Add a Docker HEALTHCHECK and make docker-smoke (closes #111) #130

Merged
clawbot merged 1 commits from issue-111-docker-smoke into next 2026-09-28 12:06:30 +02:00
Collaborator

Implements #111, part of #17.

What changed

  • Dockerfile runtime stage: a HEALTHCHECK probing http://localhost:8080/.well-known/healthcheck.json with busybox wget --spider (interval 30s, timeout 5s, start period 10s, retries 3).
  • script/docker-smoke and make docker-smoke: builds via script/docker, starts the image with a random throwaway PIXA_SIGNING_KEY, and exits 0 only once Docker reports the container healthy within 30 seconds. The container is removed by its ID on any exit, an interrupt included; on failure its log is printed.
  • The Gitea workflow runs it after script/cibuild. It is not part of make check.
  • One line in the README.md Entrypoints section; a TODO.md entry.

Why

Nothing proved the image starts a working service, and without a HEALTHCHECK the container runtime and upaas cannot tell a hung process from a healthy one.

Worth knowing

  • make docker-smoke passed locally. With a deliberately broken ENTRYPOINT (a missing binary, then a missing config file) it failed and left no container behind.
  • The probe URL hardcodes port 8080. If the port becomes configurable (#128 reads PORT), a container started with another PORT reports unhealthy.
  • The script passes --health-interval=1s; the image's 30s interval would otherwise use up the whole wait.

Disclosures

  • Deviation from item 2: the script waits on Docker's health status instead of polling a random published host port. The Gitea job runs in its own container on its own network (runner log of https://git.eeqj.de/sneak/pixa/actions/runs/6691), where a host port is not reachable at localhost, so the workflow step would always fail. No port is published, so none needs to be free.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/pixa/issues/111, part of https://git.eeqj.de/sneak/pixa/issues/17. ## What changed - `Dockerfile` runtime stage: a `HEALTHCHECK` probing `http://localhost:8080/.well-known/healthcheck.json` with busybox `wget --spider` (interval 30s, timeout 5s, start period 10s, retries 3). - `script/docker-smoke` and `make docker-smoke`: builds via `script/docker`, starts the image with a random throwaway `PIXA_SIGNING_KEY`, and exits 0 only once Docker reports the container healthy within 30 seconds. The container is removed by its ID on any exit, an interrupt included; on failure its log is printed. - The Gitea workflow runs it after `script/cibuild`. It is not part of `make check`. - One line in the `README.md` Entrypoints section; a `TODO.md` entry. ## Why Nothing proved the image starts a working service, and without a `HEALTHCHECK` the container runtime and upaas cannot tell a hung process from a healthy one. ## Worth knowing - `make docker-smoke` passed locally. With a deliberately broken `ENTRYPOINT` (a missing binary, then a missing config file) it failed and left no container behind. - The probe URL hardcodes port 8080. If the port becomes configurable (https://git.eeqj.de/sneak/pixa/issues/128 reads `PORT`), a container started with another `PORT` reports unhealthy. - The script passes `--health-interval=1s`; the image's 30s interval would otherwise use up the whole wait. ## Disclosures - Deviation from item 2: the script waits on Docker's health status instead of polling a random published host port. The Gitea job runs in its own container on its own network (runner log of https://git.eeqj.de/sneak/pixa/actions/runs/6691), where a host port is not reachable at `localhost`, so the workflow step would always fail. No port is published, so none needs to be free. Model: opus-5-5
clawbot added the needs-review label 2026-09-28 11:33:40 +02:00
clawbot self-assigned this 2026-09-28 11:33:40 +02:00
clawbot added 1 commit 2026-09-28 11:33:40 +02:00
The runtime stage declares a HEALTHCHECK that probes
/.well-known/healthcheck.json with busybox wget. script/docker-smoke
(make docker-smoke) builds the image with script/docker, starts it with
a random PIXA_SIGNING_KEY, and passes only once Docker reports the
container healthy within 30 seconds; the container is removed on exit
and its log printed on failure. The Gitea workflow runs it after
script/cibuild; it is not part of make check.

It waits on Docker's health status instead of polling a published host
port because the Gitea job runs in its own container on its own
network, where such a port is not reachable at localhost.

Model: opus-5-5
Author
Collaborator

PASS: waiting for Docker's health status is an acceptable stand-in for the host-port poll, because the Gitea job's container cannot reach a host port on localhost.

Model: opus-5-5

PASS: waiting for Docker's health status is an acceptable stand-in for the host-port poll, because the Gitea job's container cannot reach a host port on `localhost`. Model: opus-5-5
clawbot merged commit b7c1226c38 into next 2026-09-28 12:06:30 +02:00
clawbot deleted branch issue-111-docker-smoke 2026-09-28 12:06:30 +02:00
clawbot removed the needs-review label 2026-09-28 12:06:35 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#130