- .dockerignore: exclude env + credential files (.npmrc, .netrc, .aws, .ssh, secrets/, *.pem, *.key, *.p12, *.pfx, *.jks, id_rsa, id_ed25519, ...) from the build context so a local secret file cannot be embedded in the image - Dockerfile: document the T08 guarantee (no secret ARG/ENV, fixed non-secret COPY paths, runtime credentials via Compose environment) - compose.yaml: T08 in scope; runtime credentials stay in service environment, never in the image
37 lines
531 B
Plaintext
37 lines
531 B
Plaintext
# VCS
|
|
.git
|
|
.gitignore
|
|
|
|
# Dependencies
|
|
node_modules
|
|
.pnpm-store
|
|
|
|
# Build output
|
|
dist
|
|
coverage
|
|
|
|
# Local environment files (a committed .env.example lands in E00-S04)
|
|
.env
|
|
.env.*
|
|
|
|
# Secrets & credentials (E00-S02-T08) — never part of the build context, so a
|
|
# secret-bearing file cannot be embedded in the image even if a developer has
|
|
# one locally. Keep this list in sync with tests/secrets-not-embedded.test.mjs.
|
|
.npmrc
|
|
.netrc
|
|
.credentials
|
|
.aws
|
|
.ssh
|
|
secrets
|
|
secrets/
|
|
*.pem
|
|
*.key
|
|
*.p12
|
|
*.pfx
|
|
*.jks
|
|
id_rsa
|
|
id_ed25519
|
|
|
|
# Logs
|
|
*.log
|