feat: keep secrets out of the app image (E00-S02-T08)
- .dockerignore: exclude env + credential files (.npmrc, .netrc, .aws, .ssh, secrets/, *.pem, *.key, *.p12, *.pfx, *.jks, id_rsa, id_ed25519, ...) from the build context so a local secret file cannot be embedded in the image - Dockerfile: document the T08 guarantee (no secret ARG/ENV, fixed non-secret COPY paths, runtime credentials via Compose environment) - compose.yaml: T08 in scope; runtime credentials stay in service environment, never in the image
This commit is contained in:
+9
-3
@@ -1,4 +1,4 @@
|
||||
# EPPP Docker Compose baseline — [E00-S02-T01..T07]
|
||||
# EPPP Docker Compose baseline — [E00-S02-T01..T08]
|
||||
#
|
||||
# `docker compose up -d` starts both the database (PostgreSQL) and the
|
||||
# application (@personal-blog/server). Rollback: `docker compose down`.
|
||||
@@ -37,8 +37,14 @@
|
||||
# so local runs and the T01..T06 real-stack probes are unaffected. Rollback:
|
||||
# drop the `platforms` list from the `app` build config.
|
||||
#
|
||||
# Explicitly out of scope for T01..T07 (land in a later E00-S02 task):
|
||||
# - secrets not embedded (T08)
|
||||
# Secrets not embedded (T08): the app image carries no secrets — the committed
|
||||
# apps/server/Dockerfile declares no secret-bearing ARG/ENV instruction and
|
||||
# copies only fixed, non-secret paths, and the committed .dockerignore excludes
|
||||
# env and credential files from the build context. Runtime credentials are
|
||||
# injected here, at run time, via service `environment` values (the app's
|
||||
# DATABASE_URL, the db service's POSTGRES_* defaults) — they live in
|
||||
# Compose/deploy config, never in the image. Rollback: rebuild the image after
|
||||
# removing any embedded secret. Tests: tests/secrets-not-embedded.test.mjs.
|
||||
#
|
||||
# All values have defaults so `docker compose up -d` works from a clean clone
|
||||
# without a .env file (a committed .env.example template lands in E00-S04).
|
||||
|
||||
Reference in New Issue
Block a user