Write the deployment guide and an example Caddy config (closes #89) #182

Merged
clawbot merged 1 commits from issue-89-deployment-guide into next 2026-10-04 15:08:04 +02:00
Collaborator

Writes the deployment guide for #89, following the plan in its latest comment.

  • README.md gains "Deployment", before "Running under upaas": what the reverse proxy must do and what pixa does itself; the state directory's volume, its permissions and what cache_max_bytes counts; the health check for a load balancer; what SIGTERM does and the exit codes; what running outside Docker needs. It links to Routes and Configuration instead of repeating them.
  • configs/Caddyfile is the example. REPO_POLICIES.md names configs/ for configuration examples. It is one site written without braces, so it needs no indentation and is in caddy fmt form while .editorconfig asks for spaces.
  • TODO.md: the Completed Steps entry; the two documentation items leave Future Steps.

Disclosures:

  • Beyond the plan: the proxy must also pass Origin on unchanged, as the form check compares Origin with Host before it looks at Referer.
  • Beyond the plan: the guide says to set cache_max_bytes, since its default is 75% of the space free at each start, which the cache's own files reduce.
  • Judgement call: the example refuses /metrics with 404 rather than leaving that line commented out; its comment says to remove the line to read /metrics through Caddy.
  • Not verified: the Caddyfile was only validated in a Caddy container, not run in front of pixa. That Caddy's defaults never cut off a slow answer from pixa was read from Caddy's documentation and source.

Model: opus-5-5

Writes the deployment guide for https://git.eeqj.de/sneak/pixa/issues/89, following the plan in its latest comment. - `README.md` gains "Deployment", before "Running under upaas": what the reverse proxy must do and what pixa does itself; the state directory's volume, its permissions and what `cache_max_bytes` counts; the health check for a load balancer; what SIGTERM does and the exit codes; what running outside Docker needs. It links to Routes and Configuration instead of repeating them. - `configs/Caddyfile` is the example. `REPO_POLICIES.md` names `configs/` for configuration examples. It is one site written without braces, so it needs no indentation and is in `caddy fmt` form while `.editorconfig` asks for spaces. - `TODO.md`: the Completed Steps entry; the two documentation items leave Future Steps. Disclosures: - Beyond the plan: the proxy must also pass `Origin` on unchanged, as the form check compares `Origin` with `Host` before it looks at `Referer`. - Beyond the plan: the guide says to set `cache_max_bytes`, since its default is 75% of the space free at each start, which the cache's own files reduce. - Judgement call: the example refuses `/metrics` with 404 rather than leaving that line commented out; its comment says to remove the line to read `/metrics` through Caddy. - Not verified: the Caddyfile was only validated in a Caddy container, not run in front of pixa. That Caddy's defaults never cut off a slow answer from pixa was read from Caddy's documentation and source. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 13:39:40 +02:00
clawbot self-assigned this 2026-10-04 13:39:40 +02:00
Author
Collaborator

PASS 45f8c1079939edeec1258c90747dbed226cff477, rebased onto next at ba5a7162231e3493bc8a55f69a4a9b15189f4be6 (the TODO.md conflict resolved locally by keeping both entries, this PR's on top).

Model: opus-5-5

**PASS** `45f8c1079939edeec1258c90747dbed226cff477`, rebased onto `next` at `ba5a7162231e3493bc8a55f69a4a9b15189f4be6` (the `TODO.md` conflict resolved locally by keeping both entries, this PR's on top). Model: opus-5-5
clawbot added needs-rebase and removed needs-review labels 2026-10-04 14:39:41 +02:00
clawbot added 1 commit 2026-10-04 14:53:58 +02:00
README.md gains a "Deployment" section: what the reverse proxy in front
of pixa must do (terminate TLS, pass Host, Origin and Referer on
unchanged, set X-Forwarded-For with trusted_proxies to match, wait at
least downstream_timeout, optionally refuse /metrics) and what pixa does
itself; that the state directory needs a persistent volume, what
cache_max_bytes counts and why to set it; the health check for a load
balancer; what SIGTERM does and the exit codes; and what running outside
Docker needs. configs/Caddyfile is the example, as Caddy needs no
settings beyond the host name and pixa's address.

Model: opus-5-5
clawbot force-pushed issue-89-deployment-guide from 45f8c10799 to 719bdbec7a 2026-10-04 14:53:58 +02:00 Compare
clawbot added needs-review and removed needs-rebase labels 2026-10-04 14:54:01 +02:00
clawbot merged commit be6c715b36 into next 2026-10-04 15:08:04 +02:00
clawbot deleted branch issue-89-deployment-guide 2026-10-04 15:08:05 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#182