Container makes its data directory usable itself (closes #42)
check / check (push) Successful in 8s
check / check (push) Successful in 8s
sneak's standing rule: the container makes its data directory usable itself, with no step on the host. entrypoint.sh now creates /var/lib/berlin.sneak.app.routewatch if it is missing and stops the start when any step fails (set -euo pipefail); before, a failed cd went on to change the ownership of whatever directory the script was in, and a failed chown still started the daemon. Taking ownership of the directory and switching to the routewatch user through setpriv are unchanged. The README's upaas volume line now says only which path to mount. The empty-directory and other-uid cases were run by hand on the built image with upaas-style bind mounts, not added as an automated test. Model: opus-5-5
This commit was merged in pull request #44.
This commit is contained in:
@@ -235,9 +235,7 @@ with the goroutine count and Go memory figures.
|
||||
What the [upaas](https://git.eeqj.de/sneak/upaas) app needs:
|
||||
|
||||
- Container port: `8080`.
|
||||
- Volume: one, at container path `/var/lib/berlin.sneak.app.routewatch`. upaas
|
||||
does not create the host directory, so create it before the first deploy. The
|
||||
entrypoint takes ownership of it, so a root-owned directory works.
|
||||
- Volume: one, at container path `/var/lib/berlin.sneak.app.routewatch`.
|
||||
- Environment: nothing is required. Leave `XDG_DATA_HOME`, `GOMEMLIMIT` and
|
||||
`MALLOC_ARENA_MAX` at the image's values. `DEBUG=routewatch` is optional and
|
||||
adds the `System stats` memory line to the log.
|
||||
|
||||
Reference in New Issue
Block a user