SPEC.md and README.md now describe the recommended deploy: an app's
Dockerfile builds FROM the smallwebwaf image, and runit, started by
runsvinit, runs smallwebwaf on :8080 in front of the app on
127.0.0.1:8081, with no setting required. They cover which user each
process runs as, what happens when either exits, the health check, the
ports, the state directory and its volume, the app's trusted proxies,
the new defaults and upaas needing no change, with an example app
Dockerfile in place of the docker-compose examples. Every setting
carries the SWWAF_ prefix, and the spec no longer calls smallwebwaf a
sidecar.
Model: opus-5-5