Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ out/

# Environment files
.env*
backups/

# Development files
.git
Expand Down
7 changes: 4 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -29,8 +29,8 @@ CMD ["pnpm", "dev"]

# The build database must be migrated and disposable. Prisma TypedSQL inspects it.
FROM base AS builder
ARG DATABASE_URL
ARG DATABASE_DIRECT_URL
ARG BUILD_DATABASE_URL
ARG BUILD_DATABASE_DIRECT_URL
ARG NEXT_IMAGE_UNOPTIMIZED
ARG NEXT_PUBLIC_ALLOWED_ORIGINS
ARG NEXT_PUBLIC_ANDROID_LATEST_APK_URL
Expand Down Expand Up @@ -65,7 +65,8 @@ RUN pnpm install --frozen-lockfile --ignore-scripts
COPY . .
ENV NEXT_TELEMETRY_DISABLED=1
RUN pnpm version:sync
RUN DATABASE_URL="${DATABASE_URL}" DATABASE_DIRECT_URL="${DATABASE_DIRECT_URL:-${DATABASE_URL}}" \
RUN : "${BUILD_DATABASE_URL:?Set BUILD_DATABASE_URL to a migrated disposable database}" && \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Consume the database URL as a BuildKit secret

When operators follow the new self-hosting instructions and enable Use Docker Build Secrets, BUILD_DATABASE_URL is supplied as a BuildKit secret rather than as this declared build argument. Docker requires secrets to be consumed by a RUN --mount=type=secret instruction (Docker build secrets); this RUN therefore sees an empty BUILD_DATABASE_URL and aborts every Coolify app build before pnpm build. Mount the secret into this instruction, or do not instruct operators to enable secret mode.

Useful? React with 👍 / 👎.

DATABASE_URL="${BUILD_DATABASE_URL}" DATABASE_DIRECT_URL="${BUILD_DATABASE_DIRECT_URL:-${BUILD_DATABASE_URL}}" \
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY="${NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY}" \
NEXT_PUBLIC_R2_PUBLIC_BASE_URL="${NEXT_PUBLIC_R2_PUBLIC_BASE_URL}" \
NEXT_PUBLIC_R2_UPLOADS_PUBLIC_BASE_URL="${NEXT_PUBLIC_R2_UPLOADS_PUBLIC_BASE_URL}" \
Expand Down
9 changes: 5 additions & 4 deletions docs/SELF_HOSTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,12 +6,13 @@ EmuReady runs as a standalone Next.js container behind Coolify and Cloudflare. S

- Build the `app` target from `Dockerfile`; run the resulting immutable image in Coolify.
- Supply all `NEXT_PUBLIC_*` values while building. Runtime values cannot change the browser bundle.
- Use a migrated, disposable Postgres database while building because Prisma TypedSQL generation introspects the schema. Never use production for this.
- In Coolify, mark the build database URLs as build variables and enable **Use Docker Build Secrets**. Ordinary Docker build arguments expose their values in image metadata.
- Keep runtime-only secrets, such as `CLERK_SECRET_KEY`, out of the build phase.
- Set `BUILD_DATABASE_URL` to a migrated, disposable Postgres database because Prisma TypedSQL generation introspects the schema. Never use production or a restored production backup for this. Apply the existing migrations to an empty database; seeds are unnecessary.
- Optionally set `BUILD_DATABASE_DIRECT_URL` for that same disposable database. It defaults to `BUILD_DATABASE_URL`. The builder maps these names to Prisma's `DATABASE_URL` and `DATABASE_DIRECT_URL` only for `pnpm build`, and fails if `BUILD_DATABASE_URL` is missing.
- In Coolify, make `BUILD_DATABASE_URL` and `BUILD_DATABASE_DIRECT_URL` build-only variables and enable **Use Docker Build Secrets**. Ordinary Docker build arguments expose their values in image metadata.
- Keep the real `DATABASE_URL`, `DATABASE_DIRECT_URL`, and other runtime-only secrets, such as `CLERK_SECRET_KEY`, out of the build phase. Backups and environment files must remain excluded from the Docker context.
- For a release containing migrations, build the `migrator` target from the same commit and run it with `DATABASE_DIRECT_URL` before deploying the `app` image.

The VPS currently builds from source in Coolify. A verified GitHub App webhook automatically deploys pushes to the configured branch. Publishing prebuilt immutable images remains deferred.
The VPS currently builds from source in Coolify. Staging uses the GitHub App webhook to deploy its configured branch; production is configured for manual deployments. Publishing prebuilt immutable images remains deferred.

## Coolify application

Expand Down
Loading