Deploy model: listen port, token files, state directory owner (closes #33)
check / check (push) Successful in 2m37s
check / check (push) Successful in 2m37s
SWWAF_LISTEN_ADDR may set another port: the health check takes its port from it, and traefik's port label must name the same one. Its address part stays empty (:9000), so smallwebwaf keeps listening on every address, where traefik and the health check on 127.0.0.1 both reach it. A token file is made on the host owned by uid 65532 with mode 0400 and its directory mounted read-only; through upaas, that directory is one of the app's volume mounts. The run script of smallwebwaf makes the state directory and every file in it belong to the smallwebwaf user. Model: opus-5-5
This commit was merged in pull request #41.
This commit is contained in:
@@ -313,7 +313,12 @@ exec chpst -u app:app /usr/local/bin/app \
|
||||
- Port 8080 is the only one the app must leave free: the health check, the
|
||||
metrics and ban management are all on it, under `/_smallwebwaf/`. The image's
|
||||
health check passes while `smallwebwaf` answers and the app accepts
|
||||
connections.
|
||||
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
|
||||
the app then leaves free instead; the health check follows it, and traefik's
|
||||
labels must point at it. The address part of `SWWAF_LISTEN_ADDR` stays empty
|
||||
(for example `:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps
|
||||
listening on every address: traefik reaches it on the container's address, and
|
||||
the health check on `127.0.0.1`.
|
||||
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
|
||||
there to keep bans and client history when a deploy replaces the container;
|
||||
without one, it still starts.
|
||||
|
||||
Reference in New Issue
Block a user