Container makes its data directory usable itself (closes #42)
check / check (push) Successful in 8s
check / check (push) Successful in 8s
sneak's standing rule: the container makes its data directory usable itself, with no step on the host. entrypoint.sh now creates /var/lib/berlin.sneak.app.routewatch if it is missing and stops the start when any step fails (set -euo pipefail); before, a failed cd went on to change the ownership of whatever directory the script was in, and a failed chown still started the daemon. Taking ownership of the directory and switching to the routewatch user through setpriv are unchanged. The README's upaas volume line now says only which path to mount. The empty-directory and other-uid cases were run by hand on the built image with upaas-style bind mounts, not added as an automated test. Model: opus-5-5
This commit was merged in pull request #44.
This commit is contained in:
@@ -235,9 +235,7 @@ with the goroutine count and Go memory figures.
|
|||||||
What the [upaas](https://git.eeqj.de/sneak/upaas) app needs:
|
What the [upaas](https://git.eeqj.de/sneak/upaas) app needs:
|
||||||
|
|
||||||
- Container port: `8080`.
|
- Container port: `8080`.
|
||||||
- Volume: one, at container path `/var/lib/berlin.sneak.app.routewatch`. upaas
|
- Volume: one, at container path `/var/lib/berlin.sneak.app.routewatch`.
|
||||||
does not create the host directory, so create it before the first deploy. The
|
|
||||||
entrypoint takes ownership of it, so a root-owned directory works.
|
|
||||||
- Environment: nothing is required. Leave `XDG_DATA_HOME`, `GOMEMLIMIT` and
|
- Environment: nothing is required. Leave `XDG_DATA_HOME`, `GOMEMLIMIT` and
|
||||||
`MALLOC_ARENA_MAX` at the image's values. `DEBUG=routewatch` is optional and
|
`MALLOC_ARENA_MAX` at the image's values. `DEBUG=routewatch` is optional and
|
||||||
adds the `System stats` memory line to the log.
|
adds the `System stats` memory line to the log.
|
||||||
|
|||||||
@@ -28,6 +28,9 @@ The other open issue is https://git.eeqj.de/sneak/routewatch/issues/30.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-09-29: the entrypoint creates the data directory if it is missing and
|
||||||
|
stops the start if a step fails; README "Running under upaas" no longer
|
||||||
|
asks for the host directory to be created first (closes #42)
|
||||||
- 2026-09-29: `.dockerignore` keeps `.git`, local build output, local
|
- 2026-09-29: `.dockerignore` keeps `.git`, local build output, local
|
||||||
databases and `.env` out of the Docker build context, and so out of the
|
databases and `.env` out of the Docker build context, and so out of the
|
||||||
source archive in the image (closes #39)
|
source archive in the image (closes #39)
|
||||||
|
|||||||
@@ -1,4 +1,5 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
# glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here.
|
# glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here.
|
||||||
if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then
|
if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then
|
||||||
@@ -6,6 +7,9 @@ if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; t
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Give the data directory to the routewatch user before the daemon starts,
|
||||||
|
# whether it is missing, an empty root-owned mount, or holds another uid's files.
|
||||||
|
mkdir -p /var/lib/berlin.sneak.app.routewatch
|
||||||
cd /var/lib/berlin.sneak.app.routewatch
|
cd /var/lib/berlin.sneak.app.routewatch
|
||||||
chown -R routewatch:routewatch .
|
chown -R routewatch:routewatch .
|
||||||
chmod 700 .
|
chmod 700 .
|
||||||
|
|||||||
Reference in New Issue
Block a user