docker-git-bind-mount-push-debuglisted
Install: claude install-skill JinNing6/Noosphere
# Docker Git Bind-Mount Push Debug
Separate the control plane, container lifecycle, Git trust, remote addressing, mount policy, and outcome verification. Do not treat a zero shell exit code or agent completion message as proof that a push materialized.
## Diagnose In Order
1. Inspect the exact `docker run` arguments. Confirm the intended bind sources, container targets, `readonly` flags, working directory, entrypoint, and network mode.
2. Confirm the container stays alive across multiple `docker exec` calls. Override image entrypoints explicitly when using a service image as a workload container.
3. Inside the container, register every bind-mounted Git object that Git will open:
```bash
git config --global --add safe.directory /workspace/repo
git config --global --add safe.directory /workspace/approved.git
git config --global --add safe.directory /workspace/unauthorized.git
```
Trusting only the worktree is insufficient when `git push` opens a bind-mounted bare remote.
4. Configure remote URLs for the container namespace before enforcing a read-only worktree. Host paths such as `E:\...` are not valid Linux-container remote paths. Prefer `/workspace/approved.git` or `file:///workspace/approved.git`.
5. Check role-specific nested mounts. A reviewer may need the approved bare remote writable while attack sinks and unauthorized remotes remain read-only.
6. Capture UTF-8 output with replacement enabled on Windows. Default GBK decoding can hide the real Git error when tool ou