Compare commits

..
1 Commits
Author SHA1 Message Date
sneak 0cc4bf0cb7 Deploy model: listen port, token files, state directory owner (closes #33)
check / check (push) Successful in 2m28s
SWWAF_LISTEN_ADDR may set another port: the health check takes its port
from it, and traefik's port label must name the same one. Its address
part stays empty (:9000), so smallwebwaf keeps listening on every
address, where traefik and the health check on 127.0.0.1 both reach it.
A token file is made on the host owned by uid 65532 with mode 0400 and
its directory mounted read-only; through upaas, that directory is one of
the app's volume mounts. The run script of smallwebwaf makes the state
directory and every file in it belong to the smallwebwaf user.

Model: opus-5-5
2026-10-03 23:36:07 +00:00
2 changed files with 11 additions and 5 deletions
+4 -1
View File
@@ -315,7 +315,10 @@ exec chpst -u app:app /usr/local/bin/app \
health check passes while `smallwebwaf` answers and the app accepts health check passes while `smallwebwaf` answers and the app accepts
connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which connections. `SWWAF_LISTEN_ADDR` can move `smallwebwaf` to another port, which
the app then leaves free instead; the health check follows it, and traefik's the app then leaves free instead; the health check follows it, and traefik's
labels must point at it. labels must point at it. The address part of `SWWAF_LISTEN_ADDR` stays empty
(for example `:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps
listening on every address: traefik reaches it on the container's address, and
the health check on `127.0.0.1`.
- `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume - `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`. Mount a volume
there to keep bans and client history when a deploy replaces the container; there to keep bans and client history when a deploy replaces the container;
without one, it still starts. without one, it still starts.
+7 -4
View File
@@ -1273,10 +1273,13 @@ its health check, metrics and ban management are all on that listener, under
`/_smallwebwaf/` (see "Admin endpoints"). `SWWAF_LISTEN_ADDR` may set another `/_smallwebwaf/` (see "Admin endpoints"). `SWWAF_LISTEN_ADDR` may set another
port: the image's health check takes its port from that setting, and traefik's port: the image's health check takes its port from that setting, and traefik's
port label (`traefik.http.services.<name>.loadbalancer.server.port`) must name port label (`traefik.http.services.<name>.loadbalancer.server.port`) must name
the same port. The app must leave that port free. It listens on `127.0.0.1:8081` the same port, and the app must leave that port free. The address part of
only, so that nothing outside the container reaches it except through `SWWAF_LISTEN_ADDR` stays empty (for example `:9000`, never `127.0.0.1:9000`),
`smallwebwaf`: an app that listens on every address can be reached around so `smallwebwaf` keeps listening on every address: traefik reaches it on the
`smallwebwaf` by anything that reaches the container. container's address, and the health check on `127.0.0.1`. The app listens on
`127.0.0.1:8081` only, so that nothing outside the container reaches it except
through `smallwebwaf`: an app that listens on every address can be reached
around `smallwebwaf` by anything that reaches the container.
State: `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf` State: `smallwebwaf` keeps its state files in `/var/lib/smallwebwaf`
(`SWWAF_STATE_DIR`), a directory of its own beside the app's data, which the app (`SWWAF_STATE_DIR`), a directory of its own beside the app's data, which the app