feat: keep secrets out of the app image (E00-S02-T08)
- .dockerignore: exclude env + credential files (.npmrc, .netrc, .aws, .ssh, secrets/, *.pem, *.key, *.p12, *.pfx, *.jks, id_rsa, id_ed25519, ...) from the build context so a local secret file cannot be embedded in the image - Dockerfile: document the T08 guarantee (no secret ARG/ENV, fixed non-secret COPY paths, runtime credentials via Compose environment) - compose.yaml: T08 in scope; runtime credentials stay in service environment, never in the image
This commit is contained in:
@@ -17,6 +17,15 @@
|
||||
# T05 the runtime stage drops root privileges (runs as the image's non-root
|
||||
# `node` user).
|
||||
#
|
||||
# T08: the image embeds no secrets. The Dockerfile declares no secret-bearing
|
||||
# ARG/ENV instruction (the only ENV is `NODE_ENV=production`) and every COPY
|
||||
# copies a fixed, non-secret path (manifests, source, compiled dist) — never
|
||||
# `.env` or credential files; `.dockerignore` additionally excludes env and
|
||||
# credential files from the build context, so a local secret file cannot be
|
||||
# embedded even by mistake. Runtime credentials (e.g. DATABASE_URL) are
|
||||
# injected by Compose at run time (compose.yaml `app.environment`), never baked
|
||||
# into the image. Tests: tests/secrets-not-embedded.test.mjs.
|
||||
#
|
||||
# Image base: node:24.19.0-bookworm-slim (glibc Debian) per Technology-Stack
|
||||
# §5.4 — argon2 is a native dependency and musl/Alpine causes native-module
|
||||
# build surprises, so the image must stay on a glibc base.
|
||||
|
||||
Reference in New Issue
Block a user