Keep git-ignored files and data/ out of the Docker build context (closes #266) #270

Merged
clawbot merged 1 commits from issue-266-dockerignore-secrets into next 2026-10-02 05:43:41 +02:00
3 changed files with 40 additions and 6 deletions
+30 -6
View File
@@ -1,11 +1,35 @@
# .git is sent so that `make build` in the Dockerfile can stamp the commit into # .git is sent so that `make build` in the Dockerfile can stamp the commit into
# upaas. List no tracked file here: git would see it as deleted in the build and # upaas. List no tracked file here: git would see it as deleted in the build and
# the version would end in -dirty. # the version would end in -dirty.
# The patterns of .gitignore; **/ makes Docker match them in every directory.
**/.DS_Store
**/Thumbs.db
**/*.swp
**/*.swo
**/*~
**/*.bak
**/.idea/
**/.vscode/
**/*.sublime-*
**/node_modules/
**/.env
**/.env.*
**/*.pem
**/*.key
**/bin/
**/*.exe
**/*.exe~
**/*.dll
**/*.so
**/*.dylib
**/*.test
**/*.out
/data/
# Git never applies its ignore patterns inside .git; send all of it again.
!.git/**
# .git is sent without its config, because a remote URL there can carry a # .git is sent without its config, because a remote URL there can carry a
# credential; `git describe` does not need it. # credential; `git describe` does not need it. Keep this after !.git/**.
.git/config .git/config
.env
bin/
.vscode/
.idea/
*.test
+5
View File
@@ -1,3 +1,5 @@
# .dockerignore repeats these patterns; change both together.
# OS # OS
.DS_Store .DS_Store
Thumbs.db Thumbs.db
@@ -29,3 +31,6 @@ bin/
*.dylib *.dylib
*.test *.test
*.out *.out
# upaasd's data directory when it runs from the checkout (UPAAS_DATA_DIR default)
/data/
+5
View File
@@ -20,6 +20,11 @@ regress.
# Completed Steps # Completed Steps
- 2026-10-02: `docker build .` no longer sends git-ignored files, such as
`.env.local`, `*.key` files or upaasd's `data/` directory with its session
key, into the build stages and the build cache: `.dockerignore` now leaves out
everything `.gitignore` does, and `data/` is git-ignored (#266).
- 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there - 2026-10-02: `.dockerignore` leaves out `.git/config`, so a remote URL there
that carries a credential no longer goes into the Docker build; the image that carries a credential no longer goes into the Docker build; the image
still shows the commit it was built from (#269). still shows the commit it was built from (#269).