Let the daemon receive docker stop's signal itself (closes #33)
check / check (push) Successful in 2m49s

entrypoint.sh now switches to the routewatch user with setpriv instead of
runuser. setpriv replaces itself with the daemon, so the daemon gets the stop
signal directly and has its full 60 seconds to shut down; runuser stayed in
between and killed the daemon 2 seconds after passing the signal on. setpriv
keeps the environment, so GOMEMLIMIT, MALLOC_ARENA_MAX and XDG_DATA_HOME still
reach the daemon, and the state directory stays
/var/lib/berlin.sneak.app.routewatch.

Model: opus-5-5
This commit is contained in:
2026-09-28 18:11:11 +00:00
parent f2a9e90625
commit d1f912baae
3 changed files with 10 additions and 3 deletions
+4 -1
View File
@@ -10,4 +10,7 @@ cd /var/lib/berlin.sneak.app.routewatch
chown -R routewatch:routewatch .
chmod 700 .
exec runuser -u routewatch -- /app/routewatch
# setpriv replaces itself with the daemon, so the daemon receives the stop
# signal directly. runuser would stay in between and kill the daemon 2 seconds
# after passing the signal on.
exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch