Summary
Severity: Medium — Docker/Docker-compose run a development Next.js server in production; .env can be baked into the image.
Problem
Dockerfile (lines 9-19):
RUN npm install
RUN npm run build
CMD ["npm", "run", "dev"] # ← dev server!
docker-compose.yml:7:
command: npm run dev
environment: NODE_ENV=development
Additionally:
npm install (not npm ci) — non-reproducible builds.
- Runs as root.
COPY . . (Dockerfile:12) copies .env (Supabase keys, API URL) into the image if present.
Impact
next dev in production: unoptimized bundles, source maps, HMR overhead, no standalone output benefits, dramatically worse performance.
NODE_ENV=development also selects the permissive dev CSP (connect-src http: ws: everywhere, next.config.js:6-8).
- Secrets in the image; root processes in the container.
Fix
- Multi-stage build:
npm ci → npm run build → run next start with NODE_ENV=production.
- Non-root user (
USER node).
- Add
.env, .next, node_modules to .dockerignore.
- Remove the
NODE_ENV=development override from docker-compose.yml.
Files
Dockerfile (lines 9-19)
docker-compose.yml (line 7)
.dockerignore (missing/insufficient)
next.config.js (lines 6-8)
Summary
Severity: Medium — Docker/Docker-compose run a development Next.js server in production;
.envcan be baked into the image.Problem
Dockerfile(lines 9-19):docker-compose.yml:7:Additionally:
npm install(notnpm ci) — non-reproducible builds.COPY . .(Dockerfile:12) copies.env(Supabase keys, API URL) into the image if present.Impact
next devin production: unoptimized bundles, source maps, HMR overhead, no standalone output benefits, dramatically worse performance.NODE_ENV=developmentalso selects the permissive dev CSP (connect-src http: ws:everywhere,next.config.js:6-8).Fix
npm ci→npm run build→ runnext startwithNODE_ENV=production.USER node)..env,.next,node_modulesto.dockerignore.NODE_ENV=developmentoverride fromdocker-compose.yml.Files
Dockerfile(lines 9-19)docker-compose.yml(line 7).dockerignore(missing/insufficient)next.config.js(lines 6-8)