feat: keep secrets out of the app image (E00-S02-T08)

- .dockerignore: exclude env + credential files (.npmrc, .netrc, .aws, .ssh,
  secrets/, *.pem, *.key, *.p12, *.pfx, *.jks, id_rsa, id_ed25519, ...) from
  the build context so a local secret file cannot be embedded in the image
- Dockerfile: document the T08 guarantee (no secret ARG/ENV, fixed non-secret
  COPY paths, runtime credentials via Compose environment)
- compose.yaml: T08 in scope; runtime credentials stay in service environment,
  never in the image
This commit is contained in:
implementer
2026-08-29 01:28:26 +00:00
parent 25d7dc836b
commit 0938da8a73
3 changed files with 36 additions and 3 deletions
+9
View File
@@ -17,6 +17,15 @@
# T05 the runtime stage drops root privileges (runs as the image's non-root
# `node` user).
#
# T08: the image embeds no secrets. The Dockerfile declares no secret-bearing
# ARG/ENV instruction (the only ENV is `NODE_ENV=production`) and every COPY
# copies a fixed, non-secret path (manifests, source, compiled dist) — never
# `.env` or credential files; `.dockerignore` additionally excludes env and
# credential files from the build context, so a local secret file cannot be
# embedded even by mistake. Runtime credentials (e.g. DATABASE_URL) are
# injected by Compose at run time (compose.yaml `app.environment`), never baked
# into the image. Tests: tests/secrets-not-embedded.test.mjs.
#
# Image base: node:24.19.0-bookworm-slim (glibc Debian) per Technology-Stack
# §5.4 — argon2 is a native dependency and musl/Alpine causes native-module
# build surprises, so the image must stay on a glibc base.