Settle the open points of the Ubuntu and nixpkgs image (closes #38)
check / check (push) Successful in 2m47s
check / check (push) Successful in 2m47s
ca-certificates, nix-bin and runit come from a dated Ubuntu snapshot no older than the pinned Ubuntu image. The Dockerfile names the SHA-256 hash of each snapshot InRelease file apt uses, and the build checks them before apt-get install, so every package is checked against hashed files. That install uses the Go image's CA certificate file. ca-certificates is installed by name. The image writes build-users-group = to /etc/nix/nix.conf so root can build without a daemon. nixpkgs comes from its release file on releases.nixos.org, checked by SHA-256, and takes about 500 MiB of disk. runsvinit is archived upstream and is built at a fixed commit with a go.mod written for the build. The example run scripts put their code in a main function. Model: opus-5-5
This commit was merged in pull request #42.
This commit is contained in:
@@ -291,10 +291,15 @@ stand for the app's own options:
|
||||
```bash
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
sleep 1
|
||||
exec chpst -u app:app /usr/local/bin/app \
|
||||
--listen 127.0.0.1:8081 \
|
||||
--trusted-proxies 10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,127.0.0.1/32,::1/128
|
||||
|
||||
main() {
|
||||
sleep 1
|
||||
exec chpst -u app:app /usr/local/bin/app \
|
||||
--listen 127.0.0.1:8081 \
|
||||
--trusted-proxies 10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,127.0.0.1/32,::1/128
|
||||
}
|
||||
|
||||
main "$@"
|
||||
```
|
||||
|
||||
- The image's entrypoint, `runsvinit`, has runit start `smallwebwaf` and the app
|
||||
|
||||
Reference in New Issue
Block a user