Ship config as .env.production - Dokploy was overwriting the committed .env

The container was never getting its configuration, so it started with nothing
set and Traefik reported a Bad Gateway on every route.

Dokploy writes its own .env into the build context from the service's
Environment tab AFTER cloning the repository. That tab is empty, so it wrote a
zero-byte file over the committed one, and `COPY .env .` faithfully copied the
empty result into the image. The checkout showed it exactly: every file
timestamped 08:33, and .env alone at 08:34 with a size of 0. Inside the running
container, /app/.env was 0 bytes.

Nothing about this is visible from the outside. The build log shows the COPY
succeeding, the image is produced, and the platform reports only a 502.

Dokploy does not manage .env.production, so the config now travels under that
name and the Dockerfile copies it to /app/.env in the image. Anything set in the
Environment tab still wins at runtime, because settings.py calls load_dotenv()
without override=True.

Verified by reconstructing the build context the way Dokploy does - git archive
of HEAD, then an empty .env written over it - applying .dockerignore and the
COPY lines, and booting the result with an empty environment: /app/.env is 4938
bytes, the sign-in passwords are absent, and scripts/check_deploy.sh reports 6
passed, 0 failed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriyakumarvijayanayagam
2026-08-13 14:13:05 +05:30
parent 5f66a797d8
commit ea0c00d68e
4 changed files with 29 additions and 18 deletions

View File

@@ -6,11 +6,12 @@ __pycache__
.git
tests
# .env is deliberately NOT ignored - it carries this deployment's configuration
# and the Dockerfile copies it into the image. Excluding it here silently undid
# that: the build succeeded, the container started with no configuration at all,
# and died on the first required setting.
# .env.production carries this deployment's configuration and the Dockerfile
# copies it to /app/.env inside the image, so it must NOT be ignored here.
# Dokploy's own .env (written from the Environment tab, empty when that tab is
# blank) is ignored instead - it is what silently overwrote the committed one.
#
# The generated sign-in passwords must never be in the image.
SIGNIN_PASSWORDS.txt
.env
.env.local
SIGNIN_PASSWORDS.txt