Let the daemon receive docker stop's signal itself (closes #33) #35
+2
-2
@@ -79,8 +79,8 @@ RUN chown -R routewatch:routewatch /app
|
||||
ENV XDG_DATA_HOME=/var/lib
|
||||
|
||||
# Cap the Go heap at 1.5 GiB so the runtime collects harder before the
|
||||
# container's memory limit is reached. runuser preserves this the way it does
|
||||
# XDG_DATA_HOME above.
|
||||
# container's memory limit is reached. setpriv in the entrypoint preserves this
|
||||
# the way it does XDG_DATA_HOME above.
|
||||
ENV GOMEMLIMIT=1536MiB
|
||||
|
||||
# Cap glibc's malloc arenas. The SQLite C library allocates and frees millions
|
||||
|
||||
@@ -23,6 +23,11 @@ runs make check on main.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-28: `docker stop` no longer kills the daemon 2 seconds after the
|
||||
stop signal: the entrypoint switches to the `routewatch` user with
|
||||
`setpriv` instead of `runuser`, so the daemon receives the signal itself
|
||||
and gets the whole wait `docker stop` allows, up to its own 60-second
|
||||
limit (closes #33)
|
||||
- 2026-09-28: ready to run under upaas: a set but invalid `PORT`,
|
||||
`XDG_DATA_HOME` or `MALLOC_ARENA_MAX` stops the start, the health
|
||||
check follows `PORT`, README "Running under upaas" section (closes
|
||||
|
||||
+4
-1
@@ -10,4 +10,7 @@ cd /var/lib/berlin.sneak.app.routewatch
|
||||
chown -R routewatch:routewatch .
|
||||
chmod 700 .
|
||||
|
||||
exec runuser -u routewatch -- /app/routewatch
|
||||
# setpriv replaces itself with the daemon, so the daemon receives the stop
|
||||
# signal directly. runuser would stay in between and kill the daemon 2 seconds
|
||||
# after passing the signal on.
|
||||
exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch
|
||||
|
||||
Reference in New Issue
Block a user