docker: run as non-root, add health check, document upaas (closes #147)
check / check (push) Successful in 1m4s
check / check (push) Successful in 1m4s
The runtime image runs as uid 10001, which owns /var/lib/dnswatcher. The working directory is /, so config loading finds no .env or dnswatcher config file there; the binary lives in /usr/local/bin. A Docker HEALTHCHECK probes /.well-known/healthcheck every 10 seconds with busybox wget, so the container is healthy well before upaas reads its health at 60 seconds. Startup now fails with an error naming the data directory when it cannot be written, instead of running with every save failing. The check creates the directory if needed and writes and removes the temp file Save uses. README gains "Running under upaas": the prod branch, host directory setup, network and port, environment and health check. Model: opus-5-5
This commit is contained in:
@@ -148,6 +148,11 @@ func New(
|
||||
|
||||
lifecycle.Append(fx.Hook{
|
||||
OnStart: func(_ context.Context) error {
|
||||
err := state.checkDataDirWritable()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
return state.Load()
|
||||
},
|
||||
OnStop: func(_ context.Context) error {
|
||||
@@ -345,3 +350,27 @@ func (s *State) GetCertificateState(
|
||||
|
||||
return cs, ok
|
||||
}
|
||||
|
||||
// checkDataDirWritable creates the data directory if needed, then writes
|
||||
// and removes the temp file that Save uses. It runs at startup so that an
|
||||
// unwritable directory stops the process, instead of the process running
|
||||
// with every save failing and only logged.
|
||||
func (s *State) checkDataDirWritable() error {
|
||||
dir := s.config.DataDir
|
||||
tmpPath := s.config.StatePath() + ".tmp"
|
||||
|
||||
err := os.MkdirAll(dir, dirPermissions)
|
||||
if err == nil {
|
||||
err = os.WriteFile(tmpPath, nil, filePermissions)
|
||||
}
|
||||
|
||||
if err == nil {
|
||||
err = os.Remove(tmpPath)
|
||||
}
|
||||
|
||||
if err != nil {
|
||||
return fmt.Errorf("data directory %s is not writable: %w", dir, err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user