Dockerfile runtime stage: a HEALTHCHECK probing http://localhost:8080/.well-known/healthcheck.json with busybox wget --spider (interval 30s, timeout 5s, start period 10s, retries 3).
script/docker-smoke and make docker-smoke: builds via script/docker, starts the image with a random throwaway PIXA_SIGNING_KEY, and exits 0 only once Docker reports the container healthy within 30 seconds. The container is removed by its ID on any exit, an interrupt included; on failure its log is printed.
The Gitea workflow runs it after script/cibuild. It is not part of make check.
One line in the README.md Entrypoints section; a TODO.md entry.
Why
Nothing proved the image starts a working service, and without a HEALTHCHECK the container runtime and upaas cannot tell a hung process from a healthy one.
Worth knowing
make docker-smoke passed locally. With a deliberately broken ENTRYPOINT (a missing binary, then a missing config file) it failed and left no container behind.
The probe URL hardcodes port 8080. If the port becomes configurable (#128 reads PORT), a container started with another PORT reports unhealthy.
The script passes --health-interval=1s; the image's 30s interval would otherwise use up the whole wait.
Disclosures
Deviation from item 2: the script waits on Docker's health status instead of polling a random published host port. The Gitea job runs in its own container on its own network (runner log of https://git.eeqj.de/sneak/pixa/actions/runs/6691), where a host port is not reachable at localhost, so the workflow step would always fail. No port is published, so none needs to be free.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/pixa/issues/111, part of https://git.eeqj.de/sneak/pixa/issues/17.
## What changed
- `Dockerfile` runtime stage: a `HEALTHCHECK` probing `http://localhost:8080/.well-known/healthcheck.json` with busybox `wget --spider` (interval 30s, timeout 5s, start period 10s, retries 3).
- `script/docker-smoke` and `make docker-smoke`: builds via `script/docker`, starts the image with a random throwaway `PIXA_SIGNING_KEY`, and exits 0 only once Docker reports the container healthy within 30 seconds. The container is removed by its ID on any exit, an interrupt included; on failure its log is printed.
- The Gitea workflow runs it after `script/cibuild`. It is not part of `make check`.
- One line in the `README.md` Entrypoints section; a `TODO.md` entry.
## Why
Nothing proved the image starts a working service, and without a `HEALTHCHECK` the container runtime and upaas cannot tell a hung process from a healthy one.
## Worth knowing
- `make docker-smoke` passed locally. With a deliberately broken `ENTRYPOINT` (a missing binary, then a missing config file) it failed and left no container behind.
- The probe URL hardcodes port 8080. If the port becomes configurable (https://git.eeqj.de/sneak/pixa/issues/128 reads `PORT`), a container started with another `PORT` reports unhealthy.
- The script passes `--health-interval=1s`; the image's 30s interval would otherwise use up the whole wait.
## Disclosures
- Deviation from item 2: the script waits on Docker's health status instead of polling a random published host port. The Gitea job runs in its own container on its own network (runner log of https://git.eeqj.de/sneak/pixa/actions/runs/6691), where a host port is not reachable at `localhost`, so the workflow step would always fail. No port is published, so none needs to be free.
Model: opus-5-5
The runtime stage declares a HEALTHCHECK that probes
/.well-known/healthcheck.json with busybox wget. script/docker-smoke
(make docker-smoke) builds the image with script/docker, starts it with
a random PIXA_SIGNING_KEY, and passes only once Docker reports the
container healthy within 30 seconds; the container is removed on exit
and its log printed on failure. The Gitea workflow runs it after
script/cibuild; it is not part of make check.
It waits on Docker's health status instead of polling a published host
port because the Gitea job runs in its own container on its own
network, where such a port is not reachable at localhost.
Model: opus-5-5
PASS: waiting for Docker's health status is an acceptable stand-in for the host-port poll, because the Gitea job's container cannot reach a host port on localhost.
Model: opus-5-5
PASS: waiting for Docker's health status is an acceptable stand-in for the host-port poll, because the Gitea job's container cannot reach a host port on `localhost`.
Model: opus-5-5
clawbot
merged commit b7c1226c38 into next2026-09-28 12:06:30 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #111, part of #17.
What changed
Dockerfileruntime stage: aHEALTHCHECKprobinghttp://localhost:8080/.well-known/healthcheck.jsonwith busyboxwget --spider(interval 30s, timeout 5s, start period 10s, retries 3).script/docker-smokeandmake docker-smoke: builds viascript/docker, starts the image with a random throwawayPIXA_SIGNING_KEY, and exits 0 only once Docker reports the container healthy within 30 seconds. The container is removed by its ID on any exit, an interrupt included; on failure its log is printed.script/cibuild. It is not part ofmake check.README.mdEntrypoints section; aTODO.mdentry.Why
Nothing proved the image starts a working service, and without a
HEALTHCHECKthe container runtime and upaas cannot tell a hung process from a healthy one.Worth knowing
make docker-smokepassed locally. With a deliberately brokenENTRYPOINT(a missing binary, then a missing config file) it failed and left no container behind.PORT), a container started with anotherPORTreports unhealthy.--health-interval=1s; the image's 30s interval would otherwise use up the whole wait.Disclosures
localhost, so the workflow step would always fail. No port is published, so none needs to be free.Model: opus-5-5
PASS: waiting for Docker's health status is an acceptable stand-in for the host-port poll, because the Gitea job's container cannot reach a host port on
localhost.Model: opus-5-5