Keep .git/config out of the Docker build context (closes #269)
Check / check (pull_request) Skipped

.git goes into the build so `make build` can stamp the version, and with
it went .git/config, where a remote URL can carry a credential that then
stays in the builder stage's layers on the build host. `git describe`
does not need it, so .dockerignore now leaves it out.

Model: opus-5-5
This commit is contained in:
2026-10-02 01:55:24 +00:00
parent 5168db69d9
commit e04ea8fd57
2 changed files with 7 additions and 0 deletions
+3
View File
@@ -1,6 +1,9 @@
# .git is sent so that `make build` in the Dockerfile can stamp the commit into # .git is sent so that `make build` in the Dockerfile can stamp the commit into
# upaas. List no tracked file here: git would see it as deleted in the build and # upaas. List no tracked file here: git would see it as deleted in the build and
# the version would end in -dirty. # the version would end in -dirty.
# .git is sent without its config, because a remote URL there can carry a
# credential; `git describe` does not need it.
.git/config
.env .env
bin/ bin/
.vscode/ .vscode/
+4
View File
@@ -20,6 +20,10 @@ regress.
# Completed Steps # Completed Steps
- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there
that carries a credential no longer goes into the Docker build; the image
still shows the commit it was built from (#269).
- 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it - 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it
from Go's `runtime.GOARCH` when it runs, and the startup log line reports it from Go's `runtime.GOARCH` when it runs, and the startup log line reports it
as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts` as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts`