diff --git a/Dockerfile b/Dockerfile index a09829f..cbfdd93 100644 --- a/Dockerfile +++ b/Dockerfile @@ -42,9 +42,26 @@ COPY nginx.conf.template /etc/nginx/templates/default.conf.template # boot is a bad thing to leave to luck. ENV NGINX_ENVSUBST_FILTER=INGEST_TOKEN -# Empty by default, so the image runs without it. Sheet upload then fails with -# the ingest service's own 401, which says what is missing — rather than nginx -# refusing to start and taking the whole console down with it. +# Empty by default — and this line is LOAD-BEARING. Do not delete it. +# +# BuildKit warns about it: `SecretsUsedInArgOrEnv: Do not use ARG or ENV +# instructions for sensitive data (ENV "INGEST_TOKEN")`. The warning is right in +# general and wrong here: nothing sensitive is baked in, the value is the empty +# string, and the real token is supplied at RUN time by the deployment. +# +# Removing the line to silence the warning breaks the config in a way that is +# hard to see. nginx's entrypoint builds its substitution list from env vars +# that are DEFINED: +# +# defined_envs=$(printf '${%s} ' $(awk "END { for (name in ENVIRON) ... }")) +# +# With INGEST_TOKEN undefined, it is not in that list, envsubst leaves the +# placeholder alone, and nginx ends up with the literal text `${INGEST_TOKEN}` +# as the token — which is not empty, so the missing-token guard never fires and +# every ingest call goes out with a nonsense `X-API-Key`. +# +# Declaring it empty here guarantees envsubst always substitutes it, so an +# unset token is a real empty string and the guard can catch it. ENV INGEST_TOKEN="" COPY --from=builder /app/dist/ /usr/share/nginx/html/