Without an include filter, tsc pulled in drizzle.config.ts from the
repo root too, which widened the inferred rootDir and nested output
under dist/src/main.js instead of dist/main.js -- crashing the
container (Cannot find module '/app/dist/main') since the Dockerfile
CMD expects the standard Nest layout.
npm ci silently skips devDependencies when NODE_ENV=production is set
in the environment, which broke the build (nest: not found) once
Coolify injected NODE_ENV=production as a build-time var. --include=dev
makes the build stage robust regardless of that env var; the runtime
stage now does its own --omit=dev install instead of copying the build
stage's node_modules wholesale, keeping the final image prod-only.
EXPOSE was 3000 but main.ts defaults PORT to 3001. npm install had no
lockfile/legacy-peer-deps, which now fails on the @nestjs/swagger v8
vs @nestjs/common v11 peer conflict. Also adds .dockerignore so the
build stage's node_modules isn't clobbered by a local one.
Adds tenants/memberships/consent_records tables, a CASL AbilityFactory
keyed on membership role, and a TenantGuard that derives tenant_id from
session only (never client-supplied), per blueprint 8.2/8.3/11.3.
Adds outbox_events + audit_log tables, an OutboxService for transactional
writes, and a Cron-based OutboxDispatcher that publishes pending events
to a BullMQ queue, per blueprint 9.1 (events before intelligence).