buddy fix

This commit is contained in:
2026-09-25 11:55:50 +05:30
parent 276e12beb9
commit d562691f42
5 changed files with 134 additions and 12 deletions

View File

@@ -1,12 +1,16 @@
# Nothing in here reaches the image.
# What does not reach the image.
#
# `.env*` most of all: the Dockerfile does `COPY . .`, and the production
# credentials in `.env.production` were being baked into every image built
# from this folder. The running container gets its environment from the
# platform (Dokploy / Kubernetes), never from a file.
# `.env.production` IS copied in — see the Dockerfile's runtime stage. The
# container reads its own configuration from that file, so the deployment does
# not depend on every variable having been typed into a hosting platform's
# settings screen. Anything the platform DOES set still wins: godotenv never
# overwrites a variable that is already present in the environment.
#
# Every other `.env.*` stays out. `.env.local` and `.env.secrets` are one
# developer's machine, and `.env.secrets` in particular is the file that holds
# a key — it must never be inside an image.
.env*
!.env.production
.git
.claude