diff --git a/api/.dockerignore b/api/.dockerignore new file mode 100644 index 0000000..c0d77c9 --- /dev/null +++ b/api/.dockerignore @@ -0,0 +1,13 @@ +# Allowlist: the Dockerfile only copies these three things, so nothing +# else (training code, datasets, saved models, caches) is sent to the daemon. +* +!requirements.txt +!src/production +!build_models + +# Re-exclude junk inside the allowed paths +**/__pycache__ +**/*.pyc +**/*.bat +**/.env +**/*.env diff --git a/caddy/.dockerignore b/caddy/.dockerignore new file mode 100644 index 0000000..b696118 --- /dev/null +++ b/caddy/.dockerignore @@ -0,0 +1,5 @@ +# Allowlist: only the Caddyfile is copied into the image. +# data/ and config/ hold TLS certificates and private keys at runtime +# (mounted as volumes) and must never end up in the build context. +* +!Caddyfile