Next milestone: production memory under 5 GiB, ready for upaas #6
+2
-2
@@ -79,8 +79,8 @@ RUN chown -R routewatch:routewatch /app
|
|||||||
ENV XDG_DATA_HOME=/var/lib
|
ENV XDG_DATA_HOME=/var/lib
|
||||||
|
|
||||||
# Cap the Go heap at 1.5 GiB so the runtime collects harder before the
|
# Cap the Go heap at 1.5 GiB so the runtime collects harder before the
|
||||||
# container's memory limit is reached. runuser preserves this the way it does
|
# container's memory limit is reached. setpriv in the entrypoint preserves this
|
||||||
# XDG_DATA_HOME above.
|
# the way it does XDG_DATA_HOME above.
|
||||||
ENV GOMEMLIMIT=1536MiB
|
ENV GOMEMLIMIT=1536MiB
|
||||||
|
|
||||||
# Cap glibc's malloc arenas. The SQLite C library allocates and frees millions
|
# Cap glibc's malloc arenas. The SQLite C library allocates and frees millions
|
||||||
|
|||||||
@@ -23,6 +23,11 @@ runs make check on main.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-09-28: `docker stop` no longer kills the daemon 2 seconds after the
|
||||||
|
stop signal: the entrypoint switches to the `routewatch` user with
|
||||||
|
`setpriv` instead of `runuser`, so the daemon receives the signal itself
|
||||||
|
and gets the whole wait `docker stop` allows, up to its own 60-second
|
||||||
|
limit (closes #33)
|
||||||
- 2026-09-28: ready to run under upaas: a set but invalid `PORT`,
|
- 2026-09-28: ready to run under upaas: a set but invalid `PORT`,
|
||||||
`XDG_DATA_HOME` or `MALLOC_ARENA_MAX` stops the start, the health
|
`XDG_DATA_HOME` or `MALLOC_ARENA_MAX` stops the start, the health
|
||||||
check follows `PORT`, README "Running under upaas" section (closes
|
check follows `PORT`, README "Running under upaas" section (closes
|
||||||
|
|||||||
+4
-1
@@ -10,4 +10,7 @@ cd /var/lib/berlin.sneak.app.routewatch
|
|||||||
chown -R routewatch:routewatch .
|
chown -R routewatch:routewatch .
|
||||||
chmod 700 .
|
chmod 700 .
|
||||||
|
|
||||||
exec runuser -u routewatch -- /app/routewatch
|
# setpriv replaces itself with the daemon, so the daemon receives the stop
|
||||||
|
# signal directly. runuser would stay in between and kill the daemon 2 seconds
|
||||||
|
# after passing the signal on.
|
||||||
|
exec setpriv --reuid=routewatch --regid=routewatch --init-groups -- /app/routewatch
|
||||||
|
|||||||
Reference in New Issue
Block a user