docker: run as non-root, add health check, document upaas #156

Merged
clawbot merged 1 commits from issue-147-upaas-deploy-readiness into next 2026-09-28 20:13:38 +02:00
1 Commits
Author SHA1 Message Date
sneak daef29e432 docker: run as non-root, add health check, document upaas (closes #147)
check / check (push) Successful in 53s
The runtime image runs as uid 10001, which owns /var/lib/dnswatcher. The
working directory is /, so config loading finds no .env or dnswatcher
config file there; the binary lives in /usr/local/bin. A Docker
HEALTHCHECK probes /.well-known/healthcheck every 10 seconds with busybox
wget, well inside the 60 seconds upaas waits.

Startup now fails with an error naming the data directory when it cannot
be written, instead of running with every save failing. The check creates
the directory if needed and writes and removes the temp file Save uses;
tests cover the create and the write failing.

README gains "Running under upaas": the prod branch, host directory
setup, network and port, environment and health check.

Model: opus-5-5
2026-09-28 17:51:31 +00:00