Milestone 2, part 3: the image apps build FROM, with its health check #45

Open
opened 2026-10-04 02:44:50 +02:00 by clawbot · 1 comment
Collaborator

Part 3 of 3 of milestone 2, #14, and the part that makes it ready for production. The order of the three parts is on that issue's plan comment. One PR to next, after part 2 is on next.

What it builds

The container image of "Deployment" in SPEC.md, as the last stage of the Dockerfile, so a plain docker build . builds it and cannot without the lint and test phases passing:

  • Everything "Deployment" says the image holds: the pinned Ubuntu base; ca-certificates, nix-bin and runit from the dated Ubuntu snapshot, checked against the InRelease hashes the Dockerfile names; nixpkgs from its release file, checked by SHA-256, with build-users-group = in /etc/nix/nix.conf; runsvinit built at a fixed commit; smallwebwaf as a runit service with its run script; the HEALTHCHECK.
  • GET /_smallwebwaf/healthz answered as "Admin endpoints" says, since the health check calls it; the other admin endpoints come later.
  • The hash check names the snapshot's own InRelease files one by one. apt-get update --snapshot also stores the live archive's InRelease files in /var/lib/apt/lists/, and their hashes change whenever the archive updates, so a check of every file there breaks the build daily (noted by the review of #42).
  • An example app image built FROM the smallwebwaf image, as the Dockerfile example in "Deployment", that serves a request through smallwebwaf, run by a make target or script/ entrypoint, removing every container it starts.
  • README.md documents the deploy, and loses its "until milestone 2 brings its image" text.

Not in this part: anything written to disk, the other admin endpoints.

Definition of done

  • The example app image serves a request through smallwebwaf; the health check passes; sv stop lets smallwebwaf stop in order.
  • Where a fact in SPEC.md turns out wrong when built (a path, a hash, a package), the PR fixes SPEC.md too and says so in one line.
  • make check green; one PR to next, passed by a reviewer who did not write it; the landing commit title ends with this issue's (closes #N).

Model: opus-5-5

Part 3 of 3 of milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14, and the part that makes it ready for production. The order of the three parts is on that issue's plan comment. One PR to `next`, after part 2 is on `next`. ## What it builds The container image of "Deployment" in `SPEC.md`, as the last stage of the `Dockerfile`, so a plain `docker build .` builds it and cannot without the lint and test phases passing: - Everything "Deployment" says the image holds: the pinned Ubuntu base; `ca-certificates`, `nix-bin` and `runit` from the dated Ubuntu snapshot, checked against the `InRelease` hashes the `Dockerfile` names; nixpkgs from its release file, checked by SHA-256, with `build-users-group =` in `/etc/nix/nix.conf`; `runsvinit` built at a fixed commit; `smallwebwaf` as a runit service with its `run` script; the `HEALTHCHECK`. - `GET /_smallwebwaf/healthz` answered as "Admin endpoints" says, since the health check calls it; the other admin endpoints come later. - The hash check names the snapshot's own `InRelease` files one by one. `apt-get update --snapshot` also stores the live archive's `InRelease` files in `/var/lib/apt/lists/`, and their hashes change whenever the archive updates, so a check of every file there breaks the build daily (noted by the review of https://git.eeqj.de/sneak/smallwebwaf/pulls/42). - An example app image built `FROM` the smallwebwaf image, as the `Dockerfile` example in "Deployment", that serves a request through smallwebwaf, run by a `make` target or `script/` entrypoint, removing every container it starts. - `README.md` documents the deploy, and loses its "until milestone 2 brings its image" text. Not in this part: anything written to disk, the other admin endpoints. ## Definition of done - The example app image serves a request through smallwebwaf; the health check passes; `sv stop` lets smallwebwaf stop in order. - Where a fact in `SPEC.md` turns out wrong when built (a path, a hash, a package), the PR fixes `SPEC.md` too and says so in one line. - `make check` green; one PR to `next`, passed by a reviewer who did not write it; the landing commit title ends with this issue's ` (closes #N)`. Model: opus-5-5
clawbot self-assigned this 2026-10-04 02:44:50 +02:00
Author
Collaborator

Built in #57.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/smallwebwaf/pulls/57. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#45