Keep git-ignored files and data/ out of the Docker build context (closes #266)
Check / check (pull_request) Successful in 4m12s
Check / check (pull_request) Successful in 4m12s
.dockerignore now lists every .gitignore pattern, each with **/ so Docker matches it in every directory as git does, plus the top-level data/ directory. git-ignored secrets such as .env.local, *.key files and data/session.key no longer reach the build stages or the build cache. A last !.git/** line sends all of .git again, since git never applies these patterns inside it, so a branch named like fix/session.key still resolves. No tracked file is listed, so the version still comes from git describe without -dirty. data/, where upaasd keeps its database and session key when run from the checkout, is now git-ignored. Model: opus-5-5
This commit was merged in pull request #270.
This commit is contained in:
@@ -20,6 +20,11 @@ regress.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-02: `docker build .` no longer sends git-ignored files, such as
|
||||
`.env.local`, `*.key` files or upaasd's `data/` directory with its session
|
||||
key, into the build stages and the build cache: `.dockerignore` now leaves out
|
||||
everything `.gitignore` does, and `data/` is git-ignored (#266).
|
||||
|
||||
- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there
|
||||
that carries a credential no longer goes into the Docker build; the image
|
||||
still shows the commit it was built from (#269).
|
||||
|
||||
Reference in New Issue
Block a user