1 Commits
Author SHA1 Message Date
clawbot f26e892152 upaas: health check, settings checked at start, README section (closes #59)
check / check (push) Successful in 14s
The image's HEALTHCHECK requests /.well-known/healthcheck through
nginx on the port from PORT, so it fails unless both processes answer.
The backend reads PORT and DEBUG with strconv instead of viper, which
turned a bad PORT into 0 and a bad DEBUG into false. Those, and a
BIND_ADDRESS that is not an IP address, now stop the start with an
error naming the variable; the TRUSTED_PROXIES error names it too.
bin/entrypoint.sh also refuses a container PORT outside 1 to 65535,
or 8081, where the backend listens, naming PORT. README.md gains
"Running under upaas". Its first-run steps create the host directory
owned by uid 1000, so the image changes no ownership.

Model: opus-5-5
2026-09-29 03:58:07 +00:00
3 changed files with 20 additions and 6 deletions
+2 -1
View File
@@ -213,7 +213,8 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for netwatch needs:
- **Environment variables:** none is required. An empty one counts as unset, and - **Environment variables:** none is required. An empty one counts as unset, and
one set to a value netwatch cannot use stops the container at start, with the one set to a value netwatch cannot use stops the container at start, with the
reason in its log. reason in its log.
- `PORT`, default `8080`: the container port - `PORT`, default `8080`: the container port, from 1 to 65535. `8081` cannot
be used: the backend listens on it inside the container
- `REPORTS_PER_MINUTE`, default `60`: reports each client address may send a - `REPORTS_PER_MINUTE`, default `60`: reports each client address may send a
minute minute
- `DATA_DIR_MAX_BYTES`, default `1073741824` (1 GiB): the most room the - `DATA_DIR_MAX_BYTES`, default `1073741824` (1 GiB): the most room the
+4 -3
View File
@@ -29,9 +29,10 @@ latest run passes.
`DEBUG` as false: those, and a `BIND_ADDRESS` that is not an IP address, stop `DEBUG` as false: those, and a `BIND_ADDRESS` that is not an IP address, stop
it from starting with an error naming the variable, as the limits, it from starting with an error naming the variable, as the limits,
`CORS_ALLOWED_ORIGINS` and, now by name, `TRUSTED_PROXIES` already did. `CORS_ALLOWED_ORIGINS` and, now by name, `TRUSTED_PROXIES` already did.
`README.md` has a "Running under upaas" section, whose first-run steps create `bin/entrypoint.sh` also refuses a `PORT` outside 1 to 65535, and `8081`,
the host directory for `/data` owned by uid 1000; the image does not change where the backend listens inside the container, naming `PORT`. `README.md` has
its owner a "Running under upaas" section, whose first-run steps create the host
directory for `/data` owned by uid 1000; the image does not change its owner
- 2026-09-29: nginx listens on `PORT` (issue #26), 8080 when unset or empty: the - 2026-09-29: nginx listens on `PORT` (issue #26), 8080 when unset or empty: the
nginx image renders `nginx.conf` as a template at container start, filling in nginx image renders `nginx.conf` as a template at container start, filling in
`PORT` and no other variable. `bin/entrypoint.sh` refuses to start when `PORT` `PORT` and no other variable. `bin/entrypoint.sh` refuses to start when `PORT`
+14 -2
View File
@@ -10,8 +10,9 @@ set -u
# PORT is the public port nginx listens on, 8080 when unset or empty. # PORT is the public port nginx listens on, 8080 when unset or empty.
# nginx would take a value such as localhost or unix:/tmp/x.sock as an # nginx would take a value such as localhost or unix:/tmp/x.sock as an
# address and start anyway, so anything but digits stops the container # address and start anyway, and reports a bad port without naming
# here, before either process starts. # PORT, so a value that is not a usable port stops the container here,
# before either process starts.
export PORT="${PORT:-8080}" export PORT="${PORT:-8080}"
case "$PORT" in case "$PORT" in
*[!0-9]*) *[!0-9]*)
@@ -19,6 +20,17 @@ case "$PORT" in
exit 1 exit 1
;; ;;
esac esac
# The length is checked first because, for a number too big for it,
# the shell's test prints an error and is false, so the range checks
# alone would let it through.
if [ "${#PORT}" -gt 5 ] || [ "$PORT" -lt 1 ] || [ "$PORT" -gt 65535 ]; then
echo "entrypoint: PORT must be from 1 to 65535, not '$PORT'" >&2
exit 1
fi
if [ "$PORT" -eq 8081 ]; then
echo "entrypoint: PORT cannot be 8081, netwatch-server listens there" >&2
exit 1
fi
# A stop signal is only noted here; the loop below acts on it. # A stop signal is only noted here; the loop below acts on it.
stop_requested="" stop_requested=""