The container was never getting its configuration, so it started with nothing set and Traefik reported a Bad Gateway on every route. Dokploy writes its own .env into the build context from the service's Environment tab AFTER cloning the repository. That tab is empty, so it wrote a zero-byte file over the committed one, and `COPY .env .` faithfully copied the empty result into the image. The checkout showed it exactly: every file timestamped 08:33, and .env alone at 08:34 with a size of 0. Inside the running container, /app/.env was 0 bytes. Nothing about this is visible from the outside. The build log shows the COPY succeeding, the image is produced, and the platform reports only a 502. Dokploy does not manage .env.production, so the config now travels under that name and the Dockerfile copies it to /app/.env in the image. Anything set in the Environment tab still wins at runtime, because settings.py calls load_dotenv() without override=True. Verified by reconstructing the build context the way Dokploy does - git archive of HEAD, then an empty .env written over it - applying .dockerignore and the COPY lines, and booting the result with an empty environment: /app/.env is 4938 bytes, the sign-in passwords are absent, and scripts/check_deploy.sh reports 6 passed, 0 failed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
39 lines
1.2 KiB
Plaintext
39 lines
1.2 KiB
Plaintext
# .env.production is committed deliberately, at the repo owner's instruction, so
|
|
# the deployment does not depend on re-entering config in the Dokploy UI.
|
|
#
|
|
# It is NOT named .env, and that matters: Dokploy writes its own .env into the
|
|
# build context from the service's Environment tab after cloning, so a committed
|
|
# .env is silently replaced (with an empty file when that tab is blank).
|
|
# The Dockerfile copies .env.production to /app/.env inside the image.
|
|
#
|
|
# The two database secrets are NOT in it - they are set as Dokploy environment
|
|
# variables, which override the file (settings.py calls load_dotenv() without
|
|
# override=True, so the process environment wins).
|
|
#
|
|
# The auth secrets ARE in it. AUTH_SECRET_KEY signs every access token, so
|
|
# anyone with read access to this repository can mint an admin token, and git
|
|
# history keeps it after any rotation. Regenerate with
|
|
# `python scripts/make_auth_secrets.py` if that stops being acceptable.
|
|
!.env.production
|
|
.env
|
|
|
|
# Local overrides and the generated sign-in passwords stay out of git.
|
|
.env.local
|
|
SIGNIN_PASSWORDS.txt
|
|
|
|
# Python
|
|
__pycache__/
|
|
*.pyc
|
|
*.pyo
|
|
.venv/
|
|
venv/
|
|
*.egg-info/
|
|
.pytest_cache/
|
|
|
|
# Logs
|
|
*.log
|
|
|
|
# OS
|
|
.DS_Store
|
|
Thumbs.db
|