docker: run as non-root, add HEALTHCHECK, document upaas deploy (closes #147)
check / check (push) Failing after 1s

The image had never been run. A trial run (fresh named volume, port 8080,
real targets, no notification endpoints) showed it exited at once: Viper
searches the working directory and, with a YAML config type, also matches an
extension-less file named dnswatcher, so the binary at /app/dnswatcher was
parsed as a config file. The binary now lives in /usr/local/bin and the
working directory is the data dir.

The runtime stage also gains an unprivileged dnswatcher user (uid 10001) that
owns /var/lib/dnswatcher, so a fresh named volume inherits writable ownership,
and a Docker HEALTHCHECK that probes /.well-known/healthcheck with busybox
wget. README gains a "Deploying with upaas" section.

Model: opus-4-8
This commit is contained in:
2026-09-21 07:56:04 +00:00
parent b351a2350c
commit df80bc1fb6
3 changed files with 53 additions and 6 deletions
+2
View File
@@ -23,6 +23,8 @@ Rationale, Design, TODO, License, Author) if any are still missing.
# Completed Steps
- 2026-09-21: upaas deploy readiness — runtime image runs as unprivileged
`dnswatcher`, Docker `HEALTHCHECK`, README "Deploying with upaas" (closes #147).
- 2026-09-21: `go mod tidy` dropped the redundant `golang.org/x/sync`
`// indirect` line so `script/bootstrap` leaves a clean tree (#132)
- 2026-08-10: comment-only corrections to `script/bootstrap`,