commit 34a8e5ed6ab309510dc0f48c5ef2d41b6730232a
parent 86733c372d3b8c776c9e3024222fe59ead66cfe6
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Mon, 28 Sep 2026 13:41:57 -0400
docs: PUBLISH.md says which builder reads Dockerfile.build.dockerignore and what the fallback costs (review N2)
BuildKit reads the per-Dockerfile ignore file; a builder that reads only the
shared .dockerignore sends several GB from a working checkout (podman is
unverified here). Still safe: out/ comes from the site's composed data and
only the tracked .svg assets are copied in. The doctor sentence gets its own
paragraph break.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Diffstat:
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/PUBLISH.md b/PUBLISH.md
@@ -432,9 +432,16 @@ refused.
source (common/, export/) and its deps; a code change rebuilds it, but layer caching
keeps that cheap (deps re-install only when the lockfile moves). Its build context is
the allow-list in `Dockerfile.build.dockerignore`, about 7 MB from any checkout. It
-never includes the corpus, generated `export/public` data or `.export-builds/`.
-`archilyzer doctor` says whether the image is there and older than its Dockerfile. The editor mounts the host's `docker/build-site.sh` over the
-baked one, so an image older than the checkout still runs today's script.
+never includes the corpus, generated `export/public` data or `.export-builds/`. That
+file is read by BuildKit (Docker's default builder). A builder that reads only the
+shared `.dockerignore` sends several GB from a working checkout, and podman is
+unverified here. That fallback is slower but still safe: each site's `out/` is built
+from its own composed data, and only the tracked `.svg` assets are copied in from the
+image. `archilyzer doctor` says whether the image is there and older than its
+Dockerfile.
+
+The editor mounts the host's `docker/build-site.sh` over the baked one, so an image
+older than the checkout still runs today's script.
---