build: one image, nginx in front of the backend on loopback (closes #52)
check / check (push) Successful in 48s

The root Dockerfile builds the only image; Dockerfile.backend is gone.
Its stages: lint, a Go stage that runs the tests and builds
netwatch-server, the node stage, and an nginx runtime. nginx serves
dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the
backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or
INT into a stop of both, and exits non-zero when either exits on its
own. The backend runs as user netwatch and keeps reports on the /data
volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is
SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint.
script/docker is the org model verbatim.

Model: opus-5-5
This commit is contained in:
2026-09-28 23:51:57 +00:00
parent de4e86c433
commit 9d0462a2a6
21 changed files with 280 additions and 101 deletions
+4 -6
View File
@@ -1,9 +1,8 @@
#!/bin/sh
# script/cibuild: run the CI build. It builds both images: the frontend
# from Dockerfile and the backend from Dockerfile.backend. Each runs its
# half of the checks as build steps, so a successful cibuild implies the
# whole repo is green. This is the only build step the Gitea workflow
# runs.
# script/cibuild: run the CI build: build the one image from Dockerfile,
# whose stages run the checks as build steps (the backend's fmt-check,
# lint and tests, and the frontend's test, lint and fmt-check). This is
# the only build step the Gitea workflow runs.
set -eu
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
@@ -11,7 +10,6 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
main() {
cd "$ROOT"
timeout 300 docker build .
timeout 300 docker build -f Dockerfile.backend .
}
main "$@"