# An app built on the smallwebwaf image, as under "Deployment" in
# SPEC.md, which script/example-app builds and checks. The app is
# busybox's web server, from the nixpkgs in the image, serving one page;
# a real app copies in its own binary instead.
#
# A real app names the smallwebwaf image by digest. This one takes the
# image script/example-app has just built, or else the one `make docker`
# builds.
ARG SMALLWEBWAF_IMAGE=smallwebwaf
FROM ${SMALLWEBWAF_IMAGE}

# Packages the app needs, from the nixpkgs in the image.
RUN nix-env -iA nixpkgs.busybox

# The app's page, and a user of its own to run it.
RUN mkdir /var/www && echo 'hello from the example app' > /var/www/index.html
RUN useradd --system --no-create-home --shell /usr/sbin/nologin app

# The app's runit service.
COPY --chmod=755 app.run /etc/service/app/run
