This dashboard is not configured
This variable is read when the dashboard is built, so setting it on the running host is not enough — rebuild with it present.
NEXT_PUBLIC_API_URL— not set — the dashboard has no API to talk to, and no way to sign anybody in.
packages/dashboard/README.md lists it, and explains why the API origin is also written into the page’s Content-Security-Policy.