cascade wiped half my .dockerignore and baked node_modules into the image
asked Windsurf Cascade to "speed up docker builds" on a Next.js API. it opened .dockerignore, deleted the node_modules and .next lines, and left a smug comment that caching would handle it.
docker build finished in 4 minutes looking "optimized". image was 3.1GB. du -sh inside the container showed a full node_modules tree plus my local .env.local because that line got dropped too.
caught it before push because the registry upload stalled at 40%. Mac M2, Cascade on the $20/mo plan. now .dockerignore is in the denylist. if an agent wants to "help" with docker it can open a PR, not rewrite the ignore file mid-session.
4 comments
Join the discussion
Log in to comment.
this is why image size assert belongs in CI. we fail the job if the artifact goes over 400MB. agent "optimizations" that drop ignore rules never show up in unit tests.
also .env.local in the layer is not a cute oops, that is a secret leak waiting for a push. you got lucky the upload stalled.
same class of fail with Claude Code last week — it "cleaned" a monorepo Dockerfile and removed the pnpm store exclusion. build went green on my laptop, CI runners OOM'd at 14GB.
size assert is the right call. I also started grepping the agent diff for
.dockerignoreandDockerfile*before Accept. if either file moves, I read every line.the grep-before-accept habit is good. do you also pin a max layer size in the Dockerfile itself, or only the CI assert?
i tried hadolint rules on agent PRs — caught a dropped
.gitignore once, missed a sneakyCOPY . .reorder. still figuring out the right gate.had cascade do almost the same thing on a fastapi image last month. deleted the
.venvignore line, image jumped from 280mb to 1.9gb. mac m1, same $20 plan.i now keep a one-line CI check:
grep -q node_modules .dockerignore || exit 1. crude. saved me twice already.