This commit is contained in:
2026-09-25 12:39:38 +05:30
parent d562691f42
commit 7fdcc92528
2 changed files with 26 additions and 23 deletions

View File

@@ -1,16 +1,15 @@
# What does not reach the image.
# Nothing in here reaches the image.
#
# `.env.production` IS copied in — see the Dockerfile's runtime stage. The
# container reads its own configuration from that file, so the deployment does
# not depend on every variable having been typed into a hosting platform's
# settings screen. Anything the platform DOES set still wins: godotenv never
# overwrites a variable that is already present in the environment.
# `.env*` most of all: the Dockerfile does `COPY . .`, and the production
# credentials in `.env.production` were being baked into every image built
# from this folder. The running container gets its environment from the
# platform (Dokploy / Kubernetes), never from a file.
#
# Every other `.env.*` stays out. `.env.local` and `.env.secrets` are one
# developer's machine, and `.env.secrets` in particular is the file that holds
# a key — it must never be inside an image.
# An exception for `.env.production` was added on 2026-09-25 so the container
# could read its own configuration, and the deploy came back 502 on every
# endpoint. Reverted. The committed file is a stale snapshot; letting it fill
# whatever the platform leaves unset is not a safe default.
.env*
!.env.production
.git
.claude