mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
docker/README.md and docs/docker-compose.md now say that the container starts as root, corrects a daemon-created bind source and drops to PUID:PGID with setpriv, which capabilities that needs, and that a compose file written elsewhere must carry them. The README's PowerShell example runs Compose from inside docker/ so the override file is discovered, instead of the `-f docker/docker-compose.yaml` form its own Local customisation section warns silently drops it, and the reverse-proxy section no longer asks for an override file now that docker-compose.yaml forwards CODEMAN_ALLOWED_HOSTS itself. .dockerignore excludes docker-compose.override.* everywhere: it is the documented home for host-specific settings and rode `COPY . .` into the image, the same shape as the docker/.env exclusion above it (verified with a scratch build context: the override files and docker/.env are absent, .env.example and the compose file present). CLAUDE.md's Compose paragraph carries the corrected cap list, the writability probe, and the two traps behind it (KILL is for tini, the CLI prefix is appended to PATH). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
22 lines
596 B
Plaintext
22 lines
596 B
Plaintext
.git
|
|
.agents
|
|
.claude
|
|
.codex
|
|
# `**/` matters: a .dockerignore pattern is matched against the WHOLE
|
|
# context-relative path, so a bare `.env` excludes ONLY the root file and
|
|
# `COPY . .` would bake docker/.env -- CODEMAN_PASSWORD and any provider API
|
|
# keys -- into the published image at /opt/codeman/docker/.env (verified).
|
|
**/.env
|
|
**/.env.*
|
|
!**/.env.example
|
|
# Same shape: docker/docker-compose.override.yml is the documented home for
|
|
# host-specific settings, so it must not ride COPY . . into the image either.
|
|
**/docker-compose.override.*
|
|
node_modules
|
|
dist
|
|
coverage
|
|
out
|
|
test-results
|
|
tmp
|
|
*.log
|