The image apps build FROM, with its health check (closes #45)
check / check (push) Failing after 3s

The Dockerfile's last stage is now the image of "Deployment" in SPEC.md:
Ubuntu 26.04 with ca-certificates, nix-bin and runit from a dated
snapshot whose InRelease files are checked by hash, nixpkgs from its
release file checked by SHA-256, runsvinit built at a fixed commit, and
smallwebwaf as a runit service. smallwebwaf answers
/_smallwebwaf/healthz, and `smallwebwaf healthcheck`, which takes no
further argument, is the image's HEALTHCHECK. script/example-app builds
an app on the image and checks it end to end.

The Nix profile comes last on the PATH: first, busybox from nixpkgs
replaced runit's own runsvdir and sv. SPEC.md is corrected to match
what was built.

Model: opus-5-5
This commit was merged in pull request #57.
This commit is contained in:
2026-10-04 10:05:30 +02:00
parent 0750879e58
commit d4f90dba37
17 changed files with 617 additions and 71 deletions
+7 -2
View File
@@ -1,8 +1,10 @@
.PHONY: bootstrap setup test lint fmt fmt-check check docker hooks build run
.PHONY: bootstrap setup test lint fmt fmt-check check docker hooks build run \
example-app
# Makefile targets are thin shims; the implementations live in script/
# per the scripts-to-rule-them-all pattern (see the Entrypoints section
# of README.md). build and run are for working on the code by hand.
# of README.md). build and run are for working on the code by hand;
# example-app checks the image with an app built on it.
bootstrap:
@script/bootstrap
@@ -36,3 +38,6 @@ build:
run:
@script/run
example-app:
@script/example-app