Build the smallwebwaf image on the latest Ubuntu LTS with nixpkgs (closes #34)
The smallwebwaf image is now built on the newest Ubuntu LTS release, 26.04 today, pinned by digest and moved to the next LTS when that ships, with Nix and nixpkgs installed, as sneak ruled. nixpkgs is pinned to one commit of its newest release branch with a hash the build checks, so an app's build gives the same packages each time. The example app Dockerfiles add a package from nixpkgs and create the app's user with useradd, and every run script is bash with set -euo pipefail, as the style guide asks. The new base settles two of the Alpine points of the deploy follow-up. Building the image stays with milestone 2. Model: opus-5-5
This commit was merged in pull request #37.
This commit is contained in:
@@ -147,20 +147,23 @@ For each request `smallwebwaf`:
|
||||
due, and writes the log line.
|
||||
|
||||
A minimal deployment is the app's own Dockerfile, built on the `smallwebwaf`
|
||||
image, with no setting. Beyond its `FROM` line it adds the app's binary, any
|
||||
packages it needs, and the app's runit service, which starts the app as a user
|
||||
of its own, listening on `127.0.0.1:8081`:
|
||||
image, with no setting. That image is built on Ubuntu 26.04 LTS, the newest
|
||||
long-term support release of Ubuntu, pinned by digest, and moves to the next one
|
||||
when it ships. It has nixpkgs installed, so the app adds the packages it needs
|
||||
from nixpkgs. Beyond its `FROM` line the app's Dockerfile adds the app's binary,
|
||||
any packages it needs, and the app's runit service, which starts the app as a
|
||||
user of its own, listening on `127.0.0.1:8081`:
|
||||
|
||||
```dockerfile
|
||||
# The smallwebwaf image, pinned by digest.
|
||||
FROM <registry>/smallwebwaf:<pinned digest>
|
||||
|
||||
# Packages the app needs, if any.
|
||||
RUN apk add --no-cache tzdata
|
||||
# Packages the app needs, if any, from the nixpkgs in the image.
|
||||
RUN nix-env -iA nixpkgs.git
|
||||
|
||||
# The app's binary, and a user of its own to run it.
|
||||
COPY app /usr/local/bin/app
|
||||
RUN adduser -D -H -s /sbin/nologin app
|
||||
RUN useradd --system --no-create-home --shell /usr/sbin/nologin app
|
||||
|
||||
# The app's runit service.
|
||||
COPY --chmod=755 app.run /etc/service/app/run
|
||||
@@ -169,8 +172,9 @@ COPY --chmod=755 app.run /etc/service/app/run
|
||||
with `app.run` beside the Dockerfile, where `--listen` and `--trusted-proxies`
|
||||
stand for the app's own options:
|
||||
|
||||
```sh
|
||||
#!/bin/sh
|
||||
```bash
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
sleep 1
|
||||
exec chpst -u app:app /usr/local/bin/app \
|
||||
--listen 127.0.0.1:8081 \
|
||||
@@ -180,6 +184,10 @@ exec chpst -u app:app /usr/local/bin/app \
|
||||
- The image's entrypoint, `runsvinit`, has runit start `smallwebwaf` and the app
|
||||
side by side, each as its own user, and start either again a second after it
|
||||
exits. Leave out `ENTRYPOINT` and `USER` from the app's Dockerfile.
|
||||
- `nix-env -iA nixpkgs.<name>` installs a package from the nixpkgs in the image,
|
||||
and the app finds it on its `PATH`. That nixpkgs is fixed at one commit, so
|
||||
the same `smallwebwaf` image always gives the app the same packages; newer
|
||||
ones come with a newer `smallwebwaf` image.
|
||||
- Deploy it as you deploy any app, with traefik's labels on this one container
|
||||
pointing at port 8080. upaas needs no change for this.
|
||||
- The app has to trust `127.0.0.1` and `::1` for forwarded headers, besides the
|
||||
|
||||
Reference in New Issue
Block a user