fix: exclude .env secrets from python/vite deploy zips (not backups) (#23)

Only nextjs-kind excluded .env* from the deploy archive; python and vite
did not - so a project's local .env at its root got zipped and shipped to
the server on every deploy, planting local secrets over the server's own
(the operator-file restore only wins for files it preserved). Add
.env/.env.local/.env.production to the python and vite deploy excludes,
matching nextjs. Kept DEPLOY-only (like `uploads`): backups still capture
.env so a source backup stays complete. Bash + PowerShell.

Note: this covers a ROOT .env. A nested secret (e.g. DocketMail's
backend/.env) is handled separately via deploy.preserve in the project's
zconfig.
This commit is contained in:
kellymichels 2026-07-25 15:22:04 -05:00 committed by GitHub
parent b370a46d79
commit 5844fc1614
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 13 additions and 4 deletions

View File

@ -177,10 +177,16 @@ function Get-ArchiveExcludes {
$byKind = switch ([string]$Project.kind) { $byKind = switch ([string]$Project.kind) {
"python" { "python" {
$list = @(".venv", "venv", "__pycache__", ".pytest_cache", ".nicegui", "archive", "dist", "build", "htmlcov") $list = @(".venv", "venv", "__pycache__", ".pytest_cache", ".nicegui", "archive", "dist", "build", "htmlcov")
if (-not $ForBackup) { $list += "uploads" } # deploys exclude user uploads; backups keep them # Deploys exclude user uploads + local .env secrets (server keeps its
# own, preserved across deploys); backups keep both for completeness.
if (-not $ForBackup) { $list += @("uploads", ".env", ".env.local", ".env.production") }
$list
}
"vite" {
$list = @("node_modules", "dist")
if (-not $ForBackup) { $list += @(".env", ".env.local", ".env.production") }
$list $list
} }
"vite" { @("node_modules", "dist") }
"nextjs" { @("node_modules", ".next", ".env", ".env.local", ".env.production", ".vercel", "coverage", "out", "build", "next-env.d.ts") } "nextjs" { @("node_modules", ".next", ".env", ".env.local", ".env.production", ".vercel", "coverage", "out", "build", "next-env.d.ts") }
default { @() } default { @() }
} }

View File

@ -217,8 +217,11 @@ z_archive_excludes() {
case "$kind" in case "$kind" in
python) python)
printf '%s\n' .venv venv __pycache__ .pytest_cache .nicegui archive dist build htmlcov printf '%s\n' .venv venv __pycache__ .pytest_cache .nicegui archive dist build htmlcov
[ "$for_backup" -eq 1 ] || printf '%s\n' uploads ;; # deploys exclude user uploads; backups keep them # deploys exclude user uploads + local .env secrets; backups keep both
vite) printf '%s\n' node_modules dist ;; [ "$for_backup" -eq 1 ] || printf '%s\n' uploads .env .env.local .env.production ;;
vite)
printf '%s\n' node_modules dist
[ "$for_backup" -eq 1 ] || printf '%s\n' .env .env.local .env.production ;;
nextjs) printf '%s\n' node_modules .next .env .env.local .env.production .vercel coverage out build next-env.d.ts ;; nextjs) printf '%s\n' node_modules .next .env .env.local .env.production .vercel coverage out build next-env.d.ts ;;
esac esac
jq -r --arg k "$key" '.projects[$k].deploy.exclude // [] | .[]' "$ZCONFIG" jq -r --arg k "$key" '.projects[$k].deploy.exclude // [] | .[]' "$ZCONFIG"