# What does not reach the image. # # `.env.production` IS copied in — see the Dockerfile's runtime stage. The # container reads its own configuration from that file, so the deployment does # not depend on every variable having been typed into a hosting platform's # settings screen. Anything the platform DOES set still wins: godotenv never # overwrites a variable that is already present in the environment. # # Every other `.env.*` stays out. `.env.local` and `.env.secrets` are one # developer's machine, and `.env.secrets` in particular is the file that holds # a key — it must never be inside an image. .env* !.env.production .git .claude .DS_Store docs scratch init nearle server docker-compose.local.yml