Rewrites the deploy model in SPEC.md and README.md for the base sneak set on #12 (comment). The smallwebwaf image is now built on Ubuntu 26.04 LTS, the newest LTS release today, pinned by digest and moved to the next LTS release when that ships, with Nix and nixpkgs installed. Both example Dockerfiles add a package from nixpkgs (nix-env -iA nixpkgs.git) and create the app's user with useradd, since the Ubuntu image has no adduser. The rest of the deploy model is unchanged. Docs only: building the image stays with milestone 2, #14.
The new base settles two points from #33, and the spec says so: Ubuntu ships bash, and Ubuntu's runit looks for services in /etc/service, so the sv stop that runsvinit runs finds them.
Adopted choices:
nixpkgs is pinned to one commit of its newest release branch (nixos-26.05 today), with a hash the image build checks. Same image, same packages. A newer commit comes with a newer smallwebwaf image, and the image moves to each new release branch, every six months.
Nix and runit come from Ubuntu's own packages (nix-bin, runit). That is the plainest install, and Ubuntu's runit looks in /etc/service.
runsvinit is built from its source at a version fixed by hash, because neither Ubuntu nor nixpkgs packages it.
Apps install with nix-env -iA, the long-standing command. nix profile needs features Nix still marks experimental.
Whatever an app installs is on the PATH of every service, so the app finds it while running as its own user.
Every run script is bash with set -euo pipefail, as the owner's code style guide asks.
The example package is git instead of tzdata: tzdata from nixpkgs lands where programs do not look for it.
Disclosures:
Nix and runit come from Ubuntu's archive, which checks them by its signature, not by a hash in the Dockerfile.
Holding nixpkgs adds several hundred MiB to every image built on it.
Unverified: I read runsvinit's source to see how it stops the services under Ubuntu's runit; I did not run it.
Formatted with prettier 3.9.6 in Docker, because the repo has no make fmt.
Rewrites the deploy model in `SPEC.md` and `README.md` for the base sneak set on https://git.eeqj.de/sneak/smallwebwaf/issues/12#issuecomment-104616. The `smallwebwaf` image is now built on Ubuntu 26.04 LTS, the newest LTS release today, pinned by digest and moved to the next LTS release when that ships, with Nix and nixpkgs installed. Both example Dockerfiles add a package from nixpkgs (`nix-env -iA nixpkgs.git`) and create the app's user with `useradd`, since the Ubuntu image has no `adduser`. The rest of the deploy model is unchanged. Docs only: building the image stays with milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14.
The new base settles two points from https://git.eeqj.de/sneak/smallwebwaf/issues/33, and the spec says so: Ubuntu ships bash, and Ubuntu's runit looks for services in `/etc/service`, so the `sv stop` that `runsvinit` runs finds them.
Adopted choices:
- nixpkgs is pinned to one commit of its newest release branch (`nixos-26.05` today), with a hash the image build checks. Same image, same packages. A newer commit comes with a newer `smallwebwaf` image, and the image moves to each new release branch, every six months.
- Nix and runit come from Ubuntu's own packages (`nix-bin`, `runit`). That is the plainest install, and Ubuntu's runit looks in `/etc/service`.
- `runsvinit` is built from its source at a version fixed by hash, because neither Ubuntu nor nixpkgs packages it.
- Apps install with `nix-env -iA`, the long-standing command. `nix profile` needs features Nix still marks experimental.
- Whatever an app installs is on the `PATH` of every service, so the app finds it while running as its own user.
- Every `run` script is bash with `set -euo pipefail`, as the owner's code style guide asks.
- The example package is `git` instead of `tzdata`: `tzdata` from nixpkgs lands where programs do not look for it.
Disclosures:
- Nix and runit come from Ubuntu's archive, which checks them by its signature, not by a hash in the Dockerfile.
- Holding nixpkgs adds several hundred MiB to every image built on it.
- Unverified: I read `runsvinit`'s source to see how it stops the services under Ubuntu's runit; I did not run it.
- Formatted with prettier 3.9.6 in Docker, because the repo has no `make fmt`.
Closes https://git.eeqj.de/sneak/smallwebwaf/issues/34
Model: opus-5-5
The deploy model now builds the image on Ubuntu 26.04 LTS, pinned by digest
and moved to the next LTS release when that ships, with Nix and nixpkgs
installed. nixpkgs is fixed at one commit of `nixos-26.05`, so an app built on
the same image gets the same packages each time. The example Dockerfiles
install a package with `nix-env -iA nixpkgs.git` and create the app's user
with `useradd`. Nix and runit come from Ubuntu's own packages, `runsvinit` is
built from its source, and every `run` script is bash with
`set -euo pipefail`.
Model: opus-5-5
PASS: the change meets the definition of done of #34 and contradicts none of the owner's recorded rulings on #12, #13, #14, #10 and #9.
Disclosure: this review checked only those two points.
Model: opus-5-5
PASS: the change meets the definition of done of https://git.eeqj.de/sneak/smallwebwaf/issues/34 and contradicts none of the owner's recorded rulings on https://git.eeqj.de/sneak/smallwebwaf/issues/12, https://git.eeqj.de/sneak/smallwebwaf/issues/13, https://git.eeqj.de/sneak/smallwebwaf/issues/14, https://git.eeqj.de/sneak/smallwebwaf/issues/10 and https://git.eeqj.de/sneak/smallwebwaf/pulls/9.
Disclosure: this review checked only those two points.
Model: opus-5-5
clawbot
merged commit b821897db8 into next2026-09-29 02:43:56 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Rewrites the deploy model in
SPEC.mdandREADME.mdfor the base sneak set on #12 (comment). Thesmallwebwafimage is now built on Ubuntu 26.04 LTS, the newest LTS release today, pinned by digest and moved to the next LTS release when that ships, with Nix and nixpkgs installed. Both example Dockerfiles add a package from nixpkgs (nix-env -iA nixpkgs.git) and create the app's user withuseradd, since the Ubuntu image has noadduser. The rest of the deploy model is unchanged. Docs only: building the image stays with milestone 2, #14.The new base settles two points from #33, and the spec says so: Ubuntu ships bash, and Ubuntu's runit looks for services in
/etc/service, so thesv stopthatrunsvinitruns finds them.Adopted choices:
nixos-26.05today), with a hash the image build checks. Same image, same packages. A newer commit comes with a newersmallwebwafimage, and the image moves to each new release branch, every six months.nix-bin,runit). That is the plainest install, and Ubuntu's runit looks in/etc/service.runsvinitis built from its source at a version fixed by hash, because neither Ubuntu nor nixpkgs packages it.nix-env -iA, the long-standing command.nix profileneeds features Nix still marks experimental.PATHof every service, so the app finds it while running as its own user.runscript is bash withset -euo pipefail, as the owner's code style guide asks.gitinstead oftzdata:tzdatafrom nixpkgs lands where programs do not look for it.Disclosures:
runsvinit's source to see how it stops the services under Ubuntu's runit; I did not run it.make fmt.Closes #34
Model: opus-5-5
PASS: the change meets the definition of done of #34 and contradicts none of the owner's recorded rulings on #12, #13, #14, #10 and #9.
Disclosure: this review checked only those two points.
Model: opus-5-5