Skip to content

chore: clean up repository configuration, ignore rules and docs - #106

Merged
AntoineJT merged 8 commits into
masterfrom
chore/cleanup-workspace
Sep 16, 2026
Merged

AntoineJT merged 8 commits into
masterfrom
chore/cleanup-workspace

Conversation

@AntoineJT

Copy link
Copy Markdown
Member

🇬🇧 English

🎯 Summary

Housekeeping over the repository configuration: ignore rules, CODEOWNERS, environment-variable documentation and the README. No runtime change — the only source edit is the ressources/ → resources/ rename and the paths that follow it.

🤔 Motivation

Three problems the diff alone doesn't reveal.

.env.prod was neither gitignored nor docker-ignored. .gitignore only matched *.env, which does not match .env.prod, and the Dockerfile does COPY ./ /app. Creating a .env.prod from the example and building locally would have committed the token, or shipped it in an image published on ghcr.io.

I audited the three most recent published images (1.5.1, 1.5.0, 1.4.19): /app/.env.prod is present in all three but empty, and a scan of /app finds no Discord token pattern and no non-empty secret assignment. No secret has ever leaked — CI builds from a clean checkout, so the gap was reachable only from a local build. This is preventive hardening, not an incident response.

Two CODEOWNERS rules matched nothing. resources/* and alembic/* do not cross directory boundaries, so every asset under resources/font/, resources/images/ and resources/rngdle/ was unowned while appearing to be covered.

.env.example was unsafe to copy. It documented 2 of the 6 variables read by config.py, and DEBUG_GUILD_ID= was empty — so copying it verbatim, exactly as the README instructed, makes config.py raise ValueError: DEBUG_GUILD_ID must be an integer representing a guild ID. at import, for a variable documented as optional.

📦 What's included

  • 🔧 .gitignore and .dockerignore now cover the same ground; the published image no longer carries environment files, repository metadata or local bytecode.
  • 🔧 CODEOWNERS regrouped by domain, the two dead patterns fixed, and ownership extended to the RNGdle module and the production entrypoint.
  • 📝 .env.example becomes the single reference for the six variables; the README points to it instead of duplicating it — the duplicate had already drifted.
  • 🔧 Production files renamed so they read as variants of their dev counterparts rather than separate things.
  • 📝 README brought back in line with reality: organisation, required Python version, Compose CLI, collaborators.
  • 🔧 renovate.json removed. The app itself was offboarded from the repository outside this PR and its open PRs closed — deleting the file alone would have changed nothing. Dependabot already covers the same ecosystems.
  • ✅ The image builds with the new .dockerignore, and a scan of the exported filesystem confirms the exclusions take effect while every file the runtime needs is still present.

🧭 Notes

  • ⚠️ CODEOWNERS does not merge matching rules, the last one wins. The catch-all @gamingdy is therefore intentionally dropped on paths that have a more specific owner (Dockerfile, compose.prod.yaml, PRIVACY.md).
  • ⚠️ Existing checkouts keep an untracked ressources/ directory holding the gitignored RNGdle JSON tables. They are regenerated under resources/ and the old directory can be deleted by hand. Docker deployments are unaffected: the folder ships inside the image, not on a volume.

🇫🇷 Français

🎯 Résumé

Ménage sur la configuration du dépôt : règles d'ignore, CODEOWNERS, documentation des variables d'environnement et README. Aucun changement à l'exécution — la seule modification de source est le renommage ressources/ → resources/ et les chemins qui en découlent.

🤔 Motivation

Trois problèmes que le diff seul ne révèle pas.

.env.prod n'était ignoré ni par git ni par Docker. .gitignore ne contenait que *.env, qui ne correspond pas à .env.prod, et le Dockerfile fait COPY ./ /app. Créer un .env.prod à partir de l'exemple puis builder en local aurait commité le token, ou l'aurait embarqué dans une image publiée sur ghcr.io.

J'ai audité les trois dernières images publiées (1.5.1, 1.5.0, 1.4.19) : /app/.env.prod est présent dans les trois mais vide, et un scan de /app ne trouve aucun motif de token Discord ni aucune affectation de secret non vide. Aucun secret n'a jamais fuité — la CI build depuis un checkout vierge, le trou n'était donc atteignable que depuis un build local. Il s'agit d'un durcissement préventif, pas d'une réponse à incident.

Deux règles CODEOWNERS ne correspondaient à rien. resources/* et alembic/* ne traversent pas les frontières de répertoire : chaque asset sous resources/font/, resources/images/ et resources/rngdle/ était sans propriétaire tout en paraissant couvert.

.env.example était dangereux à copier. Il documentait 2 des 6 variables lues par config.py, et DEBUG_GUILD_ID= était vide — le copier tel quel, exactement comme le README l'indiquait, fait lever à config.py un ValueError: DEBUG_GUILD_ID must be an integer representing a guild ID. à l'import, pour une variable documentée comme optionnelle.

📦 Contenu

  • 🔧 .gitignore et .dockerignore couvrent désormais le même périmètre ; l'image publiée n'embarque plus de fichiers d'environnement, de métadonnées de dépôt ni de bytecode local.
  • 🔧 CODEOWNERS regroupé par domaine, les deux motifs morts corrigés, et la propriété étendue au module RNGdle et au point d'entrée de production.
  • 📝 .env.example devient la référence unique des six variables ; le README pointe dessus au lieu de la dupliquer — le doublon en avait déjà divergé.
  • 🔧 Fichiers de production renommés pour se lire comme des variantes de leurs équivalents de dev plutôt que comme des objets distincts.
  • 📝 README remis en accord avec la réalité : organisation, version de Python requise, CLI Compose, collaborateurs.
  • 🔧 renovate.json supprimé. L'app elle-même a été retirée du dépôt hors de cette MR et ses PR ouvertes fermées — supprimer le fichier seul n'aurait rien changé. Dependabot couvre déjà les mêmes écosystèmes.
  • ✅ L'image se construit avec le nouveau .dockerignore, et un scan du système de fichiers exporté confirme que les exclusions prennent effet tandis que tout ce dont l'exécution a besoin est toujours présent.

🧭 À noter

  • ⚠️ CODEOWNERS ne fusionne pas les règles qui correspondent, la dernière l'emporte. Le catch-all @gamingdy est donc volontairement abandonné sur les chemins ayant un propriétaire plus spécifique (Dockerfile, compose.prod.yaml, PRIVACY.md).
  • ⚠️ Les copies de travail existantes conservent un répertoire ressources/ non suivi contenant les tables JSON RNGdle gitignorées. Elles sont régénérées sous resources/ et l'ancien répertoire peut être supprimé à la main. Les déploiements Docker ne sont pas concernés : le dossier voyage dans l'image, pas sur un volume.

Existing checkouts keep an untracked "ressources/" directory holding the
gitignored RNGdle JSON tables; they are regenerated under "resources/"
and the old directory can be deleted by hand. Docker deployments are
unaffected: the folder ships inside the image, not on a volume.
@Lindwen wants to use dependabot for its GitHub integration.
We don't want to use both renovatebot & dependabot so
renovate must go.
Group rules by domain instead of by file type, and add owners for the
RNGdle module, the privacy policy and the design assets.

CODEOWNERS does not merge matching rules, the last one wins: the
catch-all @gamingdy is therefore intentionally dropped on paths that
have a more specific owner (Dockerfile, compose.prod.yaml, PRIVACY.md).
The organisation was renamed to GravenDev, the project now requires
Python 3.13, the docker-compose V1 CLI is gone, and @AntoineJT was
missing from the collaborators.
@AntoineJT
AntoineJT merged commit e89cca8 into master Sep 16, 2026
5 checks passed
@AntoineJT
AntoineJT deleted the chore/cleanup-workspace branch September 16, 2026 23:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant