Git-ignored secrets reach the Docker build stages; data/ is not git-ignored #266

Closed
opened 2026-10-02 02:54:03 +02:00 by clawbot · 1 comment
Collaborator

Found while investigating #261 (#261 (comment) has the details).

Since #236 (commit a48d90f), .dockerignore leaves out only .env, bin/, .vscode/, .idea/ and *.test, so docker build . sends the working copy's git-ignored files into the build stages: confirmed for .env.local, a *.key file and data/session.key. The final image holds only the binary, but the builder stage and the build cache hold the secrets. Also, data/, the data directory upaasd creates when run from the checkout, is not git-ignored, so git status shows it and the build version can end in -dirty.

Definition of done:

  • The build context holds the same files as a clean checkout, plus .git: .dockerignore also leaves out everything .gitignore leaves out, and data/. It lists no tracked file, so a clean clone's version still comes from git describe without -dirty.
  • data/ is git-ignored.
  • Checked by building from a working copy that has .env.local, a *.key and data/session.key: none of them is in the builder stage.
  • PR to next, independent review (make check and docker build . on the rebased head), squash.

Model: opus-5-5

Found while investigating https://git.eeqj.de/sneak/upaas/issues/261 (https://git.eeqj.de/sneak/upaas/issues/261#issuecomment-110547 has the details). Since https://git.eeqj.de/sneak/upaas/issues/236 (commit `a48d90f`), `.dockerignore` leaves out only `.env`, `bin/`, `.vscode/`, `.idea/` and `*.test`, so `docker build .` sends the working copy's git-ignored files into the build stages: confirmed for `.env.local`, a `*.key` file and `data/session.key`. The final image holds only the binary, but the builder stage and the build cache hold the secrets. Also, `data/`, the data directory upaasd creates when run from the checkout, is not git-ignored, so `git status` shows it and the build version can end in `-dirty`. Definition of done: - The build context holds the same files as a clean checkout, plus `.git`: `.dockerignore` also leaves out everything `.gitignore` leaves out, and `data/`. It lists no tracked file, so a clean clone's version still comes from `git describe` without `-dirty`. - `data/` is git-ignored. - Checked by building from a working copy that has `.env.local`, a `*.key` and `data/session.key`: none of them is in the builder stage. - PR to `next`, independent review (`make check` and `docker build .` on the rebased head), squash. Model: opus-5-5
clawbot self-assigned this 2026-10-02 02:54:04 +02:00
Author
Collaborator

#270: .dockerignore now leaves out every .gitignore pattern, each written with **/ so it matches in every directory as git does, plus the top-level /data/; /data/ is git-ignored.

Model: opus-5-5

https://git.eeqj.de/sneak/upaas/pulls/270: `.dockerignore` now leaves out every `.gitignore` pattern, each written with `**/` so it matches in every directory as git does, plus the top-level `/data/`; `/data/` is git-ignored. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/upaas#266