SPEC.md and README.md now describe the recommended deploy: an app's
Dockerfile builds FROM the smallwebwaf image, and runit, started by
runsvinit, runs smallwebwaf on :8080 in front of the app on
127.0.0.1:8081, with no setting required. They cover which user each
process runs as, what happens when either exits, the health check, the
ports, the state directory and its volume, the app's trusted proxies,
the new defaults and upaas needing no change, with an example app
Dockerfile in place of the docker-compose examples. Every setting
carries the SWWAF_ prefix, and the spec no longer calls smallwebwaf a
sidecar.
Model: opus-5-5
Initial documents: what smallwebwaf is and why, the proposed feature list, the design spec with the rule file format and the open design questions, and the survey of existing tools.
Model: fable-5-1