Chapter 6: Docker Images and Containers
6.6 Layer caching and .dockerignore (speed + safety)
Docker rebuilds from the first changed instruction downward. Put rarely changing lines first (FROM, dependency install) and often changing app copy later.
FROM python:3.12-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY app.py .
# COPY . . comes after deps so code edits do not redo pip every time
.dockerignore example
.git
.env
.env.*
*.pem
__pycache__
node_modules
README.md
badge-api-logs
Why. Smaller context = faster build. Ignoring .env reduces the chance a secret lands in an image layer.
Ravindra Bagale's Tip
Image madhe secret gela tar fakt container delete karun pure nahi — layer history madhe asu shakte. Rotate secret, rebuild clean, .dockerignore tight. Bilkul visru naka!