Deploy model: listen port, token files, state directory owner (closes #33)
check / check (push) Successful in 1m56s

SWWAF_LISTEN_ADDR may set another port: the health check takes its port
from it, and traefik's port label must name the same one. A token file
is made on the host owned by uid 65532 with mode 0400 and its directory
mounted read-only; through upaas, that directory is one of the app's
volume mounts. The run script of smallwebwaf makes the state directory
and every file in it belong to the smallwebwaf user.

Model: opus-5-5
This commit is contained in:
2026-10-03 15:46:20 +00:00
parent d76715b0df
commit 01049aae4e
2 changed files with 36 additions and 21 deletions
+3 -1
View File
@@ -313,7 +313,9 @@ exec chpst -u app:app /usr/local/bin/app \
- Port 8080 is the only one the app must leave free: the health check, the
metrics and ban management are all on it, under `/_smallwebwaf/`. The image's
health check passes while `smallwebwaf` answers and the app accepts
connections.
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
the app then leaves free instead; the health check follows it, and traefik's
labels must point at it.
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
there to keep bans and client history when a deploy replaces the container;
without one, it still starts.