From e11d280950746d39a6426795a41168cfb1a4055f Mon Sep 17 00:00:00 2001 From: sneak Date: Fri, 2 Oct 2026 01:17:52 +0000 Subject: [PATCH] Keep .git/config out of the Docker build context (closes #269) .git goes into the build so `make build` can stamp the version, and with it went .git/config, where a remote URL can carry a credential that then stays in the builder stage's layers on the build host. `git describe` does not need it, so .dockerignore now leaves it out. Model: opus-5-5 --- .dockerignore | 3 +++ TODO.md | 4 ++++ 2 files changed, 7 insertions(+) diff --git a/.dockerignore b/.dockerignore index 5b2701b..ae9975f 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,6 +1,9 @@ # .git is sent so that `make build` in the Dockerfile can stamp the commit into # upaas. List no tracked file here: git would see it as deleted in the build and # the version would end in -dirty. +# .git is sent without its config, because a remote URL there can carry a +# credential; `git describe` does not need it. +.git/config .env bin/ .vscode/ diff --git a/TODO.md b/TODO.md index bf60f7f..4095a92 100644 --- a/TODO.md +++ b/TODO.md @@ -20,6 +20,10 @@ regress. # Completed Steps +- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there + that carries a credential no longer goes into the Docker build; the image + still shows the commit it was built from (#269). + - 2026-10-01: Built images are tagged `upaas-:`, git's short form of the commit built, instead of the deployment number. A redeploy of a commit gives its tag to the new image; the old one is kept while the app runs