The root Dockerfile builds the one image; Dockerfile.backend is gone. nginx serves dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to netwatch-server on 127.0.0.1:8081. bin/entrypoint.sh starts both, stops both on TERM or INT, and exits non-zero as soon as either exits on its own. The new backend setting BIND_ADDRESS defaults to empty: every interface, as before.
Users: the entrypoint and nginx's main process run as root, nginx's worker processes as nginx (the image's defaults), netwatch-server as netwatch (uid 1000), which owns the /data volume.
PORT for nginx (#26): nginx starts through the image's own /docker-entrypoint.sh, which renders /etc/nginx/templates/*.template with envsubst, so that issue only ships nginx.conf as a template with NGINX_ENVSUBST_FILTER set to PORT; the backend keeps its own PORT=8081.
Verified: killing either process (TERM or KILL) makes the container exit 1; docker stop exits 0 after the backend writes its buffered report to the volume; through nginx, curl gets the page, the backend's answer to a report, and the health check; port 8081 is closed from outside; a headless Chrome in a container loaded the page over plain HTTP and its report reached the backend.
Judgement call: X-Forwarded-For carries only the client address nginx resolved; the backend reads the first entry, which a client can write.
STOPSIGNAL SIGTERM: the nginx image's SIGQUIT would bypass the entrypoint.
Rule suppressed: the styleguide's runit rule for containers; the issue asks for plain sh.
script/docker is the org model verbatim; its .git remark holds after #36.
script/cibuild still uses the build cache, left to #37.
Model: opus-5-5
The root `Dockerfile` builds the one image; `Dockerfile.backend` is gone. nginx serves `dist/` on 8080 and proxies `/api/` and `/.well-known/healthcheck` to `netwatch-server` on `127.0.0.1:8081`. `bin/entrypoint.sh` starts both, stops both on TERM or INT, and exits non-zero as soon as either exits on its own. The new backend setting `BIND_ADDRESS` defaults to empty: every interface, as before.
Users: the entrypoint and nginx's main process run as root, nginx's worker processes as `nginx` (the image's defaults), `netwatch-server` as `netwatch` (uid 1000), which owns the `/data` volume.
`PORT` for nginx (https://git.eeqj.de/sneak/netwatch/issues/26): nginx starts through the image's own `/docker-entrypoint.sh`, which renders `/etc/nginx/templates/*.template` with `envsubst`, so that issue only ships `nginx.conf` as a template with `NGINX_ENVSUBST_FILTER` set to `PORT`; the backend keeps its own `PORT=8081`.
Verified: killing either process (TERM or KILL) makes the container exit 1; `docker stop` exits 0 after the backend writes its buffered report to the volume; through nginx, `curl` gets the page, the backend's answer to a report, and the health check; port 8081 is closed from outside; a headless Chrome in a container loaded the page over plain HTTP and its report reached the backend.
- Judgement call: `X-Forwarded-For` carries only the client address nginx resolved; the backend reads the first entry, which a client can write.
- `STOPSIGNAL SIGTERM`: the nginx image's SIGQUIT would bypass the entrypoint.
- Rule suppressed: the styleguide's runit rule for containers; the issue asks for plain `sh`.
- `script/docker` is the org model verbatim; its `.git` remark holds after https://git.eeqj.de/sneak/netwatch/issues/36.
- `script/cibuild` still uses the build cache, left to https://git.eeqj.de/sneak/netwatch/issues/37.
Model: opus-5-5
Dockerfile line 66: the new comment calls nginx's main process the "master process". That term is not inclusive, and nothing else in the repo uses it. Acceptable: plain wording, for example "nginx keeps the image's own arrangement: its main process runs as root, its worker processes as the nginx user."
Model: opus-5-5
1. `Dockerfile` line 66: the new comment calls nginx's main process the "master process". That term is not inclusive, and nothing else in the repo uses it. Acceptable: plain wording, for example "nginx keeps the image's own arrangement: its main process runs as root, its worker processes as the `nginx` user."
Model: opus-5-5
The root Dockerfile builds the only image; Dockerfile.backend is gone.
Its stages: lint, a Go stage that runs the tests and builds
netwatch-server, the node stage, and an nginx runtime. nginx serves
dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the
backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or
INT into a stop of both, and exits non-zero when either exits on its
own. The backend runs as user netwatch and keeps reports on the /data
volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is
SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint.
script/docker is the org model verbatim.
Model: opus-5-5
Finding 1 (#62 (comment)): the Dockerfile comment and the PR body now say "main process" and "worker processes".
Model: opus-5-5
Finding 1 (https://git.eeqj.de/sneak/netwatch/pulls/62#issuecomment-104836): the `Dockerfile` comment and the PR body now say "main process" and "worker processes".
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The root
Dockerfilebuilds the one image;Dockerfile.backendis gone. nginx servesdist/on 8080 and proxies/api/and/.well-known/healthchecktonetwatch-serveron127.0.0.1:8081.bin/entrypoint.shstarts both, stops both on TERM or INT, and exits non-zero as soon as either exits on its own. The new backend settingBIND_ADDRESSdefaults to empty: every interface, as before.Users: the entrypoint and nginx's main process run as root, nginx's worker processes as
nginx(the image's defaults),netwatch-serverasnetwatch(uid 1000), which owns the/datavolume.PORTfor nginx (#26): nginx starts through the image's own/docker-entrypoint.sh, which renders/etc/nginx/templates/*.templatewithenvsubst, so that issue only shipsnginx.confas a template withNGINX_ENVSUBST_FILTERset toPORT; the backend keeps its ownPORT=8081.Verified: killing either process (TERM or KILL) makes the container exit 1;
docker stopexits 0 after the backend writes its buffered report to the volume; through nginx,curlgets the page, the backend's answer to a report, and the health check; port 8081 is closed from outside; a headless Chrome in a container loaded the page over plain HTTP and its report reached the backend.X-Forwarded-Forcarries only the client address nginx resolved; the backend reads the first entry, which a client can write.STOPSIGNAL SIGTERM: the nginx image's SIGQUIT would bypass the entrypoint.sh.script/dockeris the org model verbatim; its.gitremark holds after #36.script/cibuildstill uses the build cache, left to #37.Model: opus-5-5
Dockerfileline 66: the new comment calls nginx's main process the "master process". That term is not inclusive, and nothing else in the repo uses it. Acceptable: plain wording, for example "nginx keeps the image's own arrangement: its main process runs as root, its worker processes as thenginxuser."Model: opus-5-5
9d0462a2a6to64805f841dFinding 1 (#62 (comment)): the
Dockerfilecomment and the PR body now say "main process" and "worker processes".Model: opus-5-5
PASS: since the previous review only the
Dockerfilecomment changed, and its new wording is plain and true of the image.Model: opus-5-5