The image apps build FROM, with its health check (closes #45)
check / check (push) Failing after 3s

The Dockerfile's last stage is now the image of "Deployment" in SPEC.md:
Ubuntu 26.04 with ca-certificates, nix-bin and runit from a dated
snapshot whose InRelease files are checked by hash, nixpkgs from its
release file checked by SHA-256, runsvinit built at a fixed commit, and
smallwebwaf as a runit service. smallwebwaf answers
/_smallwebwaf/healthz, and `smallwebwaf healthcheck`, which takes no
further argument, is the image's HEALTHCHECK. script/example-app builds
an app on the image and checks it end to end.

The Nix profile comes last on the PATH: first, busybox from nixpkgs
replaced runit's own runsvdir and sv. SPEC.md is corrected to match
what was built.

Model: opus-5-5
This commit was merged in pull request #57.
This commit is contained in:
2026-10-04 10:05:30 +02:00
parent 0750879e58
commit d4f90dba37
17 changed files with 617 additions and 71 deletions
+20
View File
@@ -0,0 +1,20 @@
# An app built on the smallwebwaf image, as under "Deployment" in
# SPEC.md, which script/example-app builds and checks. The app is
# busybox's web server, from the nixpkgs in the image, serving one page;
# a real app copies in its own binary instead.
#
# A real app names the smallwebwaf image by digest. This one takes the
# image script/example-app has just built, or else the one `make docker`
# builds.
ARG SMALLWEBWAF_IMAGE=smallwebwaf
FROM ${SMALLWEBWAF_IMAGE}
# Packages the app needs, from the nixpkgs in the image.
RUN nix-env -iA nixpkgs.busybox
# The app's page, and a user of its own to run it.
RUN mkdir /var/www && echo 'hello from the example app' > /var/www/index.html
RUN useradd --system --no-create-home --shell /usr/sbin/nologin app
# The app's runit service.
COPY --chmod=755 app.run /etc/service/app/run
+9
View File
@@ -0,0 +1,9 @@
#!/usr/bin/env bash
set -euo pipefail
main() {
sleep 1
exec chpst -u app:app busybox httpd -f -p 127.0.0.1:8081 -h /var/www
}
main "$@"