Keep git-ignored files and data/ out of the Docker build context (closes #266)
Check / check (pull_request) Skipped
Check / check (pull_request) Skipped
.dockerignore now lists every .gitignore pattern, each with **/ so Docker matches it in every directory as git does, plus the top-level data/ directory. git-ignored secrets such as .env.local, *.key files and data/session.key no longer reach the build stages or the build cache. .git stays in the context and no tracked file is listed, so the version still comes from git describe without -dirty. data/, where upaasd keeps its database and session key when run from the checkout, is now git-ignored. Model: opus-5-5
This commit is contained in:
+25
-5
@@ -1,8 +1,28 @@
|
|||||||
# .git is sent so that `make build` in the Dockerfile can stamp the commit into
|
# .git is sent so that `make build` in the Dockerfile can stamp the commit into
|
||||||
# upaas. List no tracked file here: git would see it as deleted in the build and
|
# upaas. List no tracked file here: git would see it as deleted in the build and
|
||||||
# the version would end in -dirty.
|
# the version would end in -dirty.
|
||||||
.env
|
|
||||||
bin/
|
# The patterns of .gitignore; **/ makes Docker match them in every directory.
|
||||||
.vscode/
|
**/.DS_Store
|
||||||
.idea/
|
**/Thumbs.db
|
||||||
*.test
|
**/*.swp
|
||||||
|
**/*.swo
|
||||||
|
**/*~
|
||||||
|
**/*.bak
|
||||||
|
**/.idea/
|
||||||
|
**/.vscode/
|
||||||
|
**/*.sublime-*
|
||||||
|
**/node_modules/
|
||||||
|
**/.env
|
||||||
|
**/.env.*
|
||||||
|
**/*.pem
|
||||||
|
**/*.key
|
||||||
|
**/bin/
|
||||||
|
**/*.exe
|
||||||
|
**/*.exe~
|
||||||
|
**/*.dll
|
||||||
|
**/*.so
|
||||||
|
**/*.dylib
|
||||||
|
**/*.test
|
||||||
|
**/*.out
|
||||||
|
/data/
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# .dockerignore repeats these patterns; change both together.
|
||||||
|
|
||||||
# OS
|
# OS
|
||||||
.DS_Store
|
.DS_Store
|
||||||
Thumbs.db
|
Thumbs.db
|
||||||
@@ -29,3 +31,6 @@ bin/
|
|||||||
*.dylib
|
*.dylib
|
||||||
*.test
|
*.test
|
||||||
*.out
|
*.out
|
||||||
|
|
||||||
|
# upaasd's data directory when it runs from the checkout (UPAAS_DATA_DIR default)
|
||||||
|
/data/
|
||||||
|
|||||||
@@ -20,6 +20,11 @@ regress.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-02: `docker build .` no longer sends git-ignored files, such as
|
||||||
|
`.env.local`, `*.key` files or upaasd's `data/` directory with its session
|
||||||
|
key, into the build stages and the build cache: `.dockerignore` now leaves out
|
||||||
|
everything `.gitignore` does, and `data/` is git-ignored (#266).
|
||||||
|
|
||||||
- 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it
|
- 2026-10-02: The build no longer passes the CPU architecture in: upaas reads it
|
||||||
from Go's `runtime.GOARCH` when it runs, and the startup log line reports it
|
from Go's `runtime.GOARCH` when it runs, and the startup log line reports it
|
||||||
as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts`
|
as `arch`. `CONVENTIONS.md` follows the updated conventions in `sneak/prompts`
|
||||||
|
|||||||
Reference in New Issue
Block a user