upaas: health check, settings checked at start, README section (closes #59)
check / check (push) Successful in 14s
check / check (push) Successful in 14s
The image's HEALTHCHECK requests /.well-known/healthcheck through nginx on the port from PORT, so it fails unless both processes answer. The backend reads PORT and DEBUG with strconv instead of viper, which turned a bad PORT into 0 and a bad DEBUG into false. Those, and a BIND_ADDRESS that is not an IP address, now stop the start with an error naming the variable; the TRUSTED_PROXIES error names it too. bin/entrypoint.sh also refuses a container PORT outside 1 to 65535, or 8081, where the backend listens, naming PORT. README.md gains "Running under upaas". Its first-run steps create the host directory owned by uid 1000, so the image changes no ownership. Model: opus-5-5
This commit is contained in:
@@ -194,6 +194,46 @@ only inside the container, on `127.0.0.1:8081`. The image:
|
||||
- Writes buffered reports to disk on `docker stop`, and exits non-zero if nginx
|
||||
or the backend exits on its own, so the platform restarts it
|
||||
|
||||
## Running under upaas
|
||||
|
||||
What the [upaas](https://git.eeqj.de/sneak/upaas) app for netwatch needs:
|
||||
|
||||
- **Port:** container port `8080`.
|
||||
- **Volume:** container path `/data`; the reports are kept in `/data/reports`.
|
||||
- **First run:** upaas bind-mounts the host directory it is given and does not
|
||||
create it, and the backend, which runs as uid 1000, does not start unless it
|
||||
can write there. Create the directory, owned by uid 1000, before the first
|
||||
deploy:
|
||||
|
||||
```bash
|
||||
mkdir -p /path/to/data
|
||||
chown 1000:1000 /path/to/data
|
||||
```
|
||||
|
||||
- **Environment variables:** none is required. An empty one counts as unset, and
|
||||
one set to a value netwatch cannot use stops the container at start, with the
|
||||
reason in its log.
|
||||
- `PORT`, default `8080`: the container port, from 1 to 65535. `8081` cannot
|
||||
be used: the backend listens on it inside the container
|
||||
- `REPORTS_PER_MINUTE`, default `60`: reports each client address may send a
|
||||
minute
|
||||
- `DATA_DIR_MAX_BYTES`, default `1073741824` (1 GiB): the most room the
|
||||
report files may take
|
||||
- `CORS_ALLOWED_ORIGINS`, default empty: other origins whose pages may call
|
||||
the API
|
||||
- `DEBUG`, default `false`: debug logging
|
||||
- `DATA_DIR`, default `/data/reports`: leave unset; reports kept outside
|
||||
`/data` do not survive a redeploy
|
||||
- `TRUSTED_PROXIES`, default loopback and RFC1918: leave unset. The
|
||||
backend's only client is nginx, on loopback, which passes on the client
|
||||
address; nginx takes it from `X-Forwarded-For` only from RFC1918
|
||||
addresses.
|
||||
- **Health check:** the image's `HEALTHCHECK` requests
|
||||
`/.well-known/healthcheck` through nginx every 30 seconds, so it fails unless
|
||||
both nginx and the backend answer. upaas reads the container's health 60
|
||||
seconds after a deploy and fails the deploy unless it is `healthy`. The
|
||||
container also stops when either process exits.
|
||||
|
||||
## Browser Compatibility
|
||||
|
||||
Requires a modern browser with ES modules, Fetch API, Canvas API, and CSS custom
|
||||
|
||||
Reference in New Issue
Block a user