Keep secrets and runtime data out of the Docker images

The build context is the repository root and there was no .dockerignore, so
'COPY backend/ ./' swept backend/venv (327 MB), backend/media (the actual
library, 224 MB), backend/logs, backend/staticfiles and backend/.env
(SECRET_KEY plus the database password) into the backend image: 1.43 GB per
architecture, including secrets headed for the registry. The frontend build
stage also copied the host's node_modules over the fresh install.

- Root .dockerignore excludes .git, virtualenvs, __pycache__, db.sqlite3,
  logs/staticfiles, .env files, media/, node_modules, dist and the deploy
  runtime state (data/, tailscale-state/).
- The backend Dockerfile now asserts the context is clean (.env, venv,
  media/library, db.sqlite3 all absent) before collectstatic, so a missing
  ignore file fails the build instead of leaking.
- Rebuilt: backend 1.43 GB -> 876 MB ('COPY backend/' is now 268 kB),
  frontend stays at 65 MB. Verified by booting the compose stack with the
  new image: migrations applied, /health ok, no .env or venv inside, and
  /app/media is the mounted (empty) volume; the scheduler runs too.
- Removed the stale local images that still contained the library and the
  dev .env.
This commit is contained in:
2026-09-18 16:04:55 -05:00
parent 1170e6e9c1
commit a17dd5a4ef
3 changed files with 52 additions and 0 deletions
+9
View File
@@ -114,6 +114,15 @@ ffmpeg for video thumbnails. The `GIT_HASH` build arg is baked into the
backend image so the shell's version pill shows the commit (images have no
`.git` directory); the push scripts pass it automatically.
Both build from the repository root, which is filtered by `.dockerignore`:
`backend/venv`, `backend/media`, `backend/logs`, `backend/staticfiles`,
`backend/.env`, `frontend/node_modules`, `frontend/dist` and the deploy
runtime state never enter the images — the database, media and logs come
from the compose volumes and `deploy/.env` at runtime. The backend build
also asserts that (`.env`, `venv`, `media/library`, `db.sqlite3` absent), so
a missing ignore file fails the build instead of shipping secrets. Rebuild
(and `docker image prune`) if you built before that guard existed.
Push multi-arch images to the Gitea registry:
```bash