# The build context of Dockerfile.build ONLY. BuildKit reads .dockerignore # beside the Dockerfile in place of the shared .dockerignore, which the root Dockerfile # and Dockerfile.test keep using unchanged. # # An allow-list: everything is out, then only what one site's export build reads # (docker/build-site.sh → `archilyzer build site --nodata` → compose + next # build) is let back in. The corpus, the index, the staging and the settings are # MOUNTED at run time (common/publish/build.ts, runDockerBuildOne) and never baked. # # What this keeps out, measured on the primary checkout: export/public's generated # data (subs/ alone is 1.8 GB — and a site's `next build` would publish whatever sat # there), .diarize/ (1.3 GB), umtool's data, editor/, homepage/, mcp/, plans/. * !package.json !pnpm-lock.yaml !pnpm-workspace.yaml !tsconfig.base.json !common !export !docker/build-site.sh # Inside common/ and export/: nothing generated, cached, local or secret. No # tracked file in either starts with a dot. common/.* export/.* **/node_modules **/.next **/out **/*.tsbuildinfo **/next-env.d.ts **/.env* **/*.pem export/test-* export/playwright-report export/blob-report # export/public holds generated data beside the repo's tracked assets (all .svg). # Only the assets are baked: build-site.sh copies them into the site's composed # public/, which is what `next build` publishes. export/public/* !export/public/*.svg