Commit Graph
3 Commits
Author SHA1 Message Date
sneak d1f912baae Let the daemon receive docker stop's signal itself (closes #33)
check / check (push) Successful in 2m49s
entrypoint.sh now switches to the routewatch user with setpriv instead of
runuser. setpriv replaces itself with the daemon, so the daemon gets the stop
signal directly and has its full 60 seconds to shut down; runuser stayed in
between and killed the daemon 2 seconds after passing the signal on. setpriv
keeps the environment, so GOMEMLIMIT, MALLOC_ARENA_MAX and XDG_DATA_HOME still
reach the daemon, and the state directory stays
/var/lib/berlin.sneak.app.routewatch.

Model: opus-5-5
2026-09-28 18:11:11 +00:00
clawbot f2a9e90625 Refuse invalid settings at start, health check follows PORT (closes #31)
check / check (push) Successful in 3m17s
A set but invalid PORT (anything but plain digits from 1 to 65535) or a relative XDG_DATA_HOME now stops the start before the database opens; before, a bad PORT left the daemon running without HTTP. entrypoint.sh refuses a MALLOC_ARENA_MAX that is not a positive whole number, since glibc ignores a bad one silently. The HEALTHCHECK probes the port PORT names, 8080 when unset. PORT is now read in internal/config, so server.New takes the config.

The README gives the real Linux state directory, lists XDG_DATA_HOME, and adds "Running under upaas": port, volume, environment, the 5g memory limit and the health check.

Unverified: the 5g memory limit could not be exercised on the build host.

Model: opus-5-5
2026-09-28 20:08:42 +02:00
sneak c6fa2b0fbd Fix container to run app as routewatch user
Use runuser to drop privileges and execute the app as the routewatch
user (uid 1000). Fix data directory permissions at runtime since host
mounts may have incorrect ownership.
2025-12-31 16:17:59 -08:00