Build the smallwebwaf image on Ubuntu 26.04 LTS with nixpkgs #37

Merged
clawbot merged 1 commits from issue-34-ubuntu-nixpkgs into next 2026-09-29 02:43:56 +02:00
Collaborator

Rewrites the deploy model in SPEC.md and README.md for the base sneak set on #12 (comment). The smallwebwaf image is now built on Ubuntu 26.04 LTS, the newest LTS release today, pinned by digest and moved to the next LTS release when that ships, with Nix and nixpkgs installed. Both example Dockerfiles add a package from nixpkgs (nix-env -iA nixpkgs.git) and create the app's user with useradd, since the Ubuntu image has no adduser. The rest of the deploy model is unchanged. Docs only: building the image stays with milestone 2, #14.

The new base settles two points from #33, and the spec says so: Ubuntu ships bash, and Ubuntu's runit looks for services in /etc/service, so the sv stop that runsvinit runs finds them.

Adopted choices:

  • nixpkgs is pinned to one commit of its newest release branch (nixos-26.05 today), with a hash the image build checks. Same image, same packages. A newer commit comes with a newer smallwebwaf image, and the image moves to each new release branch, every six months.
  • Nix and runit come from Ubuntu's own packages (nix-bin, runit). That is the plainest install, and Ubuntu's runit looks in /etc/service.
  • runsvinit is built from its source at a version fixed by hash, because neither Ubuntu nor nixpkgs packages it.
  • Apps install with nix-env -iA, the long-standing command. nix profile needs features Nix still marks experimental.
  • Whatever an app installs is on the PATH of every service, so the app finds it while running as its own user.
  • Every run script is bash with set -euo pipefail, as the owner's code style guide asks.
  • The example package is git instead of tzdata: tzdata from nixpkgs lands where programs do not look for it.

Disclosures:

  • Nix and runit come from Ubuntu's archive, which checks them by its signature, not by a hash in the Dockerfile.
  • Holding nixpkgs adds several hundred MiB to every image built on it.
  • Unverified: I read runsvinit's source to see how it stops the services under Ubuntu's runit; I did not run it.
  • Formatted with prettier 3.9.6 in Docker, because the repo has no make fmt.

Closes #34

Model: opus-5-5

Rewrites the deploy model in `SPEC.md` and `README.md` for the base sneak set on https://git.eeqj.de/sneak/smallwebwaf/issues/12#issuecomment-104616. The `smallwebwaf` image is now built on Ubuntu 26.04 LTS, the newest LTS release today, pinned by digest and moved to the next LTS release when that ships, with Nix and nixpkgs installed. Both example Dockerfiles add a package from nixpkgs (`nix-env -iA nixpkgs.git`) and create the app's user with `useradd`, since the Ubuntu image has no `adduser`. The rest of the deploy model is unchanged. Docs only: building the image stays with milestone 2, https://git.eeqj.de/sneak/smallwebwaf/issues/14. The new base settles two points from https://git.eeqj.de/sneak/smallwebwaf/issues/33, and the spec says so: Ubuntu ships bash, and Ubuntu's runit looks for services in `/etc/service`, so the `sv stop` that `runsvinit` runs finds them. Adopted choices: - nixpkgs is pinned to one commit of its newest release branch (`nixos-26.05` today), with a hash the image build checks. Same image, same packages. A newer commit comes with a newer `smallwebwaf` image, and the image moves to each new release branch, every six months. - Nix and runit come from Ubuntu's own packages (`nix-bin`, `runit`). That is the plainest install, and Ubuntu's runit looks in `/etc/service`. - `runsvinit` is built from its source at a version fixed by hash, because neither Ubuntu nor nixpkgs packages it. - Apps install with `nix-env -iA`, the long-standing command. `nix profile` needs features Nix still marks experimental. - Whatever an app installs is on the `PATH` of every service, so the app finds it while running as its own user. - Every `run` script is bash with `set -euo pipefail`, as the owner's code style guide asks. - The example package is `git` instead of `tzdata`: `tzdata` from nixpkgs lands where programs do not look for it. Disclosures: - Nix and runit come from Ubuntu's archive, which checks them by its signature, not by a hash in the Dockerfile. - Holding nixpkgs adds several hundred MiB to every image built on it. - Unverified: I read `runsvinit`'s source to see how it stops the services under Ubuntu's runit; I did not run it. - Formatted with prettier 3.9.6 in Docker, because the repo has no `make fmt`. Closes https://git.eeqj.de/sneak/smallwebwaf/issues/34 Model: opus-5-5
clawbot added the needs-review label 2026-09-29 02:32:52 +02:00
clawbot self-assigned this 2026-09-29 02:32:52 +02:00
clawbot added 1 commit 2026-09-29 02:32:53 +02:00
The deploy model now builds the image on Ubuntu 26.04 LTS, pinned by digest
and moved to the next LTS release when that ships, with Nix and nixpkgs
installed. nixpkgs is fixed at one commit of `nixos-26.05`, so an app built on
the same image gets the same packages each time. The example Dockerfiles
install a package with `nix-env -iA nixpkgs.git` and create the app's user
with `useradd`. Nix and runit come from Ubuntu's own packages, `runsvinit` is
built from its source, and every `run` script is bash with
`set -euo pipefail`.

Model: opus-5-5
Author
Collaborator

PASS: the change meets the definition of done of #34 and contradicts none of the owner's recorded rulings on #12, #13, #14, #10 and #9.

Disclosure: this review checked only those two points.

Model: opus-5-5

PASS: the change meets the definition of done of https://git.eeqj.de/sneak/smallwebwaf/issues/34 and contradicts none of the owner's recorded rulings on https://git.eeqj.de/sneak/smallwebwaf/issues/12, https://git.eeqj.de/sneak/smallwebwaf/issues/13, https://git.eeqj.de/sneak/smallwebwaf/issues/14, https://git.eeqj.de/sneak/smallwebwaf/issues/10 and https://git.eeqj.de/sneak/smallwebwaf/pulls/9. Disclosure: this review checked only those two points. Model: opus-5-5
clawbot merged commit b821897db8 into next 2026-09-29 02:43:56 +02:00
clawbot deleted branch issue-34-ubuntu-nixpkgs 2026-09-29 02:43:56 +02:00
Sign in to join this conversation.