1 Commits
Author SHA1 Message Date
sneak fbc021e21b docker: run as non-root, add health check, document upaas (closes #147)
check / check (push) Successful in 1m4s
The runtime image runs as uid 10001, which owns /var/lib/dnswatcher. The
working directory is /, so config loading finds no .env or dnswatcher
config file there; the binary lives in /usr/local/bin. A Docker
HEALTHCHECK probes /.well-known/healthcheck every 10 seconds with busybox
wget, so the container is healthy well before upaas reads its health at
60 seconds.

Startup now fails with an error naming the data directory when it cannot
be written, instead of running with every save failing. The check creates
the directory if needed and writes and removes the temp file Save uses.

README gains "Running under upaas": the prod branch, host directory
setup, network and port, environment and health check.

Model: opus-5-5
2026-09-28 17:12:56 +00:00
+2 -2
View File
@@ -64,8 +64,8 @@ USER dnswatcher
EXPOSE 8080
# busybox wget (already in alpine) probes the health endpoint. The first
# probe runs one interval after start. upaas reads the container's health
# busybox wget (already in alpine) probes the health endpoint every 10
# seconds, so the container is healthy well before upaas reads its health
# 60 seconds after a deploy and fails the deploy unless it is healthy.
HEALTHCHECK --interval=10s --timeout=5s --start-period=10s --retries=3 \
CMD wget -q -O /dev/null "http://127.0.0.1:${PORT:-8080}/.well-known/healthcheck" || exit 1