# Docker context guard for the worker image build # (`docker build -f worker/Dockerfile -t strategy-lab-worker:local .` from the # project root). The Dockerfile only COPYs requirements-worker.txt and worker/, # so everything else stays out of the build context. Rationale: a full-context # build previously pushed ~2.5 GB into the builder, including private QA # evidence artifacts/, server sources, docs and caches that must never enter # an image layer derived context. # # Whitelist semantics (moby patternmatcher, last matching pattern wins): # `**/*` excludes every path (including dot entries; `**` also matches zero # directories), and the negations re-include exactly what worker/Dockerfile # COPYs: requirements-worker.txt and the worker/ tree. **/* !requirements-worker.txt !worker !worker/** # never ship caches inside the worker tree even if created locally worker/__pycache__ worker/**/__pycache__ worker/*.pyc worker/**/*.pyc worker/.pytest_cache worker/**/.pytest_cache worker/.venv worker/**/.venv