VITE_API_BASE_URL is inlined into the public JS bundle at build time, so it is readable by anyone who opens the site. Ignoring it protected nothing and only meant the value had to be remembered and re-passed as --build-arg on every deploy - which is exactly how the bundle ended up pointing at a host that did not exist. Vite reads .env during `npm run build`, so the Docker build now picks the domain up on its own and needs no build arg. Verified: a build with no --build-arg bakes in https://mcp.nearle.ai.in. .env.local stays ignored for local overrides. Nothing secret belongs in a VITE_-prefixed variable - it would be published in the bundle. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
823 B
823 B