upaas: health check, settings checked at start, README section (closes #59)
check / check (push) Successful in 14s
check / check (push) Successful in 14s
The image's HEALTHCHECK requests /.well-known/healthcheck through nginx on the port from PORT, so it fails unless both processes answer. The backend reads PORT and DEBUG with strconv instead of viper, which turned a bad PORT into 0 and a bad DEBUG into false. Those, and a BIND_ADDRESS that is not an IP address, now stop the start with an error naming the variable; the TRUSTED_PROXIES error names it too. bin/entrypoint.sh also refuses a container PORT outside 1 to 65535, or 8081, where the backend listens, naming PORT. README.md gains "Running under upaas". Its first-run steps create the host directory owned by uid 1000, so the image changes no ownership. Model: opus-5-5
This commit is contained in:
@@ -77,8 +77,8 @@ func New(
|
||||
return s, nil
|
||||
}
|
||||
|
||||
// parseTrustedProxies converts CIDR strings into prefixes,
|
||||
// failing fast on any malformed entry.
|
||||
// parseTrustedProxies converts the TRUSTED_PROXIES entries into
|
||||
// prefixes, failing fast on any malformed entry.
|
||||
func parseTrustedProxies(cidrs []string) ([]netip.Prefix, error) {
|
||||
prefixes := make([]netip.Prefix, 0, len(cidrs))
|
||||
|
||||
@@ -86,7 +86,7 @@ func parseTrustedProxies(cidrs []string) ([]netip.Prefix, error) {
|
||||
prefix, err := netip.ParsePrefix(cidr)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf(
|
||||
"trusted proxy %q: %w", cidr, err,
|
||||
"TRUSTED_PROXIES %q: %w", cidr, err,
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user