Ship the API URL as .env.production - Dokploy was overwriting .env

The deployed bundle had no API base URL baked in at all, so the app fell back to
relative /api/* requests, which the frontend's nginx forwards to a backend:8000
service that does not exist in this deployment.

Same cause as the backend: Dokploy writes its own .env into the build context
from the service's Environment tab after cloning, and that tab is empty, so the
committed file was replaced by a zero-byte one. The checkout showed .env at 0
bytes, and grepping the running container's bundle for the API host returned
nothing.

Vite loads .env.production for production builds and it takes precedence over
.env, so the config now travels under that name and survives. No Dockerfile
change is needed - Vite resolves it natively - and the --build-arg stays
unnecessary.

Verified by writing an empty .env over the checkout, exactly as Dokploy does,
and building: https://mcp.nearle.ai.in is still inlined into the bundle.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriyakumarvijayanayagam
2026-08-14 12:30:13 +05:30
parent ba9e06e7d8
commit 0096008db5
2 changed files with 15 additions and 4 deletions

View File

@@ -1,5 +1,9 @@
# Committed on purpose - see .gitignore.
#
# Named .env.production, not .env: Dokploy overwrites .env in the build context
# from the service's Environment tab (empty when that tab is blank). Vite loads
# .env.production for production builds and it wins over .env, so this survives.
#
# Nothing here is a secret. VITE_API_BASE_URL is inlined into the public JS
# bundle at build time, so it is readable by anyone who opens the site; keeping
# it out of git protected nothing and only meant the value had to be remembered

15
.gitignore vendored
View File

@@ -12,15 +12,22 @@ dist
dist-ssr
*.local
# .env is committed here deliberately. It holds only VITE_API_BASE_URL, which
# Vite inlines into the public bundle anyway - it is visible to anyone who opens
# the site, so ignoring it protected nothing. Committing it means the deploy
# .env.production is committed deliberately. It holds only VITE_API_BASE_URL,
# which Vite inlines into the public bundle anyway - visible to anyone who opens
# the site - so ignoring it protected nothing, and committing it means the deploy
# does not depend on remembering a --build-arg.
#
# The name matters. Dokploy writes its own .env into the build context from the
# service's Environment tab after cloning, so a committed .env is silently
# replaced - with an empty file when that tab is blank, which is exactly what
# left the deployed bundle with no API URL at all. Vite loads .env.production
# for production builds and it takes precedence over .env, so this survives.
#
# Anything genuinely secret must NOT go in a VITE_-prefixed variable: it would
# be published in the bundle. Use .env.local (still ignored) for local
# overrides.
!.env
!.env.production
.env
.env.local
# Editor directories and files