# Keep the build context small and keep secrets out of it. # # Everything the image needs is go-api/ and seed/fixtures/seed.json. Anything # listed here is either a secret, a build output, or bytes that would be sent # to the daemon and then ignored — each of which slows every build. # ── Secrets. Never in an image, never in a layer. ─────────────────────────── .env .env.* !.env.example *.pem *.key *.crt # ── Version control and CI ────────────────────────────────────────────────── .git .gitignore .github # ── Build output ──────────────────────────────────────────────────────────── go-api/bin/ *.test *.out coverage.* # ── Things the runtime image does not need ────────────────────────────────── # NOTE: migrations/ is deliberately NOT ignored. They are baked into the image # so a Kubernetes initContainer can apply them using the same image and tag as # the API — see Dockerfile.api. docker-compose uses a bind mount instead, which # works either way. docs/ scripts/ infrastructure/ Makefile README.md *.md # The snapshot taken before the krowdb public schema was dropped. Large, and # has no business in a container. krowdb_public_snapshot_*.sql # ── Editor / OS ───────────────────────────────────────────────────────────── .DS_Store .idea/ .vscode/