From b101bc1a80228fd6854dd915fa0b7e141cbffea8 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Fri, 2 Oct 2026 05:43:40 +0200 Subject: [PATCH] Keep git-ignored files and data/ out of the Docker build context (closes #266) .dockerignore now lists every .gitignore pattern, each with **/ so Docker matches it in every directory as git does, plus the top-level data/ directory. git-ignored secrets such as .env.local, *.key files and data/session.key no longer reach the build stages or the build cache. A last !.git/** line sends all of .git again, since git never applies these patterns inside it, so a branch named like fix/session.key still resolves. No tracked file is listed, so the version still comes from git describe without -dirty. data/, where upaasd keeps its database and session key when run from the checkout, is now git-ignored. Model: opus-5-5 --- .dockerignore | 36 ++++++++++++++++++++++++++++++------ .gitignore | 5 +++++ TODO.md | 5 +++++ 3 files changed, 40 insertions(+), 6 deletions(-) diff --git a/.dockerignore b/.dockerignore index ae9975f..5e0ca82 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,11 +1,35 @@ # .git is sent so that `make build` in the Dockerfile can stamp the commit into # upaas. List no tracked file here: git would see it as deleted in the build and # the version would end in -dirty. + +# The patterns of .gitignore; **/ makes Docker match them in every directory. +**/.DS_Store +**/Thumbs.db +**/*.swp +**/*.swo +**/*~ +**/*.bak +**/.idea/ +**/.vscode/ +**/*.sublime-* +**/node_modules/ +**/.env +**/.env.* +**/*.pem +**/*.key +**/bin/ +**/*.exe +**/*.exe~ +**/*.dll +**/*.so +**/*.dylib +**/*.test +**/*.out +/data/ + +# Git never applies its ignore patterns inside .git; send all of it again. +!.git/** + # .git is sent without its config, because a remote URL there can carry a -# credential; `git describe` does not need it. +# credential; `git describe` does not need it. Keep this after !.git/**. .git/config -.env -bin/ -.vscode/ -.idea/ -*.test diff --git a/.gitignore b/.gitignore index 69191af..5e9024a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,5 @@ +# .dockerignore repeats these patterns; change both together. + # OS .DS_Store Thumbs.db @@ -29,3 +31,6 @@ bin/ *.dylib *.test *.out + +# upaasd's data directory when it runs from the checkout (UPAAS_DATA_DIR default) +/data/ diff --git a/TODO.md b/TODO.md index 3570099..a4446ef 100644 --- a/TODO.md +++ b/TODO.md @@ -20,6 +20,11 @@ regress. # Completed Steps +- 2026-10-02: `docker build .` no longer sends git-ignored files, such as + `.env.local`, `*.key` files or upaasd's `data/` directory with its session + key, into the build stages and the build cache: `.dockerignore` now leaves out + everything `.gitignore` does, and `data/` is git-ignored (#266). + - 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there that carries a credential no longer goes into the Docker build; the image still shows the commit it was built from (#269).