docker: stop shipping the host target dir into the build

There was no .dockerignore, so `COPY . .` carried target/ -- three
gigabytes of artifacts built by a different toolchain than the builder
stage's -- plus cache/ and .git into every build. Mirror .gitignore's
allowlist and keep the context to what the build actually reads.

The final image is unchanged: the runtime stage only copies the binary,
public/ and config/.

Co-Authored-By: Claude Opus 5 <[email protected]>
This commit is contained in:
2026-10-09 23:03:02 -04:00
co-authored by Claude Opus 5
parent 95129b4e76
commit 83bcae01b7
2 changed files with 20 additions and 0 deletions
+19
View File
@@ -0,0 +1,19 @@
# Mirrors .gitignore: ignore everything, then allow what the build needs.
# Without this the context carries target/ (gigabytes of host-built
# artifacts, compiled against the wrong toolchain) and cache/ into COPY . .
*
!Cargo.lock
!Cargo.toml
# Source
!src/
!src/**
# Static assets
!public/
!public/**
# Configuration template
!config/
!config/teapot.example.toml
+1
View File
@@ -2,6 +2,7 @@
*
# Track project files
!.dockerignore
!.editorconfig
!.envrc
!.gitignore