Deploy model: points the spec leaves open, from the review of issue 12 #33

Open
opened 2026-09-29 01:49:01 +02:00 by clawbot · 2 comments
Collaborator

The review of the deploy-model spec, #32 (merged for #12), noticed points the spec leaves open. None blocked it; each is settled here, in SPEC.md, or when milestone 2 (#14) builds the image.

  • The container's health check and the "Ports" paragraph assume SWWAF_LISTEN_ADDR keeps its default :8080. The spec should say what happens when it is changed, or that it must not be.
  • The example run scripts use #!/bin/sh without strict mode. The org style guide asks for #!/usr/bin/env bash with set -euo pipefail; Alpine has no bash until the image installs it, so the image should install it and the examples follow the guide.
  • The spec says a token file readable only by the smallwebwaf user keeps the token from the app, but not how an operator delivers a file with that owner and mode, in general or through upaas.
  • The smallwebwaf run script takes ownership of the state directory; the spec does not say whether files already in it change owner too, which matters for a host directory holding files from an earlier owner.
  • For whoever builds the image: Alpine does not package runsvinit, so the image builds or fetches it; and the image must use Alpine's runit package or set SVDIR, or sv stop finds no services and smallwebwaf is killed without writing its state.

Update: the image is now built on Ubuntu with nixpkgs (#37, for #34). That settles the bash point (Ubuntu ships bash, and the example run scripts use it with set -euo pipefail) and the SVDIR point (Ubuntu's runit looks in /etc/service). runsvinit is still packaged by neither Ubuntu nor nixpkgs; the spec builds it from source. Points for the new base are in #38.

Model: opus-5-5

The review of the deploy-model spec, https://git.eeqj.de/sneak/smallwebwaf/pulls/32 (merged for https://git.eeqj.de/sneak/smallwebwaf/issues/12), noticed points the spec leaves open. None blocked it; each is settled here, in `SPEC.md`, or when milestone 2 (https://git.eeqj.de/sneak/smallwebwaf/issues/14) builds the image. - The container's health check and the "Ports" paragraph assume `SWWAF_LISTEN_ADDR` keeps its default `:8080`. The spec should say what happens when it is changed, or that it must not be. - The example `run` scripts use `#!/bin/sh` without strict mode. The org style guide asks for `#!/usr/bin/env bash` with `set -euo pipefail`; Alpine has no bash until the image installs it, so the image should install it and the examples follow the guide. - The spec says a token file readable only by the `smallwebwaf` user keeps the token from the app, but not how an operator delivers a file with that owner and mode, in general or through upaas. - The `smallwebwaf` `run` script takes ownership of the state directory; the spec does not say whether files already in it change owner too, which matters for a host directory holding files from an earlier owner. - For whoever builds the image: Alpine does not package `runsvinit`, so the image builds or fetches it; and the image must use Alpine's runit package or set `SVDIR`, or `sv stop` finds no services and smallwebwaf is killed without writing its state. Update: the image is now built on Ubuntu with nixpkgs (https://git.eeqj.de/sneak/smallwebwaf/pulls/37, for https://git.eeqj.de/sneak/smallwebwaf/issues/34). That settles the bash point (Ubuntu ships bash, and the example `run` scripts use it with `set -euo pipefail`) and the `SVDIR` point (Ubuntu's runit looks in `/etc/service`). `runsvinit` is still packaged by neither Ubuntu nor nixpkgs; the spec builds it from source. Points for the new base are in https://git.eeqj.de/sneak/smallwebwaf/issues/38. Model: opus-5-5
clawbot self-assigned this 2026-09-29 01:49:01 +02:00
Author
Collaborator

Plan. Docs only, one PR to next changing SPEC.md (and README.md where it repeats the same text). The bash, SVDIR and runsvinit points are settled above; the rest, decided:

  • SWWAF_LISTEN_ADDR may change the port, and its address part stays empty (:9000, never 127.0.0.1:9000), so smallwebwaf keeps listening on every address: traefik reaches it on the container's address and the health check on 127.0.0.1. The image's health check takes its port from SWWAF_LISTEN_ADDR, and traefik's port label must name the same port. The "Ports" paragraph says so, and the README.md bullet repeats it. (Address part added after the first review of #41.)
  • A token file: the operator makes it on the host, owned by uid 65532 (the smallwebwaf user) with mode 0400, and mounts the directory that holds it read-only; the container sees the same owner and mode. For upaas, the worker checks upaas's own README for mounted directories and writes what applies; where it offers none, the spec says the token goes in the plain setting, which the app can read.
  • The smallwebwaf run script makes the state directory and every file in it belong to the smallwebwaf user, so files left by an earlier owner can be read and replaced.

#38 changes the same section and follows once this is on next.

Model: opus-5-5

Plan. Docs only, one PR to `next` changing `SPEC.md` (and `README.md` where it repeats the same text). The bash, `SVDIR` and `runsvinit` points are settled above; the rest, decided: - `SWWAF_LISTEN_ADDR` may change the port, and its address part stays empty (`:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps listening on every address: traefik reaches it on the container's address and the health check on `127.0.0.1`. The image's health check takes its port from `SWWAF_LISTEN_ADDR`, and traefik's port label must name the same port. The "Ports" paragraph says so, and the `README.md` bullet repeats it. (Address part added after the first review of https://git.eeqj.de/sneak/smallwebwaf/pulls/41.) - A token file: the operator makes it on the host, owned by uid 65532 (the `smallwebwaf` user) with mode `0400`, and mounts the directory that holds it read-only; the container sees the same owner and mode. For upaas, the worker checks upaas's own README for mounted directories and writes what applies; where it offers none, the spec says the token goes in the plain setting, which the app can read. - The `smallwebwaf` `run` script makes the state directory and every file in it belong to the `smallwebwaf` user, so files left by an earlier owner can be read and replaced. https://git.eeqj.de/sneak/smallwebwaf/issues/38 changes the same section and follows once this is on `next`. Model: opus-5-5
Author
Collaborator

Built as #41, to next: the three points of the plan comment in SPEC.md, and the README.md bullet on ports.

Model: opus-5-5

Built as https://git.eeqj.de/sneak/smallwebwaf/pulls/41, to `next`: the three points of the plan comment in `SPEC.md`, and the `README.md` bullet on ports. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#33