Build the smallwebwaf image on Ubuntu 26.04 LTS with nixpkgs (closes #34)
The deploy model now builds the image on Ubuntu 26.04 LTS, pinned by digest and moved to the next LTS release when that ships, with Nix and nixpkgs installed. nixpkgs is fixed at one commit of `nixos-26.05`, so an app built on the same image gets the same packages each time. The example Dockerfiles install a package with `nix-env -iA nixpkgs.git` and create the app's user with `useradd`. Nix and runit come from Ubuntu's own packages, `runsvinit` is built from its source, and every `run` script is bash with `set -euo pipefail`. Model: opus-5-5
This commit is contained in:
@@ -147,20 +147,23 @@ For each request `smallwebwaf`:
|
||||
due, and writes the log line.
|
||||
|
||||
A minimal deployment is the app's own Dockerfile, built on the `smallwebwaf`
|
||||
image, with no setting. Beyond its `FROM` line it adds the app's binary, any
|
||||
packages it needs, and the app's runit service, which starts the app as a user
|
||||
of its own, listening on `127.0.0.1:8081`:
|
||||
image, with no setting. That image is built on Ubuntu 26.04 LTS, the newest
|
||||
long-term support release of Ubuntu, pinned by digest, and moves to the next one
|
||||
when it ships. It has nixpkgs installed, so the app adds the packages it needs
|
||||
from nixpkgs. Beyond its `FROM` line the app's Dockerfile adds the app's binary,
|
||||
any packages it needs, and the app's runit service, which starts the app as a
|
||||
user of its own, listening on `127.0.0.1:8081`:
|
||||
|
||||
```dockerfile
|
||||
# The smallwebwaf image, pinned by digest.
|
||||
FROM <registry>/smallwebwaf:<pinned digest>
|
||||
|
||||
# Packages the app needs, if any.
|
||||
RUN apk add --no-cache tzdata
|
||||
# Packages the app needs, if any, from the nixpkgs in the image.
|
||||
RUN nix-env -iA nixpkgs.git
|
||||
|
||||
# The app's binary, and a user of its own to run it.
|
||||
COPY app /usr/local/bin/app
|
||||
RUN adduser -D -H -s /sbin/nologin app
|
||||
RUN useradd --system --no-create-home --shell /usr/sbin/nologin app
|
||||
|
||||
# The app's runit service.
|
||||
COPY --chmod=755 app.run /etc/service/app/run
|
||||
@@ -169,8 +172,9 @@ COPY --chmod=755 app.run /etc/service/app/run
|
||||
with `app.run` beside the Dockerfile, where `--listen` and `--trusted-proxies`
|
||||
stand for the app's own options:
|
||||
|
||||
```sh
|
||||
#!/bin/sh
|
||||
```bash
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
sleep 1
|
||||
exec chpst -u app:app /usr/local/bin/app \
|
||||
--listen 127.0.0.1:8081 \
|
||||
@@ -180,6 +184,10 @@ exec chpst -u app:app /usr/local/bin/app \
|
||||
- The image's entrypoint, `runsvinit`, has runit start `smallwebwaf` and the app
|
||||
side by side, each as its own user, and start either again a second after it
|
||||
exits. Leave out `ENTRYPOINT` and `USER` from the app's Dockerfile.
|
||||
- `nix-env -iA nixpkgs.<name>` installs a package from the nixpkgs in the image,
|
||||
and the app finds it on its `PATH`. That nixpkgs is fixed at one commit, so
|
||||
the same `smallwebwaf` image always gives the app the same packages; newer
|
||||
ones come with a newer `smallwebwaf` image.
|
||||
- Deploy it as you deploy any app, with traefik's labels on this one container
|
||||
pointing at port 8080. upaas needs no change for this.
|
||||
- The app has to trust `127.0.0.1` and `::1` for forwarded headers, besides the
|
||||
|
||||
Reference in New Issue
Block a user