build: one image, nginx in front of the backend on loopback (closes #52)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
The root Dockerfile builds the only image; Dockerfile.backend is gone. Its stages: lint, a Go stage that runs the tests and builds netwatch-server, the node stage, and an nginx runtime. nginx serves dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or INT into a stop of both, and exits non-zero when either exits on its own. The backend runs as user netwatch and keeps reports on the /data volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint. script/docker is the org model verbatim. Model: opus-5-5
This commit was merged in pull request #62.
This commit is contained in:
Executable
+59
@@ -0,0 +1,59 @@
|
||||
#!/bin/sh
|
||||
# The container's entrypoint: runs netwatch-server and nginx side by
|
||||
# side. TERM or INT stops both, and the container exits 0 if both exit
|
||||
# cleanly. If either exits on its own, the other is stopped too and the
|
||||
# container exits non-zero, so the platform restarts it instead of
|
||||
# leaving it half up.
|
||||
#
|
||||
# No set -e: kill and wait return non-zero here in normal operation.
|
||||
set -u
|
||||
|
||||
# A stop signal is only noted here; the loop below acts on it.
|
||||
stop_requested=""
|
||||
trap 'stop_requested=yes' TERM INT
|
||||
|
||||
# netwatch-server runs as the netwatch user and listens on loopback
|
||||
# only, on a port other than the public one; nginx.conf proxies to this
|
||||
# address. The netwatch user has no login shell, hence -s /bin/sh.
|
||||
# busybox su replaces itself with the command instead of staying on as
|
||||
# its parent, so $! is the server's own PID.
|
||||
BIND_ADDRESS=127.0.0.1 PORT=8081 \
|
||||
su -s /bin/sh netwatch -c 'exec netwatch-server' &
|
||||
backend=$!
|
||||
|
||||
# nginx starts through the nginx image's own entrypoint, which applies
|
||||
# the image's start-up configuration and then replaces itself with
|
||||
# nginx.
|
||||
/docker-entrypoint.sh nginx -g 'daemon off;' &
|
||||
nginx=$!
|
||||
|
||||
running() {
|
||||
kill -0 "$1" 2>/dev/null
|
||||
}
|
||||
|
||||
# POSIX sh cannot wait for whichever of two children exits first, so
|
||||
# look once a second. The shell collects a child that has exited while
|
||||
# it runs sleep, and running() is false for that child from then on.
|
||||
while [ -z "$stop_requested" ] && running "$backend" && running "$nginx"; do
|
||||
sleep 1
|
||||
done
|
||||
|
||||
# Stop both, then wait until neither is left.
|
||||
kill -TERM "$backend" "$nginx" 2>/dev/null
|
||||
while running "$backend" || running "$nginx"; do
|
||||
sleep 1
|
||||
done
|
||||
|
||||
wait "$backend"
|
||||
backend_status=$?
|
||||
wait "$nginx"
|
||||
nginx_status=$?
|
||||
echo "entrypoint: netwatch-server exited $backend_status," \
|
||||
"nginx exited $nginx_status"
|
||||
|
||||
# Success is a requested stop that both processes exited cleanly from.
|
||||
if [ -n "$stop_requested" ] && [ "$backend_status" -eq 0 ] &&
|
||||
[ "$nginx_status" -eq 0 ]; then
|
||||
exit 0
|
||||
fi
|
||||
exit 1
|
||||
Reference in New Issue
Block a user