fix(deploy): harden prod env for bcrypt hash and media path
Two latent production pitfalls, both proven by probing Compose's env_file resolution: - A bcrypt ADMIN_PASSWORD_HASH is full of $; Compose env_file interpolation AND dotenvy variable substitution both eat the $… segments (as unset vars), corrupting the hash so every admin login 401s. Single-quote it so both read it literally — verified correct for env_file (container) and dotenvy 0.15.7 strong-quote (native). Updated .env.example with the quotes + a warning comment. - MEDIA_PATH: pin it to the /media mount in the app 'environment:' block so a stray host path in .env can't leak in and make every upload 500 with EACCES. environment overrides env_file, so the container is always correct. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -24,7 +24,11 @@ SESSION_EXPIRY_DAYS=30
|
|||||||
|
|
||||||
# Admin dashboard password (bcrypt hash).
|
# Admin dashboard password (bcrypt hash).
|
||||||
# Generate with: htpasswd -bnBC 12 "" yourpassword | tr -d ':\n'
|
# Generate with: htpasswd -bnBC 12 "" yourpassword | tr -d ':\n'
|
||||||
ADMIN_PASSWORD_HASH=$2y$12$placeholder_replace_me
|
# IMPORTANT: keep the SINGLE QUOTES. A bcrypt hash is full of `$` (e.g. $2b$12$…$…),
|
||||||
|
# and both Docker Compose's env_file interpolation and dotenvy's variable substitution
|
||||||
|
# would otherwise eat the `$…` segments (reading them as unset vars) and corrupt the
|
||||||
|
# hash — every admin login then 401s. Single quotes make both read it literally.
|
||||||
|
ADMIN_PASSWORD_HASH='$2y$12$placeholder_replace_me'
|
||||||
|
|
||||||
# ── Event ─────────────────────────────────────────────────────────────────────
|
# ── Event ─────────────────────────────────────────────────────────────────────
|
||||||
EVENT_NAME=Max & Maria's Wedding
|
EVENT_NAME=Max & Maria's Wedding
|
||||||
|
|||||||
@@ -29,6 +29,12 @@ services:
|
|||||||
# Activates the production secret guard in config.rs — refuses to boot with
|
# Activates the production secret guard in config.rs — refuses to boot with
|
||||||
# placeholder JWT_SECRET / ADMIN_PASSWORD_HASH.
|
# placeholder JWT_SECRET / ADMIN_PASSWORD_HASH.
|
||||||
APP_ENV: production
|
APP_ENV: production
|
||||||
|
# The media volume is mounted at /media (below), so the app MUST write there.
|
||||||
|
# Pin it here rather than trusting .env: if MEDIA_PATH in .env points elsewhere
|
||||||
|
# (e.g. a host path used for running the backend natively) the container can't
|
||||||
|
# create it and every upload 500s with EACCES. `environment` overrides `env_file`,
|
||||||
|
# so this is authoritative for the container.
|
||||||
|
MEDIA_PATH: /media
|
||||||
depends_on:
|
depends_on:
|
||||||
db:
|
db:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
|||||||
Reference in New Issue
Block a user