Commit Graph
2 Commits
Author SHA1 Message Date
clawbot e0fa31341f nginx: listen on PORT, default 8080; server_tokens off (closes #26)
check / check (push) Successful in 11s
nginx.conf is now a template the nginx image renders into conf.d at
container start. bin/entrypoint.sh gives nginx PORT, 8080 when unset or
empty, and limits the rendering to PORT with NGINX_ENVSUBST_FILTER, so
$uri, $host and every other nginx variable pass through unchanged. A
PORT nginx cannot listen on stops the container non-zero.
server_tokens off drops the version from the Server header and error
pages. script/frontend-viewport-test renders the template the same way.
EXPOSE still documents 8080; the backend stays on 127.0.0.1:8081.

Model: opus-5-5
2026-09-29 01:44:32 +00:00
clawbot bbcc7d921d build: one image, nginx in front of the backend on loopback (closes #52)
check / check (push) Successful in 12s
The root Dockerfile builds the only image; Dockerfile.backend is gone.
Its stages: lint, a Go stage that runs the tests and builds
netwatch-server, the node stage, and an nginx runtime. nginx serves
dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the
backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or
INT into a stop of both, and exits non-zero when either exits on its
own. The backend runs as user netwatch and keeps reports on the /data
volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is
SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint.
script/docker is the org model verbatim.

Model: opus-5-5
2026-09-29 02:59:33 +02:00