🔧 fix(build): provide build-time dummy DB users and S3 bucket for collectstatic

C04 added runtime guards to settings_database (distinct DB users) and
settings_storage (S3 bucket required in production). collectstatic runs during
the Docker image build in production mode but never touches the DB or S3, so it
hit these guards and the image build failed.

Pass dummy build-time values for POSTGRES_APP/PLATFORM/MIGRATION_USER and
HUB_S3_BUCKET into the collectstatic RUN step. Runtime values still come from
the instance .env; the guards remain fully enforced in production runtime.

Verified locally: collectstatic completes (163 files).
This commit is contained in:
Andrey committed 2026-07-16 19:41:30 +03:00
1 parent c9ac556ae4
commit 13e714e1be
1 file changed
+8 -1
+8 -1
View File
@@ -16,9 +16,16 @@ COPY content /app/content
# collectstatic в образе (ADR-HUB-0028): STATIC_ROOT испечён, runtime-шаг не нужен.
# Build-time secret нужен только чтобы settings загрузились в production-режиме;
# collectstatic не обращается к БД/Redis. whitenoise раздаёт static в runtime.
# collectstatic не обращается к БД/Redis/S3. whitenoise раздаёт static в runtime.
# Build-time dummy values satisfy C04 runtime guards (distinct DB users in
# settings_database, S3 bucket in settings_storage) that only matter at runtime;
# collectstatic touches neither. Runtime values come from instance .env.
RUN cd apps/backend && HUB_SECRET_KEY=collectstatic-build HUB_DEBUG=false HUB_ENV=production \
CUSTOCRM_APP_ALLOWED_HOSTS=collectstatic.invalid \
POSTGRES_APP_USER=build-app \
POSTGRES_PLATFORM_USER=build-platform \
POSTGRES_MIGRATION_USER=build-migration \
HUB_S3_BUCKET=build-placeholder \
python manage.py collectstatic --noinput
RUN chown -R hub:hub /app