Skip to content

MEDIUM: Docker/compose run dev server in production; .env baked into image #16

Description

@d-e-v-14

Summary

Severity: Medium — Docker/Docker-compose run a development Next.js server in production; .env can be baked into the image.

Problem

Dockerfile (lines 9-19):

RUN npm install
RUN npm run build
CMD ["npm", "run", "dev"]      # ← dev server!

docker-compose.yml:7:

command: npm run dev
environment: NODE_ENV=development

Additionally:

  • npm install (not npm ci) — non-reproducible builds.
  • Runs as root.
  • COPY . . (Dockerfile:12) copies .env (Supabase keys, API URL) into the image if present.

Impact

  • next dev in production: unoptimized bundles, source maps, HMR overhead, no standalone output benefits, dramatically worse performance.
  • NODE_ENV=development also selects the permissive dev CSP (connect-src http: ws: everywhere, next.config.js:6-8).
  • Secrets in the image; root processes in the container.

Fix

  • Multi-stage build: npm ci → npm run build → run next start with NODE_ENV=production.
  • Non-root user (USER node).
  • Add .env, .next, node_modules to .dockerignore.
  • Remove the NODE_ENV=development override from docker-compose.yml.

Files

  • Dockerfile (lines 9-19)
  • docker-compose.yml (line 7)
  • .dockerignore (missing/insufficient)
  • next.config.js (lines 6-8)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions