From fb8163ae30a1c55bc9a4051c699c017e9cec69bf Mon Sep 17 00:00:00 2001 From: sneak Date: Fri, 2 Oct 2026 00:56:56 +0000 Subject: [PATCH] Keep git-ignored files and data/ out of the Docker build context (closes #266) .dockerignore now lists every .gitignore pattern, each with **/ so Docker matches it in every directory as git does, plus the top-level data/ directory. git-ignored secrets such as .env.local, *.key files and data/session.key no longer reach the build stages or the build cache. A last !.git/** line sends all of .git again, since git never applies these patterns inside it, so a branch named like fix/session.key still resolves. No tracked file is listed, so the version still comes from git describe without -dirty. data/, where upaasd keeps its database and session key when run from the checkout, is now git-ignored. Model: opus-5-5 --- .dockerignore | 33 ++++++++++++++++++++++++++++----- .gitignore | 5 +++++ TODO.md | 5 +++++ 3 files changed, 38 insertions(+), 5 deletions(-) diff --git a/.dockerignore b/.dockerignore index 5b2701b..376fa60 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,8 +1,31 @@ # .git is sent so that `make build` in the Dockerfile can stamp the commit into # upaas. List no tracked file here: git would see it as deleted in the build and # the version would end in -dirty. -.env -bin/ -.vscode/ -.idea/ -*.test + +# The patterns of .gitignore; **/ makes Docker match them in every directory. +**/.DS_Store +**/Thumbs.db +**/*.swp +**/*.swo +**/*~ +**/*.bak +**/.idea/ +**/.vscode/ +**/*.sublime-* +**/node_modules/ +**/.env +**/.env.* +**/*.pem +**/*.key +**/bin/ +**/*.exe +**/*.exe~ +**/*.dll +**/*.so +**/*.dylib +**/*.test +**/*.out +/data/ + +# Git never applies its ignore patterns inside .git; send all of it again. +!.git/** diff --git a/.gitignore b/.gitignore index 69191af..5e9024a 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,5 @@ +# .dockerignore repeats these patterns; change both together. + # OS .DS_Store Thumbs.db @@ -29,3 +31,6 @@ bin/ *.dylib *.test *.out + +# upaasd's data directory when it runs from the checkout (UPAAS_DATA_DIR default) +/data/ diff --git a/TODO.md b/TODO.md index d6bca11..7482492 100644 --- a/TODO.md +++ b/TODO.md @@ -20,6 +20,11 @@ regress. # Completed Steps +- 2026-10-02: `docker build .` no longer sends git-ignored files, such as + `.env.local`, `*.key` files or upaasd's `data/` directory with its session + key, into the build stages and the build cache: `.dockerignore` now leaves out + everything `.gitignore` does, and `data/` is git-ignored (#266). + - 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it from Go's `runtime.GOARCH` when it runs, and the startup log line reports it as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts`