From f573dddb14cf4a583e8b412c926ae38477637fce Mon Sep 17 00:00:00 2001 From: Marc Billow Date: Sat, 4 Jul 2026 16:15:44 -0500 Subject: [PATCH] fix: prevent .env from being baked into mqtt_demo image; fix dangling requirements-bootstrap.txt path --- .dockerignore | 15 +++++++++++++++ requirements-bootstrap.txt | 2 +- 2 files changed, 16 insertions(+), 1 deletion(-) create mode 100644 .dockerignore diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..fffbd75 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,15 @@ +# Build context is the repo root (see mqtt_demo/docker-compose.yml's +# `context: ..`). The Dockerfile COPYs whole directories (protocol/, +# ocf/, mqtt_demo/), so anything under them that shouldn't land in the +# image has to be excluded here explicitly. + +# Secrets — never bake these into the image. Mounted at runtime via +# the /config volume instead. +**/.env +certs/ + +# Local dev cruft. +**/__pycache__/ +**/*.pyc +.git/ +.venv/ diff --git a/requirements-bootstrap.txt b/requirements-bootstrap.txt index 2360d27..a749cc8 100644 --- a/requirements-bootstrap.txt +++ b/requirements-bootstrap.txt @@ -1,4 +1,4 @@ # Setup-only deps for setup_cert.py: shells out to `openssl` for SHA-1 # signing (independent of python-cryptography's policy) and uses # pyOpenSSL for the optional --test DTLS handshake. --r requirements.txt +-r mqtt_demo/requirements.txt