feat: keep secrets out of the app image (E00-S02-T08)
- .dockerignore: exclude env + credential files (.npmrc, .netrc, .aws, .ssh, secrets/, *.pem, *.key, *.p12, *.pfx, *.jks, id_rsa, id_ed25519, ...) from the build context so a local secret file cannot be embedded in the image - Dockerfile: document the T08 guarantee (no secret ARG/ENV, fixed non-secret COPY paths, runtime credentials via Compose environment) - compose.yaml: T08 in scope; runtime credentials stay in service environment, never in the image
This commit is contained in:
@@ -14,5 +14,23 @@ coverage
|
||||
.env
|
||||
.env.*
|
||||
|
||||
# Secrets & credentials (E00-S02-T08) — never part of the build context, so a
|
||||
# secret-bearing file cannot be embedded in the image even if a developer has
|
||||
# one locally. Keep this list in sync with tests/secrets-not-embedded.test.mjs.
|
||||
.npmrc
|
||||
.netrc
|
||||
.credentials
|
||||
.aws
|
||||
.ssh
|
||||
secrets
|
||||
secrets/
|
||||
*.pem
|
||||
*.key
|
||||
*.p12
|
||||
*.pfx
|
||||
*.jks
|
||||
id_rsa
|
||||
id_ed25519
|
||||
|
||||
# Logs
|
||||
*.log
|
||||
|
||||
Reference in New Issue
Block a user