Skip to content

Docker build context can include ignored local secrets and generated artifacts #1917

Description

@david-rocca

Evidence:

  • .dockerignore:1-2 only excludes node_modules and npm-debug.log.
  • docker/Dockerfile:23 and docker/Dockerfile.dev:26 both use ADD . /home/node/app.
  • Current ignored local files include .env, .agents/, .crush/, .nyc_output/, coverage/, docker/.docker-env, test-http/docker/.docker-env, Python cache directories, .DS_Store, and src/scripts/export.xlsx.
  • Current local artifact sizes include coverage at about 119 MB and .nyc_output at about 1.9 MB.

Impact:

  • Local Docker builds can copy ignored local secrets and generated artifacts into the build context and possibly the image.
  • Build context size is larger than necessary.
  • Production and dev images depend on the state of a developer workstation, not just tracked source.

Recommendation:

  • Expand .dockerignore to mirror relevant .gitignore entries: .env, .env.*, .git, .agents, .crush, .vscode, coverage, .nyc_output, .DS_Store, **/__pycache__, **/.pytest_cache, **/*.pyc, test-http/src/testOutput.txt, docker/.docker-env, test-http/docker/.docker-env, src/scripts/export.xlsx, user-secret.txt, and similar local-only outputs.
  • Prefer explicit COPY steps in production Dockerfile: package manifests first, install with npm ci --omit=dev, then copy only runtime directories/files (src, schemas, api-docs, config, docker/entrypoint.sh, etc.).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions