buddy fix
This commit is contained in:
@@ -1,12 +1,16 @@
|
||||
# Nothing in here reaches the image.
|
||||
# What does not reach the image.
|
||||
#
|
||||
# `.env*` most of all: the Dockerfile does `COPY . .`, and the production
|
||||
# credentials in `.env.production` were being baked into every image built
|
||||
# from this folder. The running container gets its environment from the
|
||||
# platform (Dokploy / Kubernetes), never from a file.
|
||||
|
||||
|
||||
|
||||
# `.env.production` IS copied in — see the Dockerfile's runtime stage. The
|
||||
# container reads its own configuration from that file, so the deployment does
|
||||
# not depend on every variable having been typed into a hosting platform's
|
||||
# settings screen. Anything the platform DOES set still wins: godotenv never
|
||||
# overwrites a variable that is already present in the environment.
|
||||
#
|
||||
# Every other `.env.*` stays out. `.env.local` and `.env.secrets` are one
|
||||
# developer's machine, and `.env.secrets` in particular is the file that holds
|
||||
# a key — it must never be inside an image.
|
||||
.env*
|
||||
!.env.production
|
||||
|
||||
.git
|
||||
.claude
|
||||
|
||||
Reference in New Issue
Block a user