submodule add --name`. **/.git/config **/.git/modules/**/config # Agent scratch: one full checkout of the repo per in-flight agent. # Anchored because it occurs once where agents run at the repo root. # KNOWN GAP: a repo running agents in subdirectories still ships # `services/api/.claude/` and must add its own anchored entry. .claude # Environment files. `*.env` covers bare `.env` and the `prod.env` # convention. Re-include a committed template with a negation if the # build needs one: `!docs/example.env`. **/*.[eE][nN][vV] **/.[eE][nN][vV].* **/.[eE][nN][vV][rR][cC] # Private keys and the bundles carrying them. Public certificates # (*.crt, *.cer) are deliberately absent: they are legitimate inputs. **/*.[pP][eE][mM] **/*.[kK][eE][yY] **/*.[pP]12 **/*.[pP][fF][xX] **/[iI][dD]_[rR][sS][aA] **/[iI][dD]_[dD][sS][aA] **/[iI][dD]_[eE][cC][dD][sS][aA] **/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK] **/[iI][dD]_[eE][dD]25519 **/[iI][dD]_[eE][dD]25519_[sS][kK] # Dependencies: restored inside the image, never copied in. **/node_modules # OS metadata. **/.DS_Store **/Thumbs.db # Editor state: never a build input, and it churns COPY. **/*.swp **/*.swo **/*~ **/*.bak **/.idea **/.vscode **/*.sublime-*