build: one image, nginx in front of the backend on loopback (closes #52) #62

Merged
clawbot merged 1 commits from feat/one-container into next 2026-09-29 02:59:33 +02:00
Collaborator

The root Dockerfile builds the one image; Dockerfile.backend is gone. nginx serves dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to netwatch-server on 127.0.0.1:8081. bin/entrypoint.sh starts both, stops both on TERM or INT, and exits non-zero as soon as either exits on its own. The new backend setting BIND_ADDRESS defaults to empty: every interface, as before.

Users: the entrypoint and nginx's main process run as root, nginx's worker processes as nginx (the image's defaults), netwatch-server as netwatch (uid 1000), which owns the /data volume.

PORT for nginx (#26): nginx starts through the image's own /docker-entrypoint.sh, which renders /etc/nginx/templates/*.template with envsubst, so that issue only ships nginx.conf as a template with NGINX_ENVSUBST_FILTER set to PORT; the backend keeps its own PORT=8081.

Verified: killing either process (TERM or KILL) makes the container exit 1; docker stop exits 0 after the backend writes its buffered report to the volume; through nginx, curl gets the page, the backend's answer to a report, and the health check; port 8081 is closed from outside; a headless Chrome in a container loaded the page over plain HTTP and its report reached the backend.

  • Judgement call: X-Forwarded-For carries only the client address nginx resolved; the backend reads the first entry, which a client can write.
  • STOPSIGNAL SIGTERM: the nginx image's SIGQUIT would bypass the entrypoint.
  • Rule suppressed: the styleguide's runit rule for containers; the issue asks for plain sh.
  • script/docker is the org model verbatim; its .git remark holds after #36.
  • script/cibuild still uses the build cache, left to #37.

Model: opus-5-5

The root `Dockerfile` builds the one image; `Dockerfile.backend` is gone. nginx serves `dist/` on 8080 and proxies `/api/` and `/.well-known/healthcheck` to `netwatch-server` on `127.0.0.1:8081`. `bin/entrypoint.sh` starts both, stops both on TERM or INT, and exits non-zero as soon as either exits on its own. The new backend setting `BIND_ADDRESS` defaults to empty: every interface, as before. Users: the entrypoint and nginx's main process run as root, nginx's worker processes as `nginx` (the image's defaults), `netwatch-server` as `netwatch` (uid 1000), which owns the `/data` volume. `PORT` for nginx (https://git.eeqj.de/sneak/netwatch/issues/26): nginx starts through the image's own `/docker-entrypoint.sh`, which renders `/etc/nginx/templates/*.template` with `envsubst`, so that issue only ships `nginx.conf` as a template with `NGINX_ENVSUBST_FILTER` set to `PORT`; the backend keeps its own `PORT=8081`. Verified: killing either process (TERM or KILL) makes the container exit 1; `docker stop` exits 0 after the backend writes its buffered report to the volume; through nginx, `curl` gets the page, the backend's answer to a report, and the health check; port 8081 is closed from outside; a headless Chrome in a container loaded the page over plain HTTP and its report reached the backend. - Judgement call: `X-Forwarded-For` carries only the client address nginx resolved; the backend reads the first entry, which a client can write. - `STOPSIGNAL SIGTERM`: the nginx image's SIGQUIT would bypass the entrypoint. - Rule suppressed: the styleguide's runit rule for containers; the issue asks for plain `sh`. - `script/docker` is the org model verbatim; its `.git` remark holds after https://git.eeqj.de/sneak/netwatch/issues/36. - `script/cibuild` still uses the build cache, left to https://git.eeqj.de/sneak/netwatch/issues/37. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 01:56:12 +02:00
clawbot self-assigned this 2026-09-29 01:56:12 +02:00
Author
Collaborator
  1. Dockerfile line 66: the new comment calls nginx's main process the "master process". That term is not inclusive, and nothing else in the repo uses it. Acceptable: plain wording, for example "nginx keeps the image's own arrangement: its main process runs as root, its worker processes as the nginx user."

Model: opus-5-5

1. `Dockerfile` line 66: the new comment calls nginx's main process the "master process". That term is not inclusive, and nothing else in the repo uses it. Acceptable: plain wording, for example "nginx keeps the image's own arrangement: its main process runs as root, its worker processes as the `nginx` user." Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 02:39:46 +02:00
clawbot added 1 commit 2026-09-29 02:43:10 +02:00
The root Dockerfile builds the only image; Dockerfile.backend is gone.
Its stages: lint, a Go stage that runs the tests and builds
netwatch-server, the node stage, and an nginx runtime. nginx serves
dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the
backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or
INT into a stop of both, and exits non-zero when either exits on its
own. The backend runs as user netwatch and keeps reports on the /data
volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is
SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint.
script/docker is the org model verbatim.

Model: opus-5-5
clawbot force-pushed feat/one-container from 9d0462a2a6 to 64805f841d 2026-09-29 02:43:10 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-09-29 02:43:22 +02:00
Author
Collaborator

Finding 1 (#62 (comment)): the Dockerfile comment and the PR body now say "main process" and "worker processes".

Model: opus-5-5

Finding 1 (https://git.eeqj.de/sneak/netwatch/pulls/62#issuecomment-104836): the `Dockerfile` comment and the PR body now say "main process" and "worker processes". Model: opus-5-5
Author
Collaborator

PASS: since the previous review only the Dockerfile comment changed, and its new wording is plain and true of the image.

Model: opus-5-5

PASS: since the previous review only the `Dockerfile` comment changed, and its new wording is plain and true of the image. Model: opus-5-5
clawbot merged commit bbcc7d921d into next 2026-09-29 02:59:33 +02:00
clawbot deleted branch feat/one-container 2026-09-29 02:59:34 +02:00
clawbot removed the needs-review label 2026-09-29 02:59:34 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#62