pub struct Pack {
pub secret_globs: Vec<String>,
pub cache_dirs: Vec<String>,
pub keep: Vec<String>,
pub no_link_report: Vec<String>,
}Expand description
Classification overrides for lds pack.
Every list here is added to the built-in defaults rather than replacing
them, so a project that declares one project-specific secret name does not
silently lose the protection of the built-in list. keep is the one escape
hatch that subtracts: it names files the built-ins would classify as secret
or cache but that this operator wants carried anyway.
Every list here scopes its globs the way .gitignore does: one with no /
(*.vault, my-app-keys.json) matches the file name at any depth, one
with a / (docs/samples/*.pem, frontend/dist) is anchored to that
path relative to the project root.
Reaching the whole tree is the right default for naming a kind of file, and
the hazard when naming one particular file: keep = ["*.pem"] written to
carry one sample key carries every private key in the project. Anchor such a
rule to a path and it stays where it was meant to apply.
Fields§
§secret_globs: Vec<String>Extra globs to treat as secrets (never packed, only reported).
cache_dirs: Vec<String>Extra directories to treat as regenerable caches (never packed).
keep: Vec<String>Globs that must be packed even if a built-in rule excludes them.
The only subtractive list, and so the only way a file the secret rules
named ends up in the archive. Anything it rescues is recorded in the
manifest’s kept_over_secret.
no_link_report: Vec<String>Path globs whose symlinks are packed but left out of the link report.
A symlink is a problem by default: it breaks when the project is carried
somewhere else, so every one is reported for the operator to deal with.
The exception is a directory that is meant to be links — a shared
dotfile tree such as .zsh/, deployed the same way on every machine the
operator uses. Those are already known, so reporting them is noise that
hides the links that do need attention.
Scoped like the lists above, and in practice always with a / — what
makes links expected is where they sit.
No built-in default: only the operator knows which of their directories are link-by-design. Left unset, every symlink is reported.
Suppression affects the report alone — the links are packed either way, and every rule that suppressed something is named in the manifest, so a silent report can always be told apart from an empty one.