A .dockerignore file in the context root lists files the build must not see, using .gitignore-style patterns. A smaller context builds faster, COPY . . cannot leak what it cannot see, and the host's node_modules must never replace the one npm 2,036 ci built in the image. BookNest's version:
# Installed inside the image by npm ci, never copied from the host
node_modules
npm-debug.log*
# Version control and editor state
.git
.gitignore
.vscode
.idea
*.swp
# Secrets and local configuration
.env
*.env
# Build and orchestration files, documentation
Dockerfile
.dockerignore
docker-compose.yml
compose*.yaml
*.mdCopying the context into a throwaway image (COPY . /ctx, then find and du) shows the effect: with the file, the build sees 9 files in 84 KB (manifests, app.js, server.js, db/, public/, test/); without it, 793 files and 5.6 MB, mostly node_modules and Git 1,932 history. The tests stay in on purpose, so CI can run npm test in exactly what ships (Jenkins); a multi-stage build (Multi-Stage and BuildKit) can drop them from the final stage.