feat: keep secrets out of the app image (E00-S02-T08)

- .dockerignore: exclude env + credential files (.npmrc, .netrc, .aws, .ssh,
  secrets/, *.pem, *.key, *.p12, *.pfx, *.jks, id_rsa, id_ed25519, ...) from
  the build context so a local secret file cannot be embedded in the image
- Dockerfile: document the T08 guarantee (no secret ARG/ENV, fixed non-secret
  COPY paths, runtime credentials via Compose environment)
- compose.yaml: T08 in scope; runtime credentials stay in service environment,
  never in the image
This commit is contained in:
implementer
2026-08-29 01:28:26 +00:00
parent 25d7dc836b
commit 0938da8a73
3 changed files with 36 additions and 3 deletions
+18
View File
@@ -14,5 +14,23 @@ coverage
.env
.env.*
# Secrets & credentials (E00-S02-T08) — never part of the build context, so a
# secret-bearing file cannot be embedded in the image even if a developer has
# one locally. Keep this list in sync with tests/secrets-not-embedded.test.mjs.
.npmrc
.netrc
.credentials
.aws
.ssh
secrets
secrets/
*.pem
*.key
*.p12
*.pfx
*.jks
id_rsa
id_ed25519
# Logs
*.log