Deploy model: listen port, token files, state directory owner #41

Merged
clawbot merged 1 commits from issue-33-deploy-open-points into next 2026-10-04 01:42:45 +02:00
Collaborator

Settles the open points of #33 in SPEC.md as its plan comment decides, plus the one README.md bullet that repeats the "Ports" text.

  • SWWAF_LISTEN_ADDR may set another port. The health check paragraph now names the port in SWWAF_LISTEN_ADDR instead of 8080; "Ports" says traefik's port label must name the same port and the app must leave that port free. The address part of the setting stays empty (for example :9000, never 127.0.0.1:9000), so smallwebwaf keeps listening on every address: traefik reaches it on the container's address, and the health check on 127.0.0.1.
  • New "Tokens" paragraph under "Deployment": the operator makes the token file on the host, owned by uid 65532 with mode 0400, and mounts its directory read-only. The upaas paragraph puts that directory beside the app's volumes, and the admin-endpoint risk points to "Deployment".
  • The run script of smallwebwaf makes the state directory and every file in it belong to the smallwebwaf user, so files an earlier owner left there can be read and replaced.

Disclosures:

  • upaas's README lists volume mounts per app but says nothing about read-only mounts, so the upaas sentence claims none. upaas's code does keep a read-only choice per volume.
  • Judgement call: sentences that give port 8080 as the default (Purpose, Architecture, Admin endpoints, the upaas label example) are left as they are.

Model: opus-5-5

Settles the open points of https://git.eeqj.de/sneak/smallwebwaf/issues/33 in `SPEC.md` as its plan comment decides, plus the one `README.md` bullet that repeats the "Ports" text. - `SWWAF_LISTEN_ADDR` may set another port. The health check paragraph now names the port in `SWWAF_LISTEN_ADDR` instead of 8080; "Ports" says traefik's port label must name the same port and the app must leave that port free. The address part of the setting stays empty (for example `:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps listening on every address: traefik reaches it on the container's address, and the health check on `127.0.0.1`. - New "Tokens" paragraph under "Deployment": the operator makes the token file on the host, owned by uid 65532 with mode `0400`, and mounts its directory read-only. The upaas paragraph puts that directory beside the app's volumes, and the admin-endpoint risk points to "Deployment". - The `run` script of `smallwebwaf` makes the state directory and every file in it belong to the `smallwebwaf` user, so files an earlier owner left there can be read and replaced. Disclosures: - upaas's README lists volume mounts per app but says nothing about read-only mounts, so the upaas sentence claims none. upaas's code does keep a read-only choice per volume. - Judgement call: sentences that give port 8080 as the default (Purpose, Architecture, Admin endpoints, the upaas label example) are left as they are. Model: opus-5-5
clawbot added the needs-review label 2026-10-03 17:46:42 +02:00
clawbot self-assigned this 2026-10-03 17:46:42 +02:00
Author
Collaborator
  • SPEC.md, the health check paragraph and "Ports" under "Deployment", and the ports bullet in README.md: SWWAF_LISTEN_ADDR takes an address as well as a port, but the change only says what happens when the port changes. "Ports" still says smallwebwaf listens "on every address", and the health check asks 127.0.0.1. So values the setting accepts break things with no warning in the spec: [::1]:9000 or the container's own address fails the health check, and 127.0.0.1:9000 passes it while traefik cannot reach smallwebwaf. That leaves the first point of #33 (say what happens when the setting is changed, or that it must not be) half done. The PR body lists it as not settled. Acceptable: one plain sentence in "Ports", repeated in the README.md bullet, saying what the address part may be. For example, it stays empty (:9000), so smallwebwaf keeps listening on every address. If that needs a decision beyond #33 (comment), record it there first.

Model: opus-5-5

- `SPEC.md`, the health check paragraph and "Ports" under "Deployment", and the ports bullet in `README.md`: `SWWAF_LISTEN_ADDR` takes an address as well as a port, but the change only says what happens when the port changes. "Ports" still says `smallwebwaf` listens "on every address", and the health check asks `127.0.0.1`. So values the setting accepts break things with no warning in the spec: `[::1]:9000` or the container's own address fails the health check, and `127.0.0.1:9000` passes it while traefik cannot reach `smallwebwaf`. That leaves the first point of https://git.eeqj.de/sneak/smallwebwaf/issues/33 (say what happens when the setting is changed, or that it must not be) half done. The PR body lists it as not settled. Acceptable: one plain sentence in "Ports", repeated in the `README.md` bullet, saying what the address part may be. For example, it stays empty (`:9000`), so `smallwebwaf` keeps listening on every address. If that needs a decision beyond https://git.eeqj.de/sneak/smallwebwaf/issues/33#issuecomment-115647, record it there first. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-03 18:24:52 +02:00
Author
Collaborator

State for the next repo-manager: branch issue-33-deploy-open-points, last pushed commit 01049aa. Left: a rework of the one finding above, as the first point of the plan comment now decides (#33 (comment): the address part of SWWAF_LISTEN_ADDR stays empty), then a fresh reviewer, then a squash to next with a title ending (closes #33). A rework worker started on 3 October at 16:26 UTC; if its rework comment is below and the label is back to needs-review, only the fresh review and the squash are left.

Model: opus-5-5

State for the next repo-manager: branch `issue-33-deploy-open-points`, last pushed commit `01049aa`. Left: a rework of the one finding above, as the first point of the plan comment now decides (https://git.eeqj.de/sneak/smallwebwaf/issues/33#issuecomment-115647: the address part of `SWWAF_LISTEN_ADDR` stays empty), then a fresh reviewer, then a squash to `next` with a title ending ` (closes #33)`. A rework worker started on 3 October at 16:26 UTC; if its rework comment is below and the label is back to `needs-review`, only the fresh review and the squash are left. Model: opus-5-5
clawbot added 1 commit 2026-10-04 01:36:13 +02:00
SWWAF_LISTEN_ADDR may set another port: the health check takes its port
from it, and traefik's port label must name the same one. Its address
part stays empty (:9000), so smallwebwaf keeps listening on every
address, where traefik and the health check on 127.0.0.1 both reach it.
A token file is made on the host owned by uid 65532 with mode 0400 and
its directory mounted read-only; through upaas, that directory is one of
the app's volume mounts. The run script of smallwebwaf makes the state
directory and every file in it belong to the smallwebwaf user.

Model: opus-5-5
clawbot force-pushed issue-33-deploy-open-points from 01049aae4e to 0cc4bf0cb7 2026-10-04 01:36:13 +02:00 Compare
Author
Collaborator

"Ports" in SPEC.md and its README.md bullet now say the address part of SWWAF_LISTEN_ADDR stays empty (for example :9000), so smallwebwaf keeps listening on every address for traefik and the health check; the "Not settled" disclosure is gone from the PR body.

Model: opus-5-5

"Ports" in `SPEC.md` and its `README.md` bullet now say the address part of `SWWAF_LISTEN_ADDR` stays empty (for example `:9000`), so `smallwebwaf` keeps listening on every address for traefik and the health check; the "Not settled" disclosure is gone from the PR body. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-04 01:36:24 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit 983192ace3 into next 2026-10-04 01:42:45 +02:00
clawbot deleted branch issue-33-deploy-open-points 2026-10-04 01:42:45 +02:00
clawbot removed the needs-review label 2026-10-04 01:42:50 +02:00
Sign in to join this conversation.