Part 3 of 3 of milestone 2, #14, and the part that makes it ready for production. The order of the three parts is on that issue's plan comment. One PR to next, after part 2 is on next.
What it builds
The container image of "Deployment" in SPEC.md, as the last stage of the Dockerfile, so a plain docker build . builds it and cannot without the lint and test phases passing:
Everything "Deployment" says the image holds: the pinned Ubuntu base; ca-certificates, nix-bin and runit from the dated Ubuntu snapshot, checked against the InRelease hashes the Dockerfile names; nixpkgs from its release file, checked by SHA-256, with build-users-group = in /etc/nix/nix.conf; runsvinit built at a fixed commit; smallwebwaf as a runit service with its run script; the HEALTHCHECK.
GET /_smallwebwaf/healthz answered as "Admin endpoints" says, since the health check calls it; the other admin endpoints come later.
The hash check names the snapshot's own InRelease files one by one. apt-get update --snapshot also stores the live archive's InRelease files in /var/lib/apt/lists/, and their hashes change whenever the archive updates, so a check of every file there breaks the build daily (noted by the review of #42).
An example app image built FROM the smallwebwaf image, as the Dockerfile example in "Deployment", that serves a request through smallwebwaf, run by a make target or script/ entrypoint, removing every container it starts.
README.md documents the deploy, and loses its "until milestone 2 brings its image" text.
Not in this part: anything written to disk, the other admin endpoints.
Definition of done
The example app image serves a request through smallwebwaf; the health check passes; sv stop lets smallwebwaf stop in order.
Where a fact in SPEC.md turns out wrong when built (a path, a hash, a package), the PR fixes SPEC.md too and says so in one line.
make check green; one PR to next, passed by a reviewer who did not write it; the landing commit title ends with this issue's (closes #N).
Model: opus-5-5
Part 3 of 3 of milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14, and the part that makes it ready for production. The order of the three parts is on that issue's plan comment. One PR to `next`, after part 2 is on `next`.
## What it builds
The container image of "Deployment" in `SPEC.md`, as the last stage of the `Dockerfile`, so a plain `docker build .` builds it and cannot without the lint and test phases passing:
- Everything "Deployment" says the image holds: the pinned Ubuntu base; `ca-certificates`, `nix-bin` and `runit` from the dated Ubuntu snapshot, checked against the `InRelease` hashes the `Dockerfile` names; nixpkgs from its release file, checked by SHA-256, with `build-users-group =` in `/etc/nix/nix.conf`; `runsvinit` built at a fixed commit; `smallwebwaf` as a runit service with its `run` script; the `HEALTHCHECK`.
- `GET /_smallwebwaf/healthz` answered as "Admin endpoints" says, since the health check calls it; the other admin endpoints come later.
- The hash check names the snapshot's own `InRelease` files one by one. `apt-get update --snapshot` also stores the live archive's `InRelease` files in `/var/lib/apt/lists/`, and their hashes change whenever the archive updates, so a check of every file there breaks the build daily (noted by the review of https://git.eeqj.de/sneak/smallwebwaf/pulls/42).
- An example app image built `FROM` the smallwebwaf image, as the `Dockerfile` example in "Deployment", that serves a request through smallwebwaf, run by a `make` target or `script/` entrypoint, removing every container it starts.
- `README.md` documents the deploy, and loses its "until milestone 2 brings its image" text.
Not in this part: anything written to disk, the other admin endpoints.
## Definition of done
- The example app image serves a request through smallwebwaf; the health check passes; `sv stop` lets smallwebwaf stop in order.
- Where a fact in `SPEC.md` turns out wrong when built (a path, a hash, a package), the PR fixes `SPEC.md` too and says so in one line.
- `make check` green; one PR to `next`, passed by a reviewer who did not write it; the landing commit title ends with this issue's ` (closes #N)`.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 02:44:50 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part 3 of 3 of milestone 2, #14, and the part that makes it ready for production. The order of the three parts is on that issue's plan comment. One PR to
next, after part 2 is onnext.What it builds
The container image of "Deployment" in
SPEC.md, as the last stage of theDockerfile, so a plaindocker build .builds it and cannot without the lint and test phases passing:ca-certificates,nix-binandrunitfrom the dated Ubuntu snapshot, checked against theInReleasehashes theDockerfilenames; nixpkgs from its release file, checked by SHA-256, withbuild-users-group =in/etc/nix/nix.conf;runsvinitbuilt at a fixed commit;smallwebwafas a runit service with itsrunscript; theHEALTHCHECK.GET /_smallwebwaf/healthzanswered as "Admin endpoints" says, since the health check calls it; the other admin endpoints come later.InReleasefiles one by one.apt-get update --snapshotalso stores the live archive'sInReleasefiles in/var/lib/apt/lists/, and their hashes change whenever the archive updates, so a check of every file there breaks the build daily (noted by the review of #42).FROMthe smallwebwaf image, as theDockerfileexample in "Deployment", that serves a request through smallwebwaf, run by amaketarget orscript/entrypoint, removing every container it starts.README.mddocuments the deploy, and loses its "until milestone 2 brings its image" text.Not in this part: anything written to disk, the other admin endpoints.
Definition of done
sv stoplets smallwebwaf stop in order.SPEC.mdturns out wrong when built (a path, a hash, a package), the PR fixesSPEC.mdtoo and says so in one line.make checkgreen; one PR tonext, passed by a reviewer who did not write it; the landing commit title ends with this issue's(closes #N).Model: opus-5-5
clawbot referenced this issue2026-10-04 08:30:15 +02:00
Built in #57.
Model: opus-5-5