From aeee1959027f034fb459e8fe103a8b23f47f8b23 Mon Sep 17 00:00:00 2001 From: Dijana Pavlovic Date: Thu, 1 Aug 2024 17:52:56 +0200 Subject: [PATCH] Remove env vars from Dockerfile --- .github/workflows/publish-image.yml | 11 +---------- Dockerfile | 29 ----------------------------- 2 files changed, 1 insertion(+), 39 deletions(-) diff --git a/.github/workflows/publish-image.yml b/.github/workflows/publish-image.yml index 2e75825..124ea1d 100644 --- a/.github/workflows/publish-image.yml +++ b/.github/workflows/publish-image.yml @@ -7,6 +7,7 @@ on: jobs: build-and-publish: + permissions: write-all runs-on: ubuntu-latest steps: @@ -34,13 +35,3 @@ jobs: context: . push: true tags: ghcr.io/${{ github.actor }}/qna-admin:latest - secrets: | - "OPENAI_KEY=${{ secrets.OPENAI_KEY }}" - "DISCORD_TOKEN=${{ secrets.DISCORD_TOKEN }}" - "DISCORD_CLIENT_PUBLIC_KEY=${{ secrets.DISCORD_CLIENT_PUBLIC_KEY }}" - "DISCORD_GUILD_ID=${{ secrets.DISCORD_GUILD_ID }}" - "DISCORD_MODERATION_ACCESS_ROLES=${{ secrets.DISCORD_MODERATION_ACCESS_ROLES }}" - "REVIEW_CHANNEL_ID=${{ secrets.REVIEW_CHANNEL_ID }}" - "DISCORD_CLIENT_ID=${{ secrets.DISCORD_CLIENT_ID }}" - "EDGEDB_SECRET_KEY=${{ secrets.EDGEDB_SECRET_KEY }}" - "EDGEDB_INSTANCE=${{ secrets.EDGEDB_INSTANCE }}" diff --git a/Dockerfile b/Dockerfile index 203b9dc..3a8dacc 100644 --- a/Dockerfile +++ b/Dockerfile @@ -39,35 +39,6 @@ FROM base AS runner WORKDIR /app ENV NODE_ENV production -ENV BASE_URL https://localhost:3000 -ENV EDGEDB_INSTANCE edgedb/qna - -# Copy the .env.production file from the builder stage -COPY .env.production ./ - -RUN --mount=type=secret,id=OPENAI_KEY \ - sed -i "s/OPENAI_KEY=/OPENAI_KEY=$(cat /run/secrets/OPENAI_KEY)/" .env.production - -RUN --mount=type=secret,id=DISCORD_TOKEN \ - sed -i "s/DISCORD_TOKEN=/DISCORD_TOKEN=$(cat /run/secrets/DISCORD_TOKEN)/" .env.production - -RUN --mount=type=secret,id=DISCORD_CLIENT_PUBLIC_KEY \ - sed -i "s/DISCORD_CLIENT_PUBLIC_KEY=/DISCORD_CLIENT_PUBLIC_KEY=$(cat /run/secrets/DISCORD_CLIENT_PUBLIC_KEY)/" .env.production - -RUN --mount=type=secret,id=DISCORD_GUILD_ID \ - sed -i "s/DISCORD_GUILD_ID=/DISCORD_GUILD_ID=$(cat /run/secrets/DISCORD_GUILD_ID)/" .env.production - -RUN --mount=type=secret,id=DISCORD_MODERATION_ACCESS_ROLES \ - sed -i "s/DISCORD_MODERATION_ACCESS_ROLES=/DISCORD_MODERATION_ACCESS_ROLES=$(cat /run/secrets/DISCORD_MODERATION_ACCESS_ROLES)/" .env.production - -RUN --mount=type=secret,id=REVIEW_CHANNEL_ID \ - sed -i "s/REVIEW_CHANNEL_ID=/REVIEW_CHANNEL_ID=$(cat /run/secrets/REVIEW_CHANNEL_ID)/" .env.production - -RUN --mount=type=secret,id=DISCORD_CLIENT_ID \ - sed -i "s/DISCORD_CLIENT_ID=/DISCORD_CLIENT_ID=$(cat /run/secrets/DISCORD_CLIENT_ID)/" .env.production - -RUN --mount=type=secret,id=EDGEDB_SECRET_KEY \ - sed -i "s/EDGEDB_SECRET_KEY=/EDGEDB_SECRET_KEY=$(cat /run/secrets/EDGEDB_SECRET_KEY)/" .env.production # Uncomment the following line in case you want to disable telemetry during runtime. # ENV NEXT_TELEMETRY_DISABLED 1