Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1dace858e9 |
@@ -1156,12 +1156,12 @@ The image holds:
|
||||
- Ubuntu 26.04 LTS, the newest long-term support release of Ubuntu, pinned by
|
||||
digest. The image moves to the next LTS release when that ships.
|
||||
- Three packages from Ubuntu, `ca-certificates`, `nix-bin` and `runit`,
|
||||
installed from a dated snapshot of Ubuntu's archive (see "Packages from
|
||||
Ubuntu" below). The Ubuntu image has no CA certificates, and they come with
|
||||
`nix-bin` only because a library it uses recommends them, so `ca-certificates`
|
||||
is installed by name. Without it Nix cannot download packages, and
|
||||
`smallwebwaf`, unable to reach GeoJS, would count every visitor as coming from
|
||||
an unknown country.
|
||||
installed from a dated snapshot of Ubuntu's archive and checked by hash (see
|
||||
"Packages from Ubuntu" below). The Ubuntu image has no CA certificates, and
|
||||
they come with `nix-bin` only because a library it uses recommends them, so
|
||||
`ca-certificates` is installed by name. Without it Nix cannot download
|
||||
packages, and `smallwebwaf`, unable to reach GeoJS, would count every visitor
|
||||
as coming from an unknown country.
|
||||
- Nix, the package manager, from Ubuntu's own `nix-bin` package, and nixpkgs,
|
||||
the collection of packages Nix installs from, fixed at one commit (see
|
||||
"Packages from nixpkgs" below). Root uses Nix directly, and no Nix daemon runs
|
||||
@@ -1173,11 +1173,11 @@ The image holds:
|
||||
nor nixpkgs packages `runsvinit`, so the image builds it from its source
|
||||
(`github.com/peterbourgon/runsvinit`) at a fixed commit hash. Its repository
|
||||
is archived and has not changed since 2015, and its last tag is `v2.0.0`. It
|
||||
has no `go.mod`, which Go needs to build it, so the build writes one; since
|
||||
`runsvinit` uses only Go's standard library, that file names nothing else.
|
||||
`runsvinit` starts runit's `runsvdir`, which starts a `runsv` for each
|
||||
directory under `/etc/service`; each `runsv` runs the `run` script in its
|
||||
directory, and runs it again whenever it exits. Ubuntu's runit looks for
|
||||
has no `go.mod`, and `go build` of its directory needs one, so the build
|
||||
writes one; since `runsvinit` uses only Go's standard library, that file names
|
||||
nothing else. `runsvinit` starts runit's `runsvdir`, which starts a `runsv`
|
||||
for each directory under `/etc/service`; each `runsv` runs the `run` script in
|
||||
its directory, and runs it again whenever it exits. Ubuntu's runit looks for
|
||||
services in `/etc/service` too, so when `docker stop` has `runsvinit` stop
|
||||
each service with runit's `sv`, `sv` finds it.
|
||||
- The `smallwebwaf` binary, and a user of its own, `smallwebwaf` (uid and gid
|
||||
@@ -1249,12 +1249,21 @@ Packages from Ubuntu: the image installs `ca-certificates`, `nix-bin` and
|
||||
given moment, rather than from the archive itself, whose packages change with
|
||||
every update. The image's Dockerfile names that moment, in apt's
|
||||
`--snapshot 20261001T000000Z` form, on both `apt-get update` and
|
||||
`apt-get install`, so the same Dockerfile always installs the same files, which
|
||||
apt checks against the archive's signature as usual. The snapshot service is
|
||||
`apt-get install`. That moment is never earlier than the date of the pinned
|
||||
Ubuntu image, since packages from an older snapshot can need older versions of
|
||||
packages the Ubuntu image already holds, and it moves forward whenever that
|
||||
image's digest does. `apt-get update` keeps the snapshot's `InRelease` files,
|
||||
which apt checks against the archive's signature, in `/var/lib/apt/lists/`; each
|
||||
lists the SHA-256 hash of the package lists it covers, and each package list the
|
||||
hash of every package in it. The Dockerfile also names the SHA-256 hash of each
|
||||
`InRelease` file apt uses, and the build checks them after `apt-get update` and
|
||||
before `apt-get install`, so every package apt installs is checked, through
|
||||
those files, against hashes the Dockerfile names. The snapshot service is
|
||||
reached over HTTPS, and the Ubuntu image has no CA certificates of its own, so
|
||||
this one install uses those of the Go image that `smallwebwaf` is built in,
|
||||
which is pinned by digest too: apt's `Acquire::https::CaInfo` option names that
|
||||
file.
|
||||
image's CA certificate file, `/etc/ssl/certs/ca-certificates.crt`, copied into
|
||||
the build.
|
||||
|
||||
Packages from nixpkgs: nixpkgs is fixed at one commit of its newest release
|
||||
branch, `nixos-26.05` today. For each commit of the branch that has passed its
|
||||
@@ -1267,12 +1276,13 @@ before unpacking it. nixpkgs is set up for root under the name `nixpkgs`, so the
|
||||
app's Dockerfile installs a package with `nix-env -iA nixpkgs.<name>`, and
|
||||
whatever it installs is on the `PATH` of every service. Because nixpkgs stays at
|
||||
that commit, an app built on the same `smallwebwaf` image gets the same packages
|
||||
each time it is built. Unpacked, nixpkgs adds about 200 MiB to the image, and
|
||||
each package an app installs from it adds its own size, with everything it
|
||||
depends on. A newer commit of the branch, with its security fixes, comes with a
|
||||
newer `smallwebwaf` image, as do Ubuntu's own fixes; an app takes them by
|
||||
changing the digest in its `FROM` line. When nixpkgs makes its next release,
|
||||
every six months, the image moves to that release's branch.
|
||||
each time it is built. Unpacked, nixpkgs takes about 500 MiB of disk, more on
|
||||
some filesystems such as ZFS, and each package an app installs from it adds its
|
||||
own size, with everything it depends on. A newer commit of the branch, with its
|
||||
security fixes, comes with a newer `smallwebwaf` image, as do Ubuntu's own
|
||||
fixes; an app takes them by changing the digest in its `FROM` line. When nixpkgs
|
||||
makes its next release, every six months, the image moves to that release's
|
||||
branch.
|
||||
|
||||
The two processes:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user