Function
The parsed location manifest, or null when there is none
Store that answers for a key matching no override and no route.
Exact key → store name, for single assets that escape their prefix.
Exact key → declared placement. Outranks every other layer.
One pattern per store reachable at an absolute http(s) URL
next/image rejects any remote host absent from that list with a hard 500,
so placing posters in a bucket has to widen the allowlist too. Deriving it
from the same manifest that routes the content keeps the promise honest:
moving an asset stays a configuration change, never a code change.
Signed stores contribute nothing — their posters are fetched from the app's own origin through the signing endpoint, not from the bucket.
Each pattern is scoped to its store's path prefix rather than the whole host, so adding one bucket does not implicitly allowlist every image on that domain.
The
images.remotePatternsentries a location manifest requires.