# Keep the build context small and NEVER bake secrets or host-built artifacts into the image. # Secrets — must never enter the image (env is injected by Dokploy at runtime). .env .env.* !.env.example # Dependencies + build outputs (reinstalled / rebuilt inside the image). node_modules **/node_modules apps/web/dist apps/api/dist dist build .turbo .cache coverage # VCS / CI / editor / OS noise. .git .gitignore .github .vscode .idea .DS_Store Thumbs.db # Logs and legacy Plesk/Passenger runtime scratch. *.log logs tmp # Local-only storage dirs (documents live in Spaces). storage uploads # Tests aren't needed in the runtime image. apps/api/test **/*.test.ts # Note: certs/ is intentionally NOT ignored — the Postgres CA cert (if committed) is baked in # so production TLS verification works. See DEPLOY-DOKPLOY.md.