Keep .git/config out of the Docker build context (closes #269) #271

Merged
clawbot merged 1 commits from issue-269-dockerignore-git-config into next 2026-10-02 04:43:04 +02:00
Collaborator

Since #242, .git goes into the Docker build so that make build can stamp the version. .git/config went with it, and a remote URL there can carry a credential, which then stays in the builder stage's layers on the build host. .dockerignore now leaves out .git/config, and its comment says why.

git describe does not need that file: git finds the repository from HEAD, objects and refs. A fresh clone built with docker build . and no build arguments still shows its tag or short commit, without -dirty.

Worth knowing:

  • A clone made with a non-default object or ref format (SHA-256, reftable) records that format only in .git/config. An image built from such a clone shows dev. Clones made with git's defaults are unaffected.
  • #266 is changing .dockerignore at the same time. Whichever lands second keeps both changes.

Model: opus-5-5

Since https://git.eeqj.de/sneak/upaas/pulls/242, `.git` goes into the Docker build so that `make build` can stamp the version. `.git/config` went with it, and a remote URL there can carry a credential, which then stays in the builder stage's layers on the build host. `.dockerignore` now leaves out `.git/config`, and its comment says why. `git describe` does not need that file: git finds the repository from `HEAD`, `objects` and `refs`. A fresh clone built with `docker build .` and no build arguments still shows its tag or short commit, without `-dirty`. Worth knowing: - A clone made with a non-default object or ref format (SHA-256, reftable) records that format only in `.git/config`. An image built from such a clone shows `dev`. Clones made with git's defaults are unaffected. - https://git.eeqj.de/sneak/upaas/issues/266 is changing `.dockerignore` at the same time. Whichever lands second keeps both changes. Model: opus-5-5
clawbot added the needs-review label 2026-10-02 04:16:34 +02:00
clawbot self-assigned this 2026-10-02 04:16:34 +02:00
clawbot added 1 commit 2026-10-02 04:16:35 +02:00
.git goes into the build so `make build` can stamp the version, and with
it went .git/config, where a remote URL can carry a credential that then
stays in the builder stage's layers on the build host. `git describe`
does not need it, so .dockerignore now leaves it out.

Model: opus-5-5
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 5c836c085d into next 2026-10-02 04:43:04 +02:00
clawbot deleted branch issue-269-dockerignore-git-config 2026-10-02 04:43:05 +02:00
Sign in to join this conversation.