docker issue

This commit is contained in:
2026-08-27 17:12:54 +05:30
parent 904a5d816f
commit 9a352e9f71

View File

@@ -42,9 +42,26 @@ COPY nginx.conf.template /etc/nginx/templates/default.conf.template
# boot is a bad thing to leave to luck.
ENV NGINX_ENVSUBST_FILTER=INGEST_TOKEN
# Empty by default, so the image runs without it. Sheet upload then fails with
# the ingest service's own 401, which says what is missing — rather than nginx
# refusing to start and taking the whole console down with it.
# Empty by default — and this line is LOAD-BEARING. Do not delete it.
#
# BuildKit warns about it: `SecretsUsedInArgOrEnv: Do not use ARG or ENV
# instructions for sensitive data (ENV "INGEST_TOKEN")`. The warning is right in
# general and wrong here: nothing sensitive is baked in, the value is the empty
# string, and the real token is supplied at RUN time by the deployment.
#
# Removing the line to silence the warning breaks the config in a way that is
# hard to see. nginx's entrypoint builds its substitution list from env vars
# that are DEFINED:
#
# defined_envs=$(printf '${%s} ' $(awk "END { for (name in ENVIRON) ... }"))
#
# With INGEST_TOKEN undefined, it is not in that list, envsubst leaves the
# placeholder alone, and nginx ends up with the literal text `${INGEST_TOKEN}`
# as the token — which is not empty, so the missing-token guard never fires and
# every ingest call goes out with a nonsense `X-API-Key`.
#
# Declaring it empty here guarantees envsubst always substitutes it, so an
# unset token is a real empty string and the guard can catch it.
ENV INGEST_TOKEN=""
COPY --from=builder /app/dist/ /usr/share/nginx/html/