Files
J621/.dockerignore
JakeBreath a17dd5a4ef Keep secrets and runtime data out of the Docker images
The build context is the repository root and there was no .dockerignore, so
'COPY backend/ ./' swept backend/venv (327 MB), backend/media (the actual
library, 224 MB), backend/logs, backend/staticfiles and backend/.env
(SECRET_KEY plus the database password) into the backend image: 1.43 GB per
architecture, including secrets headed for the registry. The frontend build
stage also copied the host's node_modules over the fresh install.

- Root .dockerignore excludes .git, virtualenvs, __pycache__, db.sqlite3,
  logs/staticfiles, .env files, media/, node_modules, dist and the deploy
  runtime state (data/, tailscale-state/).
- The backend Dockerfile now asserts the context is clean (.env, venv,
  media/library, db.sqlite3 all absent) before collectstatic, so a missing
  ignore file fails the build instead of leaking.
- Rebuilt: backend 1.43 GB -> 876 MB ('COPY backend/' is now 268 kB),
  frontend stays at 65 MB. Verified by booting the compose stack with the
  new image: migrations applied, /health ok, no .env or venv inside, and
  /app/media is the mounted (empty) volume; the scheduler runs too.
- Removed the stale local images that still contained the library and the
  dev .env.
2026-09-18 16:04:55 -05:00

36 lines
829 B
Plaintext

# Build context is the repository root (see deploy/J621-Backend and
# deploy/J621-Frontend). Keep the context small and, more importantly, keep
# secrets and runtime data out of the images.
# Version control / tooling
.git
.gitignore
.dockerignore
# Python: the dev virtualenv, caches, and anything generated at runtime
backend/venv/
**/__pycache__/
**/*.py[cod]
backend/db.sqlite3
backend/logs/
backend/staticfiles/
# Secrets and media: the .env holds SECRET_KEY and DB passwords, media/ is
# the actual library. The deploy composes mount these at runtime instead.
backend/.env
backend/.env.*
backend/media/
# Frontend build artefacts (npm ci installs fresh from the lockfile)
frontend/node_modules/
frontend/dist/
# Deploy runtime state and env
deploy/.env
deploy/.env.*
deploy/data/
deploy/tailscale-state/
# Misc
*.log