build: one image, nginx in front of the backend on loopback (closes #52)
check / check (push) Successful in 10s

The root Dockerfile builds the only image; Dockerfile.backend is gone.
Its stages: lint, a Go stage that runs the tests and builds
netwatch-server, the node stage, and an nginx runtime. nginx serves
dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the
backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or
INT into a stop of both, and exits non-zero when either exits on its
own. The backend runs as user netwatch and keeps reports on the /data
volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is
SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint.
script/docker is the org model verbatim.

Model: opus-5-5
This commit is contained in:
2026-09-29 00:40:30 +00:00
committed by sneak
parent de4e86c433
commit 64805f841d
21 changed files with 280 additions and 101 deletions
+4
View File
@@ -33,6 +33,7 @@ type Params struct {
// Config holds the resolved application configuration.
type Config struct {
BindAddress string
DataDir string
Debug bool
MetricsPassword string
@@ -62,6 +63,8 @@ func New(
viper.SetDefault("DATA_DIR", "./data/reports")
viper.SetDefault("DEBUG", "false")
// An empty BIND_ADDRESS listens on every interface.
viper.SetDefault("BIND_ADDRESS", "")
viper.SetDefault("PORT", "8080")
viper.SetDefault("SENTRY_DSN", "")
viper.SetDefault("METRICS_USERNAME", "")
@@ -78,6 +81,7 @@ func New(
}
s := &Config{
BindAddress: viper.GetString("BIND_ADDRESS"),
DataDir: viper.GetString("DATA_DIR"),
Debug: viper.GetBool("DEBUG"),
MetricsPassword: viper.GetString("METRICS_PASSWORD"),