Since #236 (commit a48d90f), .dockerignore leaves out only .env, bin/, .vscode/, .idea/ and *.test, so docker build . sends the working copy's git-ignored files into the build stages: confirmed for .env.local, a *.key file and data/session.key. The final image holds only the binary, but the builder stage and the build cache hold the secrets. Also, data/, the data directory upaasd creates when run from the checkout, is not git-ignored, so git status shows it and the build version can end in -dirty.
Definition of done:
The build context holds the same files as a clean checkout, plus .git: .dockerignore also leaves out everything .gitignore leaves out, and data/. It lists no tracked file, so a clean clone's version still comes from git describe without -dirty.
data/ is git-ignored.
Checked by building from a working copy that has .env.local, a *.key and data/session.key: none of them is in the builder stage.
PR to next, independent review (make check and docker build . on the rebased head), squash.
Model: opus-5-5
Found while investigating https://git.eeqj.de/sneak/upaas/issues/261 (https://git.eeqj.de/sneak/upaas/issues/261#issuecomment-110547 has the details).
Since https://git.eeqj.de/sneak/upaas/issues/236 (commit `a48d90f`), `.dockerignore` leaves out only `.env`, `bin/`, `.vscode/`, `.idea/` and `*.test`, so `docker build .` sends the working copy's git-ignored files into the build stages: confirmed for `.env.local`, a `*.key` file and `data/session.key`. The final image holds only the binary, but the builder stage and the build cache hold the secrets. Also, `data/`, the data directory upaasd creates when run from the checkout, is not git-ignored, so `git status` shows it and the build version can end in `-dirty`.
Definition of done:
- The build context holds the same files as a clean checkout, plus `.git`: `.dockerignore` also leaves out everything `.gitignore` leaves out, and `data/`. It lists no tracked file, so a clean clone's version still comes from `git describe` without `-dirty`.
- `data/` is git-ignored.
- Checked by building from a working copy that has `.env.local`, a `*.key` and `data/session.key`: none of them is in the builder stage.
- PR to `next`, independent review (`make check` and `docker build .` on the rebased head), squash.
Model: opus-5-5
clawbot
self-assigned this 2026-10-02 02:54:04 +02:00
#270: .dockerignore now leaves out every .gitignore pattern, each written with **/ so it matches in every directory as git does, plus the top-level /data/; /data/ is git-ignored.
Model: opus-5-5
https://git.eeqj.de/sneak/upaas/pulls/270: `.dockerignore` now leaves out every `.gitignore` pattern, each written with `**/` so it matches in every directory as git does, plus the top-level `/data/`; `/data/` is git-ignored.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found while investigating #261 (#261 (comment) has the details).
Since #236 (commit
a48d90f),.dockerignoreleaves out only.env,bin/,.vscode/,.idea/and*.test, sodocker build .sends the working copy's git-ignored files into the build stages: confirmed for.env.local, a*.keyfile anddata/session.key. The final image holds only the binary, but the builder stage and the build cache hold the secrets. Also,data/, the data directory upaasd creates when run from the checkout, is not git-ignored, sogit statusshows it and the build version can end in-dirty.Definition of done:
.git:.dockerignorealso leaves out everything.gitignoreleaves out, anddata/. It lists no tracked file, so a clean clone's version still comes fromgit describewithout-dirty.data/is git-ignored..env.local, a*.keyanddata/session.key: none of them is in the builder stage.next, independent review (make checkanddocker build .on the rebased head), squash.Model: opus-5-5
#270:
.dockerignorenow leaves out every.gitignorepattern, each written with**/so it matches in every directory as git does, plus the top-level/data/;/data/is git-ignored.Model: opus-5-5