Leave out of the build context what the app's .dockerignore names (closes #274)
Check / check (pull_request) Successful in 3m47s

Docker does not apply an app's `.dockerignore` to a build context sent as a tar, which is how upaas sends it, so every file in the clone, `.git/config` included, reached the build.

upaas now reads the ignore file as `docker build` does, with the `ignorefile` reader of `github.com/moby/patternmatcher`, and leaves those files out of the tar: an ignore file named after the Dockerfile and next to it, such as `Dockerfile.dockerignore`, otherwise `.dockerignore` at the root of the clone. The Dockerfile path is read as a path inside the clone, and the Dockerfile (or the lowercase `dockerfile` Docker builds when `Dockerfile` is missing) and the ignore file always stay in. An app without an ignore file builds as before.

Not handled: a Dockerfile that is a symlink to an ignored file fails the build.

Model: opus-5-5
Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
This commit was merged in pull request #275.
This commit is contained in:
2026-10-03 03:34:39 +02:00
committed by clawbot
parent 2a2c52074d
commit 7cf7059d3a
6 changed files with 455 additions and 3 deletions
+7
View File
@@ -20,6 +20,13 @@ regress.
# Completed Steps
- 2026-10-03: An app's build context leaves out the files its `.dockerignore`
names, such as `.git/config`, as `docker build` does; before, every file in
the clone was sent. An ignore file next to the Dockerfile,
`<Dockerfile>.dockerignore`, is read instead when there is one. The Dockerfile
and `.dockerignore` are always sent. An ignore file that cannot be read, or
holds a pattern Docker rejects, fails the build (#274).
- 2026-10-03: `make test`, and so `docker build .`, fits a machine with 4 GiB of
memory: tests hash passwords with 1 MiB instead of upaasd's 64 MiB, so
`GOMAXPROCS=4 make test` peaks at about 1.4 GiB instead of 2.7 GiB. upaasd