upaas: health check, settings checked at start, README section (closes #59) #67

Merged
clawbot merged 1 commits from feat/upaas-ready into next 2026-09-29 06:39:12 +02:00
Collaborator

Closes #59.

  • Dockerfile gains a HEALTHCHECK requesting /.well-known/healthcheck through nginx on the port from PORT, so it fails unless both processes answer.

  • bin/entrypoint.sh also refuses a container PORT outside 1 to 65535, or 8081, where the backend listens inside the container, with a message naming PORT. A value longer than five digits is refused before the range check, because the shell's test lets a number too big for it through.

  • The backend reads PORT and DEBUG with strconv instead of viper, which turned a bad PORT into 0 (a random port) and a bad DEBUG into false. Those, and a BIND_ADDRESS that is not an IP address, now stop the start with an error naming the variable; the TRUSTED_PROXIES error names it too. The existing checks moved into Config.check to keep New within the linter's length limit.

  • README.md gains "Running under upaas": container port, volume and first-run steps, each environment variable with its default, the health check. Its PORT line says 8081 cannot be used.

  • Judgement call: the first-run steps give the host directory to uid 1000, instead of the entrypoint doing it at start: no code, and the image never changes the owner of host files.

  • Judgement call: the README leaves out SENTRY_DSN, METRICS_USERNAME and METRICS_PASSWORD, which the backend reads but never uses.

Model: opus-5-5

Closes https://git.eeqj.de/sneak/netwatch/issues/59. - `Dockerfile` gains a `HEALTHCHECK` requesting `/.well-known/healthcheck` through nginx on the port from `PORT`, so it fails unless both processes answer. - `bin/entrypoint.sh` also refuses a container `PORT` outside 1 to 65535, or `8081`, where the backend listens inside the container, with a message naming `PORT`. A value longer than five digits is refused before the range check, because the shell's `test` lets a number too big for it through. - The backend reads `PORT` and `DEBUG` with `strconv` instead of viper, which turned a bad `PORT` into 0 (a random port) and a bad `DEBUG` into false. Those, and a `BIND_ADDRESS` that is not an IP address, now stop the start with an error naming the variable; the `TRUSTED_PROXIES` error names it too. The existing checks moved into `Config.check` to keep `New` within the linter's length limit. - `README.md` gains "Running under upaas": container port, volume and first-run steps, each environment variable with its default, the health check. Its `PORT` line says `8081` cannot be used. - Judgement call: the first-run steps give the host directory to uid 1000, instead of the entrypoint doing it at start: no code, and the image never changes the owner of host files. - Judgement call: the README leaves out `SENTRY_DSN`, `METRICS_USERNAME` and `METRICS_PASSWORD`, which the backend reads but never uses. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 05:34:22 +02:00
clawbot self-assigned this 2026-09-29 05:34:22 +02:00
Author
Collaborator
  1. bin/entrypoint.sh: a container PORT made of digits that is still not a usable port gets past the entrypoint's check: 0, anything above 65535, or 8081, which the backend already listens on inside the container. The start then fails with an nginx message ("invalid port", or "Address in use" for 8081) that does not name PORT. The plan in #59 (comment) requires a message naming the variable. The PR body discloses this as a judgement call, but that call departs from the plan. Acceptable: the entrypoint's PORT check also refuses a value outside 1 to 65535, and 8081, with a message naming PORT, and the PORT line in the "Running under upaas" section says 8081 cannot be used.

Model: opus-5-5

1. `bin/entrypoint.sh`: a container `PORT` made of digits that is still not a usable port gets past the entrypoint's check: `0`, anything above `65535`, or `8081`, which the backend already listens on inside the container. The start then fails with an nginx message ("invalid port", or "Address in use" for `8081`) that does not name `PORT`. The plan in https://git.eeqj.de/sneak/netwatch/issues/59#issuecomment-103928 requires a message naming the variable. The PR body discloses this as a judgement call, but that call departs from the plan. Acceptable: the entrypoint's `PORT` check also refuses a value outside 1 to 65535, and `8081`, with a message naming `PORT`, and the `PORT` line in the "Running under upaas" section says `8081` cannot be used. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 05:55:43 +02:00
clawbot added 1 commit 2026-09-29 06:03:40 +02:00
The image's HEALTHCHECK requests /.well-known/healthcheck through
nginx on the port from PORT, so it fails unless both processes answer.
The backend reads PORT and DEBUG with strconv instead of viper, which
turned a bad PORT into 0 and a bad DEBUG into false. Those, and a
BIND_ADDRESS that is not an IP address, now stop the start with an
error naming the variable; the TRUSTED_PROXIES error names it too.
bin/entrypoint.sh also refuses a container PORT outside 1 to 65535,
or 8081, where the backend listens, naming PORT. README.md gains
"Running under upaas". Its first-run steps create the host directory
owned by uid 1000, so the image changes no ownership.

Model: opus-5-5
clawbot force-pushed feat/upaas-ready from ad35798dee to f26e892152 2026-09-29 06:03:40 +02:00 Compare
clawbot added needs-review and removed needs-rework labels 2026-09-29 06:03:58 +02:00
Author
Collaborator
  1. Fixed: bin/entrypoint.sh refuses a PORT outside 1 to 65535, or 8081, naming PORT; the README PORT line says 8081 cannot be used.

Model: opus-5-5

1. Fixed: `bin/entrypoint.sh` refuses a `PORT` outside 1 to 65535, or `8081`, naming `PORT`; the README `PORT` line says `8081` cannot be used. Model: opus-5-5
Author
Collaborator

PASS: The image health check, the settings checked at start (now including a PORT outside 1 to 65535 or equal to 8081), and the "Running under upaas" section meet #59 and its plan.

Model: opus-5-5

PASS: The image health check, the settings checked at start (now including a `PORT` outside 1 to 65535 or equal to `8081`), and the "Running under upaas" section meet https://git.eeqj.de/sneak/netwatch/issues/59 and its plan. Model: opus-5-5
clawbot merged commit d2f219ca19 into next 2026-09-29 06:39:12 +02:00
clawbot deleted branch feat/upaas-ready 2026-09-29 06:39:13 +02:00
clawbot removed the needs-review label 2026-09-29 06:39:13 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/netwatch#67