docker issue
This commit is contained in:
23
Dockerfile
23
Dockerfile
@@ -42,9 +42,26 @@ COPY nginx.conf.template /etc/nginx/templates/default.conf.template
|
||||
# boot is a bad thing to leave to luck.
|
||||
ENV NGINX_ENVSUBST_FILTER=INGEST_TOKEN
|
||||
|
||||
# Empty by default, so the image runs without it. Sheet upload then fails with
|
||||
# the ingest service's own 401, which says what is missing — rather than nginx
|
||||
# refusing to start and taking the whole console down with it.
|
||||
# Empty by default — and this line is LOAD-BEARING. Do not delete it.
|
||||
#
|
||||
# BuildKit warns about it: `SecretsUsedInArgOrEnv: Do not use ARG or ENV
|
||||
# instructions for sensitive data (ENV "INGEST_TOKEN")`. The warning is right in
|
||||
# general and wrong here: nothing sensitive is baked in, the value is the empty
|
||||
# string, and the real token is supplied at RUN time by the deployment.
|
||||
#
|
||||
# Removing the line to silence the warning breaks the config in a way that is
|
||||
# hard to see. nginx's entrypoint builds its substitution list from env vars
|
||||
# that are DEFINED:
|
||||
#
|
||||
# defined_envs=$(printf '${%s} ' $(awk "END { for (name in ENVIRON) ... }"))
|
||||
#
|
||||
# With INGEST_TOKEN undefined, it is not in that list, envsubst leaves the
|
||||
# placeholder alone, and nginx ends up with the literal text `${INGEST_TOKEN}`
|
||||
# as the token — which is not empty, so the missing-token guard never fires and
|
||||
# every ingest call goes out with a nonsense `X-API-Key`.
|
||||
#
|
||||
# Declaring it empty here guarantees envsubst always substitutes it, so an
|
||||
# unset token is a real empty string and the guard can catch it.
|
||||
ENV INGEST_TOKEN=""
|
||||
|
||||
COPY --from=builder /app/dist/ /usr/share/nginx/html/
|
||||
|
||||
Reference in New Issue
Block a user