Settle the open points of the Ubuntu and nixpkgs image (closes #38)
check / check (push) Successful in 2m26s

ca-certificates, nix-bin and runit come from a dated Ubuntu snapshot.
The snapshot service needs HTTPS and the Ubuntu image has no CA
certificates, so that one install uses those of the Go image, pinned by
digest. ca-certificates is installed by name. The image writes
build-users-group = to /etc/nix/nix.conf so root can build without a
daemon. nixpkgs comes from its release file on releases.nixos.org,
checked by SHA-256, and adds about 200 MiB. runsvinit is archived
upstream and is built at a fixed commit with a go.mod made for the
build. The example run scripts put their code in a main function.

Model: opus-5-5
This commit is contained in:
2026-10-03 23:55:58 +00:00
parent 983192ace3
commit 939ff89fc0
2 changed files with 66 additions and 24 deletions
+9 -4
View File
@@ -291,10 +291,15 @@ stand for the app's own options:
```bash
#!/usr/bin/env bash
set -euo pipefail
sleep 1
exec chpst -u app:app /usr/local/bin/app \
--listen 127.0.0.1:8081 \
--trusted-proxies 10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,127.0.0.1/32,::1/128
main() {
sleep 1
exec chpst -u app:app /usr/local/bin/app \
--listen 127.0.0.1:8081 \
--trusted-proxies 10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,127.0.0.1/32,::1/128
}
main "$@"
```
- The image's entrypoint, `runsvinit`, has runit start `smallwebwaf` and the app