upaas: health check, settings checked at start, README section (closes #59)
check / check (push) Successful in 14s
check / check (push) Successful in 14s
The image's HEALTHCHECK requests /.well-known/healthcheck through nginx on the port from PORT, so it fails unless both processes answer. The backend reads PORT and DEBUG with strconv instead of viper, which turned a bad PORT into 0 and a bad DEBUG into false. Those, and a BIND_ADDRESS that is not an IP address, now stop the start with an error naming the variable; the TRUSTED_PROXIES error names it too. bin/entrypoint.sh also refuses a container PORT outside 1 to 65535, or 8081, where the backend listens, naming PORT. README.md gains "Running under upaas". Its first-run steps create the host directory owned by uid 1000, so the image changes no ownership. Model: opus-5-5
This commit is contained in:
+14
-2
@@ -10,8 +10,9 @@ set -u
|
||||
|
||||
# PORT is the public port nginx listens on, 8080 when unset or empty.
|
||||
# nginx would take a value such as localhost or unix:/tmp/x.sock as an
|
||||
# address and start anyway, so anything but digits stops the container
|
||||
# here, before either process starts.
|
||||
# address and start anyway, and reports a bad port without naming
|
||||
# PORT, so a value that is not a usable port stops the container here,
|
||||
# before either process starts.
|
||||
export PORT="${PORT:-8080}"
|
||||
case "$PORT" in
|
||||
*[!0-9]*)
|
||||
@@ -19,6 +20,17 @@ case "$PORT" in
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
# The length is checked first because, for a number too big for it,
|
||||
# the shell's test prints an error and is false, so the range checks
|
||||
# alone would let it through.
|
||||
if [ "${#PORT}" -gt 5 ] || [ "$PORT" -lt 1 ] || [ "$PORT" -gt 65535 ]; then
|
||||
echo "entrypoint: PORT must be from 1 to 65535, not '$PORT'" >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ "$PORT" -eq 8081 ]; then
|
||||
echo "entrypoint: PORT cannot be 8081, netwatch-server listens there" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# A stop signal is only noted here; the loop below acts on it.
|
||||
stop_requested=""
|
||||
|
||||
Reference in New Issue
Block a user