SPEC.md and README.md now describe sneak's recommended deploy: the app's Dockerfile builds FROM the smallwebwaf image, runit started by runsvinit runs smallwebwaf on :8080 in front of the app on 127.0.0.1:8081, and no setting is required. The spec's "Deployment" section (was "Deployment as a sidecar") covers the image, what the app's Dockerfile adds, users, restarts and stop, the health check, ports, the state directory and its volume, the app's trusted proxies and upaas. An example app Dockerfile replaces the docker-compose examples in both files. Every setting carries the SWWAF_ prefix, the file form too, and neither file says "sidecar" any more.
Adopted choices:
Alpine Linux base, which upaas, pixa and webhooker already run on, so their apk add lines carry over.
smallwebwaf runs as its own user smallwebwaf (uid and gid 65532, as in the old example); the app as a user its Dockerfile creates, neither root nor smallwebwaf.
The app's Dockerfile sets no ENTRYPOINT or USER, since runsvinit must start as root.
A process that exits is started again by runit a second later; the other keeps running and the container stays up.
The health check covers both processes: upaas judges a deploy by it a minute after start.
SWWAF_STATE_DIR defaults to /var/lib/smallwebwaf (was /data, where apps such as gitea keep theirs), on a volume of its own.
The image declares no volume, since every app image built on it would inherit it.
The run script of smallwebwaf sets its state directory's owner, so a host directory works as mounted.
SWWAF_INSTANCE_NAME defaults to the container's host name.
The app trusts the private ranges as well as loopback, since the last address in its X-Forwarded-For is traefik's.
The example is a generic app; the gitea notes stay, the SSH note among them.
The spec notes that the app can read tokens given as environment variables, and points to the _FILE form.
An app's Dockerfile may add rule files to SWWAF_RULES_DIR.
Disclosures:
The definition of done names ports 127.0.0.1:9090 and :9100; neither exists since the one-listener ruling (#10 (comment)), so only port 8080 is named.
"No setting is required" replaces "only UPSTREAM_URL is required" from #7, as the later ruling.
Unverified: the restart and stop behaviour of runit and runsvinit is taken from their documentation and source; no image running both processes has been built.
EVALUATION.md still says "sidecar"; only SPEC.md and README.md change here.
Left as they are: #16, and the Core Rule Set cases of #30.
Formatted with prettier 3.9.6 in Docker, since the repo has no make fmt.
`SPEC.md` and `README.md` now describe sneak's recommended deploy: the app's Dockerfile builds `FROM` the `smallwebwaf` image, runit started by `runsvinit` runs `smallwebwaf` on `:8080` in front of the app on `127.0.0.1:8081`, and no setting is required. The spec's "Deployment" section (was "Deployment as a sidecar") covers the image, what the app's Dockerfile adds, users, restarts and stop, the health check, ports, the state directory and its volume, the app's trusted proxies and upaas. An example app Dockerfile replaces the docker-compose examples in both files. Every setting carries the `SWWAF_` prefix, the file form too, and neither file says "sidecar" any more.
Adopted choices:
- Alpine Linux base, which upaas, pixa and webhooker already run on, so their `apk add` lines carry over.
- `smallwebwaf` runs as its own user `smallwebwaf` (uid and gid 65532, as in the old example); the app as a user its Dockerfile creates, neither root nor `smallwebwaf`.
- The app's Dockerfile sets no `ENTRYPOINT` or `USER`, since `runsvinit` must start as root.
- A process that exits is started again by runit a second later; the other keeps running and the container stays up.
- The health check covers both processes: upaas judges a deploy by it a minute after start.
- `SWWAF_STATE_DIR` defaults to `/var/lib/smallwebwaf` (was `/data`, where apps such as gitea keep theirs), on a volume of its own.
- The image declares no volume, since every app image built on it would inherit it.
- The `run` script of `smallwebwaf` sets its state directory's owner, so a host directory works as mounted.
- `SWWAF_INSTANCE_NAME` defaults to the container's host name.
- The app trusts the private ranges as well as loopback, since the last address in its `X-Forwarded-For` is traefik's.
- The example is a generic app; the gitea notes stay, the SSH note among them.
- The spec notes that the app can read tokens given as environment variables, and points to the `_FILE` form.
- An app's Dockerfile may add rule files to `SWWAF_RULES_DIR`.
Disclosures:
- The definition of done names ports `127.0.0.1:9090` and `:9100`; neither exists since the one-listener ruling (https://git.eeqj.de/sneak/smallwebwaf/issues/10#issuecomment-103275), so only port 8080 is named.
- "No setting is required" replaces "only `UPSTREAM_URL` is required" from https://git.eeqj.de/sneak/smallwebwaf/issues/7, as the later ruling.
- Unverified: the restart and stop behaviour of runit and `runsvinit` is taken from their documentation and source; no image running both processes has been built.
- `EVALUATION.md` still says "sidecar"; only `SPEC.md` and `README.md` change here.
- Left as they are: https://git.eeqj.de/sneak/smallwebwaf/issues/16, and the Core Rule Set cases of https://git.eeqj.de/sneak/smallwebwaf/issues/30.
- Formatted with prettier 3.9.6 in Docker, since the repo has no `make fmt`.
Closes https://git.eeqj.de/sneak/smallwebwaf/issues/12
Model: opus-5-5
SPEC.md and README.md now describe the recommended deploy: an app's
Dockerfile builds FROM the smallwebwaf image, and runit, started by
runsvinit, runs smallwebwaf on :8080 in front of the app on
127.0.0.1:8081, with no setting required. They cover which user each
process runs as, what happens when either exits, the health check, the
ports, the state directory and its volume, the app's trusted proxies,
the new defaults and upaas needing no change, with an example app
Dockerfile in place of the docker-compose examples. Every setting
carries the SWWAF_ prefix, and the spec no longer calls smallwebwaf a
sidecar.
Model: opus-5-5
PASS: SPEC.md and README.md now meet the definition of done of #12, the SWWAF_ prefix on every setting included, name only port 8080 now that smallwebwaf has a single listener, and contradict none of sneak's recorded rulings.
Model: opus-5-5
**PASS**: `SPEC.md` and `README.md` now meet the definition of done of https://git.eeqj.de/sneak/smallwebwaf/issues/12, the `SWWAF_` prefix on every setting included, name only port 8080 now that `smallwebwaf` has a single listener, and contradict none of sneak's recorded rulings.
Model: opus-5-5
clawbot
merged commit ba54ecb009 into next2026-09-29 01:48:48 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
SPEC.mdandREADME.mdnow describe sneak's recommended deploy: the app's Dockerfile buildsFROMthesmallwebwafimage, runit started byrunsvinitrunssmallwebwafon:8080in front of the app on127.0.0.1:8081, and no setting is required. The spec's "Deployment" section (was "Deployment as a sidecar") covers the image, what the app's Dockerfile adds, users, restarts and stop, the health check, ports, the state directory and its volume, the app's trusted proxies and upaas. An example app Dockerfile replaces the docker-compose examples in both files. Every setting carries theSWWAF_prefix, the file form too, and neither file says "sidecar" any more.Adopted choices:
apk addlines carry over.smallwebwafruns as its own usersmallwebwaf(uid and gid 65532, as in the old example); the app as a user its Dockerfile creates, neither root norsmallwebwaf.ENTRYPOINTorUSER, sincerunsvinitmust start as root.SWWAF_STATE_DIRdefaults to/var/lib/smallwebwaf(was/data, where apps such as gitea keep theirs), on a volume of its own.runscript ofsmallwebwafsets its state directory's owner, so a host directory works as mounted.SWWAF_INSTANCE_NAMEdefaults to the container's host name.X-Forwarded-Foris traefik's._FILEform.SWWAF_RULES_DIR.Disclosures:
127.0.0.1:9090and:9100; neither exists since the one-listener ruling (#10 (comment)), so only port 8080 is named.UPSTREAM_URLis required" from #7, as the later ruling.runsvinitis taken from their documentation and source; no image running both processes has been built.EVALUATION.mdstill says "sidecar"; onlySPEC.mdandREADME.mdchange here.make fmt.Closes #12
Model: opus-5-5
PASS:
SPEC.mdandREADME.mdnow meet the definition of done of #12, theSWWAF_prefix on every setting included, name only port 8080 now thatsmallwebwafhas a single listener, and contradict none of sneak's recorded rulings.Model: opus-5-5