From 2daa63796a53915b91dacf211f1fca62d9610456 Mon Sep 17 00:00:00 2001 From: sneak Date: Fri, 2 Oct 2026 00:56:56 +0000 Subject: [PATCH] Keep git-ignored files and data/ out of the Docker build context (closes #266) .dockerignore now lists every .gitignore pattern, each with **/ so Docker matches it in every directory as git does, plus the top-level data/ directory. git-ignored secrets such as .env.local, *.key files and data/session.key no longer reach the build stages or the build cache. .git stays in the context and no tracked file is listed, so the version still comes from git describe without -dirty. data/, where upaasd keeps its database and session key when run from the checkout, is now git-ignored. Model: opus-5-5 --- .dockerignore | 30 +++++++++++++++++++++++++----- .gitignore | 5 +++++ TODO.md | 5 +++++ 3 files changed, 35 insertions(+), 5 deletions(-) diff --git a/.dockerignore b/.dockerignore index 5b2701b..1e34192 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,8 +1,28 @@ # .git is sent so that `make build` in the Dockerfile can stamp the commit into # upaas. List no tracked file here: git would see it as deleted in the build and # the version would end in -dirty. -.env -bin/ -.vscode/ -.idea/ -*.test + +# The patterns of .gitignore; **/ makes Docker match them in every directory. +**/.DS_Store +**/Thumbs.db +**/*.swp +**/*.swo +**/*~ +**/*.bak +**/.idea/ +**/.vscode/ +**/*.sublime-* +**/node_modules/ +**/.env +**/.env.* +**/*.pem +**/*.key +**/bin/ +**/*.exe +**/*.exe~ +**/*.dll +**/*.so +**/*.dylib +**/*.test +**/*.out +/data/ diff --git a/.gitignore b/.gitignore index 69191af..5e9024a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,5 @@ +# .dockerignore repeats these patterns; change both together. + # OS .DS_Store Thumbs.db @@ -29,3 +31,6 @@ bin/ *.dylib *.test *.out + +# upaasd's data directory when it runs from the checkout (UPAAS_DATA_DIR default) +/data/ diff --git a/TODO.md b/TODO.md index bf60f7f..de2930c 100644 --- a/TODO.md +++ b/TODO.md @@ -20,6 +20,11 @@ regress. # Completed Steps +- 2026-10-02: `docker build .` no longer sends git-ignored files, such as + `.env.local`, `*.key` files or upaasd's `data/` directory with its session + key, into the build stages and the build cache: `.dockerignore` now leaves out + everything `.gitignore` does, and `data/` is git-ignored (#266). + - 2026-10-01: Built images are tagged `upaas-:`, git's short form of the commit built, instead of the deployment number. A redeploy of a commit gives its tag to the new image; the old one is kept while the app runs