mirror of
https://github.com/oblien/openship.git
synced 2026-10-01 23:34:46 +08:00
94 lines
3.7 KiB
Plaintext
94 lines
3.7 KiB
Plaintext
# Build-context hygiene — keep the context small and never leak host artifacts
|
|
# or secrets into image layers. Applies to every `docker build` / compose build
|
|
# rooted at the repo (context: .). The Dockerfiles run `bun install` + build
|
|
# INSIDE the image, so none of the host-built output below is needed.
|
|
|
|
# Dependencies + build output (rebuilt in-image)
|
|
**/node_modules
|
|
**/.next
|
|
**/dist
|
|
**/release-dist
|
|
apps/desktop/out
|
|
apps/desktop/.vite
|
|
|
|
# The webmail client's Vite output (apps/email/client/.gitignore: `/build`).
|
|
#
|
|
# Anchored, and NOT `**/build`. Three tracked SOURCE trees in this repo are named
|
|
# `build` — apps/cli/build, apps/desktop/build, and the dashboard's own
|
|
# src/app/(dashboard)/(deployment)/build/[id] route — and because an excluded
|
|
# directory takes its contents with it, the glob dropped all three from the context
|
|
# of every image. v0.6.6's openship-dashboard was built from a tree with no
|
|
# /build/[id] page and shipped 52 routes instead of 53: every deployment-detail
|
|
# link 404'd, while `main` and any local `next build` looked fine (GH-622).
|
|
# Guarded by apps/api/test/lib/dockerignore-source-coverage.test.ts.
|
|
apps/email/client/build
|
|
|
|
# Host-local state + dev artifacts. All gitignored, none copied by any Dockerfile,
|
|
# and all previously IN the context of every image: `.next-saas` is a dashboard dev
|
|
# build carrying NEXT_PUBLIC_* values inlined from .env.local-saas (the GH-567 class
|
|
# of leak, one layer deeper), `.dev-secrets.json` is generated secrets, and
|
|
# .openship/data/*.pglite is the operator's own local database.
|
|
#
|
|
# `apps/desktop/resources` is anchored deliberately: `**/resources` matches 10 tracked
|
|
# source paths (apps/web/content/resources, apps/web/src/components/resources,
|
|
# fixtures/deploy/springboot/src/main/resources) and would repeat GH-622 verbatim.
|
|
# `.react-router` and `.wrangler` are gitignored but 29 of their files are tracked
|
|
# under apps/email/client, so they are deliberately NOT excluded here.
|
|
**/.next-saas
|
|
**/.source
|
|
**/.openship
|
|
**/*.pglite
|
|
apps/desktop/resources
|
|
apps/cli/.cli-payload
|
|
.dev-secrets.json
|
|
data
|
|
|
|
# VCS + CI
|
|
.git
|
|
.gitignore
|
|
.github
|
|
|
|
# Claude worktrees — full duplicate checkouts of this repo (multi-GB), each
|
|
# carrying its own tracked env files. Nothing builds from them.
|
|
.claude/worktrees
|
|
|
|
# Secrets / local env — MUST NOT enter the build context or image.
|
|
#
|
|
# The `**/` prefixes are load-bearing: a pattern without one is matched only
|
|
# against the CONTEXT-ROOT-relative path, so the previous `.env` / `.env.*`
|
|
# covered a root-level `.env` and nothing deeper. Every per-app env file was
|
|
# therefore in the context of every image. Two consequences, both real:
|
|
#
|
|
# • `docker build -f apps/api/Dockerfile .` from a working checkout shipped
|
|
# the operator's own apps/api/.env — DB URL, auth secret, provider keys —
|
|
# into openship-api, because Dockerfile:10 is `COPY apps/ ./apps/` and the
|
|
# runtime stage copies apps/api forward. Same exposure via
|
|
# apps/dashboard/Dockerfile. CI escaped it only because a clean checkout
|
|
# has no untracked .env.
|
|
# • apps/email/client/.env.development reached the webmail builder, where
|
|
# `node` is bun and bun auto-loads it whenever NODE_ENV is unset — which is
|
|
# how GH-567 froze `http://localhost:3000` into the published client
|
|
# bundle. (Also fixed at the source in apps/email/scripts/build-release.ts;
|
|
# this is the second lock on the same door.)
|
|
#
|
|
# No Dockerfile copies a `.env*` out of the context — every env COPY is a
|
|
# `--from=builder` — so excluding them cannot break a build.
|
|
**/.env
|
|
**/.env.*
|
|
!**/.env.example
|
|
|
|
# Caches + logs
|
|
**/.turbo
|
|
**/.cache
|
|
**/coverage
|
|
**/*.log
|
|
**/.DS_Store
|
|
|
|
# Docs / assets not needed at build time
|
|
docs
|
|
*.md
|
|
!README.md
|
|
|
|
# Compose files themselves
|
|
docker-compose*.yml
|