diff --git a/.env b/.env.production similarity index 77% rename from .env rename to .env.production index 80809ce..8f25364 100644 --- a/.env +++ b/.env.production @@ -1,5 +1,9 @@ # Committed on purpose - see .gitignore. # +# Named .env.production, not .env: Dokploy overwrites .env in the build context +# from the service's Environment tab (empty when that tab is blank). Vite loads +# .env.production for production builds and it wins over .env, so this survives. +# # Nothing here is a secret. VITE_API_BASE_URL is inlined into the public JS # bundle at build time, so it is readable by anyone who opens the site; keeping # it out of git protected nothing and only meant the value had to be remembered diff --git a/.gitignore b/.gitignore index cf60b8b..aac5a69 100644 --- a/.gitignore +++ b/.gitignore @@ -12,15 +12,22 @@ dist dist-ssr *.local -# .env is committed here deliberately. It holds only VITE_API_BASE_URL, which -# Vite inlines into the public bundle anyway - it is visible to anyone who opens -# the site, so ignoring it protected nothing. Committing it means the deploy +# .env.production is committed deliberately. It holds only VITE_API_BASE_URL, +# which Vite inlines into the public bundle anyway - visible to anyone who opens +# the site - so ignoring it protected nothing, and committing it means the deploy # does not depend on remembering a --build-arg. # +# The name matters. Dokploy writes its own .env into the build context from the +# service's Environment tab after cloning, so a committed .env is silently +# replaced - with an empty file when that tab is blank, which is exactly what +# left the deployed bundle with no API URL at all. Vite loads .env.production +# for production builds and it takes precedence over .env, so this survives. +# # Anything genuinely secret must NOT go in a VITE_-prefixed variable: it would # be published in the bundle. Use .env.local (still ignored) for local # overrides. -!.env +!.env.production +.env .env.local # Editor directories and files