Writes the deployment guide for #89, following the plan in its latest comment.
README.md gains "Deployment", before "Running under upaas": what the reverse proxy must do and what pixa does itself; the state directory's volume, its permissions and what cache_max_bytes counts; the health check for a load balancer; what SIGTERM does and the exit codes; what running outside Docker needs. It links to Routes and Configuration instead of repeating them.
configs/Caddyfile is the example. REPO_POLICIES.md names configs/ for configuration examples. It is one site written without braces, so it needs no indentation and is in caddy fmt form while .editorconfig asks for spaces.
TODO.md: the Completed Steps entry; the two documentation items leave Future Steps.
Disclosures:
Beyond the plan: the proxy must also pass Origin on unchanged, as the form check compares Origin with Host before it looks at Referer.
Beyond the plan: the guide says to set cache_max_bytes, since its default is 75% of the space free at each start, which the cache's own files reduce.
Judgement call: the example refuses /metrics with 404 rather than leaving that line commented out; its comment says to remove the line to read /metrics through Caddy.
Not verified: the Caddyfile was only validated in a Caddy container, not run in front of pixa. That Caddy's defaults never cut off a slow answer from pixa was read from Caddy's documentation and source.
Model: opus-5-5
Writes the deployment guide for https://git.eeqj.de/sneak/pixa/issues/89, following the plan in its latest comment.
- `README.md` gains "Deployment", before "Running under upaas": what the reverse proxy must do and what pixa does itself; the state directory's volume, its permissions and what `cache_max_bytes` counts; the health check for a load balancer; what SIGTERM does and the exit codes; what running outside Docker needs. It links to Routes and Configuration instead of repeating them.
- `configs/Caddyfile` is the example. `REPO_POLICIES.md` names `configs/` for configuration examples. It is one site written without braces, so it needs no indentation and is in `caddy fmt` form while `.editorconfig` asks for spaces.
- `TODO.md`: the Completed Steps entry; the two documentation items leave Future Steps.
Disclosures:
- Beyond the plan: the proxy must also pass `Origin` on unchanged, as the form check compares `Origin` with `Host` before it looks at `Referer`.
- Beyond the plan: the guide says to set `cache_max_bytes`, since its default is 75% of the space free at each start, which the cache's own files reduce.
- Judgement call: the example refuses `/metrics` with 404 rather than leaving that line commented out; its comment says to remove the line to read `/metrics` through Caddy.
- Not verified: the Caddyfile was only validated in a Caddy container, not run in front of pixa. That Caddy's defaults never cut off a slow answer from pixa was read from Caddy's documentation and source.
Model: opus-5-5
PASS45f8c1079939edeec1258c90747dbed226cff477, rebased onto next at ba5a7162231e3493bc8a55f69a4a9b15189f4be6 (the TODO.md conflict resolved locally by keeping both entries, this PR's on top).
Model: opus-5-5
**PASS** `45f8c1079939edeec1258c90747dbed226cff477`, rebased onto `next` at `ba5a7162231e3493bc8a55f69a4a9b15189f4be6` (the `TODO.md` conflict resolved locally by keeping both entries, this PR's on top).
Model: opus-5-5
README.md gains a "Deployment" section: what the reverse proxy in front
of pixa must do (terminate TLS, pass Host, Origin and Referer on
unchanged, set X-Forwarded-For with trusted_proxies to match, wait at
least downstream_timeout, optionally refuse /metrics) and what pixa does
itself; that the state directory needs a persistent volume, what
cache_max_bytes counts and why to set it; the health check for a load
balancer; what SIGTERM does and the exit codes; and what running outside
Docker needs. configs/Caddyfile is the example, as Caddy needs no
settings beyond the host name and pixa's address.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Writes the deployment guide for #89, following the plan in its latest comment.
README.mdgains "Deployment", before "Running under upaas": what the reverse proxy must do and what pixa does itself; the state directory's volume, its permissions and whatcache_max_bytescounts; the health check for a load balancer; what SIGTERM does and the exit codes; what running outside Docker needs. It links to Routes and Configuration instead of repeating them.configs/Caddyfileis the example.REPO_POLICIES.mdnamesconfigs/for configuration examples. It is one site written without braces, so it needs no indentation and is incaddy fmtform while.editorconfigasks for spaces.TODO.md: the Completed Steps entry; the two documentation items leave Future Steps.Disclosures:
Originon unchanged, as the form check comparesOriginwithHostbefore it looks atReferer.cache_max_bytes, since its default is 75% of the space free at each start, which the cache's own files reduce./metricswith 404 rather than leaving that line commented out; its comment says to remove the line to read/metricsthrough Caddy.Model: opus-5-5
PASS
45f8c1079939edeec1258c90747dbed226cff477, rebased ontonextatba5a7162231e3493bc8a55f69a4a9b15189f4be6(theTODO.mdconflict resolved locally by keeping both entries, this PR's on top).Model: opus-5-5
45f8c10799to719bdbec7a