Build the smallwebwaf image on Ubuntu 26.04 LTS with nixpkgs (closes #34)

The deploy model now builds the image on Ubuntu 26.04 LTS, pinned by digest
and moved to the next LTS release when that ships, with Nix and nixpkgs
installed. nixpkgs is fixed at one commit of `nixos-26.05`, so an app built on
the same image gets the same packages each time. The example Dockerfiles
install a package with `nix-env -iA nixpkgs.git` and create the app's user
with `useradd`. Nix and runit come from Ubuntu's own packages, `runsvinit` is
built from its source, and every `run` script is bash with
`set -euo pipefail`.

Model: opus-5-5
This commit is contained in:
2026-09-29 00:31:51 +00:00
parent 7be4314f55
commit 9462144f33
2 changed files with 66 additions and 30 deletions
+16 -8
View File
@@ -147,20 +147,23 @@ For each request `smallwebwaf`:
due, and writes the log line.
A minimal deployment is the app's own Dockerfile, built on the `smallwebwaf`
image, with no setting. Beyond its `FROM` line it adds the app's binary, any
packages it needs, and the app's runit service, which starts the app as a user
of its own, listening on `127.0.0.1:8081`:
image, with no setting. That image is built on Ubuntu 26.04 LTS, the newest
long-term support release of Ubuntu, pinned by digest, and moves to the next one
when it ships. It has nixpkgs installed, so the app adds the packages it needs
from nixpkgs. Beyond its `FROM` line the app's Dockerfile adds the app's binary,
any packages it needs, and the app's runit service, which starts the app as a
user of its own, listening on `127.0.0.1:8081`:
```dockerfile
# The smallwebwaf image, pinned by digest.
FROM <registry>/smallwebwaf:<pinned digest>
# Packages the app needs, if any.
RUN apk add --no-cache tzdata
# Packages the app needs, if any, from the nixpkgs in the image.
RUN nix-env -iA nixpkgs.git
# The app's binary, and a user of its own to run it.
COPY app /usr/local/bin/app
RUN adduser -D -H -s /sbin/nologin app
RUN useradd --system --no-create-home --shell /usr/sbin/nologin app
# The app's runit service.
COPY --chmod=755 app.run /etc/service/app/run
@@ -169,8 +172,9 @@ COPY --chmod=755 app.run /etc/service/app/run
with `app.run` beside the Dockerfile, where `--listen` and `--trusted-proxies`
stand for the app's own options:
```sh
#!/bin/sh
```bash
#!/usr/bin/env bash
set -euo pipefail
sleep 1
exec chpst -u app:app /usr/local/bin/app \
--listen 127.0.0.1:8081 \
@@ -180,6 +184,10 @@ exec chpst -u app:app /usr/local/bin/app \
- The image's entrypoint, `runsvinit`, has runit start `smallwebwaf` and the app
side by side, each as its own user, and start either again a second after it
exits. Leave out `ENTRYPOINT` and `USER` from the app's Dockerfile.
- `nix-env -iA nixpkgs.<name>` installs a package from the nixpkgs in the image,
and the app finds it on its `PATH`. That nixpkgs is fixed at one commit, so
the same `smallwebwaf` image always gives the app the same packages; newer
ones come with a newer `smallwebwaf` image.
- Deploy it as you deploy any app, with traefik's labels on this one container
pointing at port 8080. upaas needs no change for this.
- The app has to trust `127.0.0.1` and `::1` for forwarded headers, besides the