Keep git-ignored files and data/ out of the Docker build context (closes #266)
Check / check (pull_request) Skipped

.dockerignore now lists every .gitignore pattern, each with **/ so Docker
matches it in every directory as git does, plus the top-level data/
directory. git-ignored secrets such as .env.local, *.key files and
data/session.key no longer reach the build stages or the build cache. A last
!.git/** line sends all of .git again, since git never applies these patterns
inside it, so a branch named like fix/session.key still resolves. No tracked
file is listed, so the version still comes from git describe without -dirty.

data/, where upaasd keeps its database and session key when run from the
checkout, is now git-ignored.

Model: opus-5-5
This commit is contained in:
2026-10-02 02:26:27 +00:00
parent 5168db69d9
commit fb8163ae30
3 changed files with 38 additions and 5 deletions
+28 -5
View File
@@ -1,8 +1,31 @@
# .git is sent so that `make build` in the Dockerfile can stamp the commit into # .git is sent so that `make build` in the Dockerfile can stamp the commit into
# upaas. List no tracked file here: git would see it as deleted in the build and # upaas. List no tracked file here: git would see it as deleted in the build and
# the version would end in -dirty. # the version would end in -dirty.
.env
bin/ # The patterns of .gitignore; **/ makes Docker match them in every directory.
.vscode/ **/.DS_Store
.idea/ **/Thumbs.db
*.test **/*.swp
**/*.swo
**/*~
**/*.bak
**/.idea/
**/.vscode/
**/*.sublime-*
**/node_modules/
**/.env
**/.env.*
**/*.pem
**/*.key
**/bin/
**/*.exe
**/*.exe~
**/*.dll
**/*.so
**/*.dylib
**/*.test
**/*.out
/data/
# Git never applies its ignore patterns inside .git; send all of it again.
!.git/**
+5
View File
@@ -1,3 +1,5 @@
# .dockerignore repeats these patterns; change both together.
# OS # OS
.DS_Store .DS_Store
Thumbs.db Thumbs.db
@@ -29,3 +31,6 @@ bin/
*.dylib *.dylib
*.test *.test
*.out *.out
# upaasd's data directory when it runs from the checkout (UPAAS_DATA_DIR default)
/data/
+5
View File
@@ -20,6 +20,11 @@ regress.
# Completed Steps # Completed Steps
- 2026-10-02: `docker build .` no longer sends git-ignored files, such as
`.env.local`, `*.key` files or upaasd's `data/` directory with its session
key, into the build stages and the build cache: `.dockerignore` now leaves out
everything `.gitignore` does, and `data/` is git-ignored (#266).
- 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it - 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it
from Go's `runtime.GOARCH` when it runs, and the startup log line reports it from Go's `runtime.GOARCH` when it runs, and the startup log line reports it
as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts` as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts`