docker build . sent the working copy's git-ignored files into the build stages, so secrets such as .env.local, *.key files and upaasd's data/session.key ended up in the builder stage and the build cache (found in #261 (comment)).
.dockerignore now lists every .gitignore pattern, plus /data/. .git stays in the context and no tracked file is listed, so the version still comes from git describe without -dirty.
.gitignore now leaves out /data/, the data directory upaasd creates when run from the checkout, and says at the top that .dockerignore repeats its patterns.
What the diff does not show:
Each pattern in .dockerignore starts with **/. Without it Docker matches a pattern only at the top of the build context, while git matches it in every directory, so a .env.local or a *.key in a subdirectory would still be sent.
**/ also reaches inside .git, where git never applies these patterns: a branch or tag named like fix/session.key would lose its ref and the image would show dev. The !.git/** line after the patterns sends all of .git again; the .git/config exclusion from #271 comes after it so it still applies.
Judgement call: data/ is written /data/ in both files, so only the checkout's top-level data directory is left out, not every directory named data.
Nothing checks that the two files agree: a pattern added to .gitignore has to be added to .dockerignore by hand.
Model: opus-5-5
`docker build .` sent the working copy's git-ignored files into the build stages, so secrets such as `.env.local`, `*.key` files and upaasd's `data/session.key` ended up in the builder stage and the build cache (found in https://git.eeqj.de/sneak/upaas/issues/261#issuecomment-110547).
- `.dockerignore` now lists every `.gitignore` pattern, plus `/data/`. `.git` stays in the context and no tracked file is listed, so the version still comes from `git describe` without `-dirty`.
- `.gitignore` now leaves out `/data/`, the data directory upaasd creates when run from the checkout, and says at the top that `.dockerignore` repeats its patterns.
What the diff does not show:
- Each pattern in `.dockerignore` starts with `**/`. Without it Docker matches a pattern only at the top of the build context, while git matches it in every directory, so a `.env.local` or a `*.key` in a subdirectory would still be sent.
- `**/` also reaches inside `.git`, where git never applies these patterns: a branch or tag named like `fix/session.key` would lose its ref and the image would show `dev`. The `!.git/**` line after the patterns sends all of `.git` again; the `.git/config` exclusion from https://git.eeqj.de/sneak/upaas/pulls/271 comes after it so it still applies.
- Judgement call: `data/` is written `/data/` in both files, so only the checkout's top-level data directory is left out, not every directory named `data`.
- Nothing checks that the two files agree: a pattern added to `.gitignore` has to be added to `.dockerignore` by hand.
Model: opus-5-5
.dockerignore lines 6 to 27: the **/ prefix makes Docker apply these patterns inside .git too, which git never does. A branch or tag whose name matches one of them (for example a branch named fix/session.key or release.test, or one under a bin/ path) loses its ref file from the build context, so the build cannot resolve HEAD and the image is stamped dev instead of the git describe version. Before this change these patterns matched only at the top of the context and .git arrived whole. Acceptable: after the patterns, a !.git/** line with a one-line comment, so everything under .git is sent again as the definition of done requires (!.git alone does not do it). It must stay above the .git/config exclusion that #269 adds.
Model: opus-5-5
`.dockerignore` lines 6 to 27: the `**/` prefix makes Docker apply these patterns inside `.git` too, which git never does. A branch or tag whose name matches one of them (for example a branch named `fix/session.key` or `release.test`, or one under a `bin/` path) loses its ref file from the build context, so the build cannot resolve `HEAD` and the image is stamped `dev` instead of the `git describe` version. Before this change these patterns matched only at the top of the context and `.git` arrived whole. Acceptable: after the patterns, a `!.git/**` line with a one-line comment, so everything under `.git` is sent again as the definition of done requires (`!.git` alone does not do it). It must stay above the `.git/config` exclusion that https://git.eeqj.de/sneak/upaas/issues/269 adds.
Model: opus-5-5
.dockerignore now lists every .gitignore pattern, each with **/ so Docker
matches it in every directory as git does, plus the top-level data/
directory. git-ignored secrets such as .env.local, *.key files and
data/session.key no longer reach the build stages or the build cache. A last
!.git/** line sends all of .git again, since git never applies these patterns
inside it, so a branch named like fix/session.key still resolves. No tracked
file is listed, so the version still comes from git describe without -dirty.
data/, where upaasd keeps its database and session key when run from the
checkout, is now git-ignored.
Model: opus-5-5
Rework: .dockerignore now ends its patterns with !.git/**, so all of .git is sent again and a branch or tag named like fix/session.key keeps its ref; the .git/config exclusion from #271, now on next, sits after it so it still applies. Rebased onto next; the PR body mentions the new line.
Model: opus-5-5
Rework: `.dockerignore` now ends its patterns with `!.git/**`, so all of `.git` is sent again and a branch or tag named like `fix/session.key` keeps its ref; the `.git/config` exclusion from https://git.eeqj.de/sneak/upaas/pulls/271, now on `next`, sits after it so it still applies. Rebased onto `next`; the PR body mentions the new line.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
docker build .sent the working copy's git-ignored files into the build stages, so secrets such as.env.local,*.keyfiles and upaasd'sdata/session.keyended up in the builder stage and the build cache (found in #261 (comment))..dockerignorenow lists every.gitignorepattern, plus/data/..gitstays in the context and no tracked file is listed, so the version still comes fromgit describewithout-dirty..gitignorenow leaves out/data/, the data directory upaasd creates when run from the checkout, and says at the top that.dockerignorerepeats its patterns.What the diff does not show:
.dockerignorestarts with**/. Without it Docker matches a pattern only at the top of the build context, while git matches it in every directory, so a.env.localor a*.keyin a subdirectory would still be sent.**/also reaches inside.git, where git never applies these patterns: a branch or tag named likefix/session.keywould lose its ref and the image would showdev. The!.git/**line after the patterns sends all of.gitagain; the.git/configexclusion from #271 comes after it so it still applies.data/is written/data/in both files, so only the checkout's top-level data directory is left out, not every directory nameddata..gitignorehas to be added to.dockerignoreby hand.Model: opus-5-5
.dockerignorelines 6 to 27: the**/prefix makes Docker apply these patterns inside.gittoo, which git never does. A branch or tag whose name matches one of them (for example a branch namedfix/session.keyorrelease.test, or one under abin/path) loses its ref file from the build context, so the build cannot resolveHEADand the image is stampeddevinstead of thegit describeversion. Before this change these patterns matched only at the top of the context and.gitarrived whole. Acceptable: after the patterns, a!.git/**line with a one-line comment, so everything under.gitis sent again as the definition of done requires (!.gitalone does not do it). It must stay above the.git/configexclusion that #269 adds.Model: opus-5-5
fecf06d8e5tofb8163ae30fb8163ae30to629011522fRework:
.dockerignorenow ends its patterns with!.git/**, so all of.gitis sent again and a branch or tag named likefix/session.keykeeps its ref; the.git/configexclusion from #271, now onnext, sits after it so it still applies. Rebased ontonext; the PR body mentions the new line.Model: opus-5-5
Review passed.
Model: opus-5-5