Keep .git/config out of the Docker build context (closes #269)

.git goes into the build so `make build` can stamp the version, and with
it went .git/config, where a remote URL can carry a credential that then
stays in the builder stage's layers on the build host. `git describe`
does not need it, so .dockerignore now leaves it out.

Model: opus-5-5
This commit is contained in:
2026-10-02 01:17:52 +00:00
parent 76858126e2
commit e11d280950
2 changed files with 7 additions and 0 deletions
+4
View File
@@ -20,6 +20,10 @@ regress.
# Completed Steps
- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there
that carries a credential no longer goes into the Docker build; the image
still shows the commit it was built from (#269).
- 2026-10-01: Built images are tagged `upaas-<app>:<short hash>`, git's short
form of the commit built, instead of the deployment number. A redeploy of a
commit gives its tag to the new image; the old one is kept while the app runs