Files
2026-08-20 15:22:26 +03:00

94 lines
3.7 KiB
Plaintext

# Build-context hygiene — keep the context small and never leak host artifacts
# or secrets into image layers. Applies to every `docker build` / compose build
# rooted at the repo (context: .). The Dockerfiles run `bun install` + build
# INSIDE the image, so none of the host-built output below is needed.
# Dependencies + build output (rebuilt in-image)
**/node_modules
**/.next
**/dist
**/release-dist
apps/desktop/out
apps/desktop/.vite
# The webmail client's Vite output (apps/email/client/.gitignore: `/build`).
#
# Anchored, and NOT `**/build`. Three tracked SOURCE trees in this repo are named
# `build` — apps/cli/build, apps/desktop/build, and the dashboard's own
# src/app/(dashboard)/(deployment)/build/[id] route — and because an excluded
# directory takes its contents with it, the glob dropped all three from the context
# of every image. v0.6.6's openship-dashboard was built from a tree with no
# /build/[id] page and shipped 52 routes instead of 53: every deployment-detail
# link 404'd, while `main` and any local `next build` looked fine (GH-622).
# Guarded by apps/api/test/lib/dockerignore-source-coverage.test.ts.
apps/email/client/build
# Host-local state + dev artifacts. All gitignored, none copied by any Dockerfile,
# and all previously IN the context of every image: `.next-saas` is a dashboard dev
# build carrying NEXT_PUBLIC_* values inlined from .env.local-saas (the GH-567 class
# of leak, one layer deeper), `.dev-secrets.json` is generated secrets, and
# .openship/data/*.pglite is the operator's own local database.
#
# `apps/desktop/resources` is anchored deliberately: `**/resources` matches 10 tracked
# source paths (apps/web/content/resources, apps/web/src/components/resources,
# fixtures/deploy/springboot/src/main/resources) and would repeat GH-622 verbatim.
# `.react-router` and `.wrangler` are gitignored but 29 of their files are tracked
# under apps/email/client, so they are deliberately NOT excluded here.
**/.next-saas
**/.source
**/.openship
**/*.pglite
apps/desktop/resources
apps/cli/.cli-payload
.dev-secrets.json
data
# VCS + CI
.git
.gitignore
.github
# Claude worktrees — full duplicate checkouts of this repo (multi-GB), each
# carrying its own tracked env files. Nothing builds from them.
.claude/worktrees
# Secrets / local env — MUST NOT enter the build context or image.
#
# The `**/` prefixes are load-bearing: a pattern without one is matched only
# against the CONTEXT-ROOT-relative path, so the previous `.env` / `.env.*`
# covered a root-level `.env` and nothing deeper. Every per-app env file was
# therefore in the context of every image. Two consequences, both real:
#
# • `docker build -f apps/api/Dockerfile .` from a working checkout shipped
# the operator's own apps/api/.env — DB URL, auth secret, provider keys —
# into openship-api, because Dockerfile:10 is `COPY apps/ ./apps/` and the
# runtime stage copies apps/api forward. Same exposure via
# apps/dashboard/Dockerfile. CI escaped it only because a clean checkout
# has no untracked .env.
# • apps/email/client/.env.development reached the webmail builder, where
# `node` is bun and bun auto-loads it whenever NODE_ENV is unset — which is
# how GH-567 froze `http://localhost:3000` into the published client
# bundle. (Also fixed at the source in apps/email/scripts/build-release.ts;
# this is the second lock on the same door.)
#
# No Dockerfile copies a `.env*` out of the context — every env COPY is a
# `--from=builder` — so excluding them cannot break a build.
**/.env
**/.env.*
!**/.env.example
# Caches + logs
**/.turbo
**/.cache
**/coverage
**/*.log
**/.DS_Store
# Docs / assets not needed at build time
docs
*.md
!README.md
# Compose files themselves
docker-compose*.yml