build: one image, nginx in front of the backend on loopback (closes #52)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
The root Dockerfile builds the only image; Dockerfile.backend is gone. Its stages: lint, a Go stage that runs the tests and builds netwatch-server, the node stage, and an nginx runtime. nginx serves dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or INT into a stop of both, and exits non-zero when either exits on its own. The backend runs as user netwatch and keeps reports on the /data volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint. script/docker is the org model verbatim. Model: opus-5-5
This commit was merged in pull request #62.
This commit is contained in:
@@ -3,3 +3,9 @@ package server
|
||||
// MaxRequestBodyBytes exposes the router-wide body limit to the
|
||||
// external tests.
|
||||
const MaxRequestBodyBytes = maxRequestBodyBytes
|
||||
|
||||
// ListenAddr exposes the address the server listens on to the
|
||||
// external tests.
|
||||
func (s *Server) ListenAddr() string {
|
||||
return s.newHTTPServer().Addr
|
||||
}
|
||||
|
||||
@@ -2,8 +2,9 @@ package server
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"net"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"time"
|
||||
|
||||
"go.uber.org/fx"
|
||||
@@ -27,7 +28,10 @@ const (
|
||||
// newHTTPServer constructs the http.Server. It performs no I/O
|
||||
// and does not start listening.
|
||||
func (s *Server) newHTTPServer() *http.Server {
|
||||
listenAddr := fmt.Sprintf(":%d", s.params.Config.Port)
|
||||
listenAddr := net.JoinHostPort(
|
||||
s.params.Config.BindAddress,
|
||||
strconv.Itoa(s.params.Config.Port),
|
||||
)
|
||||
|
||||
return &http.Server{
|
||||
Addr: listenAddr,
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
package server_test
|
||||
|
||||
import "testing"
|
||||
|
||||
// TestListenAddress checks that the server listens on BIND_ADDRESS
|
||||
// and PORT, and on port 8080 on every interface when neither is set.
|
||||
// The container image sets both, to keep the backend on loopback
|
||||
// behind nginx.
|
||||
func TestListenAddress(t *testing.T) {
|
||||
tests := []struct {
|
||||
bindAddress string
|
||||
port string
|
||||
want string
|
||||
}{
|
||||
{bindAddress: "", port: "", want: ":8080"},
|
||||
{bindAddress: "127.0.0.1", port: "8081", want: "127.0.0.1:8081"},
|
||||
{bindAddress: "::1", port: "8081", want: "[::1]:8081"},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.want, func(t *testing.T) {
|
||||
// t.Setenv rules out t.Parallel.
|
||||
t.Setenv("BIND_ADDRESS", tt.bindAddress)
|
||||
t.Setenv("PORT", tt.port)
|
||||
|
||||
got := newServer(t).ListenAddr()
|
||||
if got != tt.want {
|
||||
t.Errorf("listen address = %q, want %q", got, tt.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -19,16 +19,14 @@ import (
|
||||
"go.uber.org/fx/fxtest"
|
||||
)
|
||||
|
||||
// TestHealthCheckRejectsOversizeBody sends the health check, which
|
||||
// never reads its body, a body one byte over the limit. Only the
|
||||
// router-wide body limit can reject it.
|
||||
func TestHealthCheckRejectsOversizeBody(t *testing.T) {
|
||||
t.Parallel()
|
||||
// newServer builds a Server from the same constructors as main,
|
||||
// configured from the environment. It is never started, so nothing
|
||||
// listens.
|
||||
func newServer(t *testing.T) *server.Server {
|
||||
t.Helper()
|
||||
|
||||
var srv *server.Server
|
||||
|
||||
// The same constructors as main, never started: SetupRoutes is
|
||||
// called directly, so nothing listens.
|
||||
app := fxtest.New(t,
|
||||
fx.Provide(
|
||||
config.New,
|
||||
@@ -48,6 +46,16 @@ func TestHealthCheckRejectsOversizeBody(t *testing.T) {
|
||||
t.Fatalf("build server: %v", err)
|
||||
}
|
||||
|
||||
return srv
|
||||
}
|
||||
|
||||
// TestHealthCheckRejectsOversizeBody sends the health check, which
|
||||
// never reads its body, a body one byte over the limit. Only the
|
||||
// router-wide body limit can reject it.
|
||||
func TestHealthCheckRejectsOversizeBody(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
srv := newServer(t)
|
||||
srv.SetupRoutes()
|
||||
|
||||
rec := httptest.NewRecorder()
|
||||
|
||||
Reference in New Issue
Block a user