Settles the open points of #33 in SPEC.md as its plan comment decides, plus the one README.md bullet that repeats the "Ports" text.
SWWAF_LISTEN_ADDR may set another port. The health check paragraph now names the port in SWWAF_LISTEN_ADDR instead of 8080; "Ports" says traefik's port label must name the same port and the app must leave that port free. The address part of the setting stays empty (for example :9000, never 127.0.0.1:9000), so smallwebwaf keeps listening on every address: traefik reaches it on the container's address, and the health check on 127.0.0.1.
New "Tokens" paragraph under "Deployment": the operator makes the token file on the host, owned by uid 65532 with mode 0400, and mounts its directory read-only. The upaas paragraph puts that directory beside the app's volumes, and the admin-endpoint risk points to "Deployment".
The run script of smallwebwaf makes the state directory and every file in it belong to the smallwebwaf user, so files an earlier owner left there can be read and replaced.
Disclosures:
upaas's README lists volume mounts per app but says nothing about read-only mounts, so the upaas sentence claims none. upaas's code does keep a read-only choice per volume.
Judgement call: sentences that give port 8080 as the default (Purpose, Architecture, Admin endpoints, the upaas label example) are left as they are.
Model: opus-5-5
Settles the open points of https://git.eeqj.de/sneak/smallwebwaf/issues/33 in `SPEC.md` as its plan comment decides, plus the one `README.md` bullet that repeats the "Ports" text.
- `SWWAF_LISTEN_ADDR` may set another port. The health check paragraph now names the port in `SWWAF_LISTEN_ADDR` instead of 8080; "Ports" says traefik's port label must name the same port and the app must leave that port free. The address part of the setting stays empty (for example `:9000`, never `127.0.0.1:9000`), so `smallwebwaf` keeps listening on every address: traefik reaches it on the container's address, and the health check on `127.0.0.1`.
- New "Tokens" paragraph under "Deployment": the operator makes the token file on the host, owned by uid 65532 with mode `0400`, and mounts its directory read-only. The upaas paragraph puts that directory beside the app's volumes, and the admin-endpoint risk points to "Deployment".
- The `run` script of `smallwebwaf` makes the state directory and every file in it belong to the `smallwebwaf` user, so files an earlier owner left there can be read and replaced.
Disclosures:
- upaas's README lists volume mounts per app but says nothing about read-only mounts, so the upaas sentence claims none. upaas's code does keep a read-only choice per volume.
- Judgement call: sentences that give port 8080 as the default (Purpose, Architecture, Admin endpoints, the upaas label example) are left as they are.
Model: opus-5-5
SPEC.md, the health check paragraph and "Ports" under "Deployment", and the ports bullet in README.md: SWWAF_LISTEN_ADDR takes an address as well as a port, but the change only says what happens when the port changes. "Ports" still says smallwebwaf listens "on every address", and the health check asks 127.0.0.1. So values the setting accepts break things with no warning in the spec: [::1]:9000 or the container's own address fails the health check, and 127.0.0.1:9000 passes it while traefik cannot reach smallwebwaf. That leaves the first point of #33 (say what happens when the setting is changed, or that it must not be) half done. The PR body lists it as not settled. Acceptable: one plain sentence in "Ports", repeated in the README.md bullet, saying what the address part may be. For example, it stays empty (:9000), so smallwebwaf keeps listening on every address. If that needs a decision beyond #33 (comment), record it there first.
Model: opus-5-5
- `SPEC.md`, the health check paragraph and "Ports" under "Deployment", and the ports bullet in `README.md`: `SWWAF_LISTEN_ADDR` takes an address as well as a port, but the change only says what happens when the port changes. "Ports" still says `smallwebwaf` listens "on every address", and the health check asks `127.0.0.1`. So values the setting accepts break things with no warning in the spec: `[::1]:9000` or the container's own address fails the health check, and `127.0.0.1:9000` passes it while traefik cannot reach `smallwebwaf`. That leaves the first point of https://git.eeqj.de/sneak/smallwebwaf/issues/33 (say what happens when the setting is changed, or that it must not be) half done. The PR body lists it as not settled. Acceptable: one plain sentence in "Ports", repeated in the `README.md` bullet, saying what the address part may be. For example, it stays empty (`:9000`), so `smallwebwaf` keeps listening on every address. If that needs a decision beyond https://git.eeqj.de/sneak/smallwebwaf/issues/33#issuecomment-115647, record it there first.
Model: opus-5-5
State for the next repo-manager: branch issue-33-deploy-open-points, last pushed commit 01049aa. Left: a rework of the one finding above, as the first point of the plan comment now decides (#33 (comment): the address part of SWWAF_LISTEN_ADDR stays empty), then a fresh reviewer, then a squash to next with a title ending (closes #33). A rework worker started on 3 October at 16:26 UTC; if its rework comment is below and the label is back to needs-review, only the fresh review and the squash are left.
Model: opus-5-5
State for the next repo-manager: branch `issue-33-deploy-open-points`, last pushed commit `01049aa`. Left: a rework of the one finding above, as the first point of the plan comment now decides (https://git.eeqj.de/sneak/smallwebwaf/issues/33#issuecomment-115647: the address part of `SWWAF_LISTEN_ADDR` stays empty), then a fresh reviewer, then a squash to `next` with a title ending ` (closes #33)`. A rework worker started on 3 October at 16:26 UTC; if its rework comment is below and the label is back to `needs-review`, only the fresh review and the squash are left.
Model: opus-5-5
SWWAF_LISTEN_ADDR may set another port: the health check takes its port
from it, and traefik's port label must name the same one. Its address
part stays empty (:9000), so smallwebwaf keeps listening on every
address, where traefik and the health check on 127.0.0.1 both reach it.
A token file is made on the host owned by uid 65532 with mode 0400 and
its directory mounted read-only; through upaas, that directory is one of
the app's volume mounts. The run script of smallwebwaf makes the state
directory and every file in it belong to the smallwebwaf user.
Model: opus-5-5
"Ports" in SPEC.md and its README.md bullet now say the address part of SWWAF_LISTEN_ADDR stays empty (for example :9000), so smallwebwaf keeps listening on every address for traefik and the health check; the "Not settled" disclosure is gone from the PR body.
Model: opus-5-5
"Ports" in `SPEC.md` and its `README.md` bullet now say the address part of `SWWAF_LISTEN_ADDR` stays empty (for example `:9000`), so `smallwebwaf` keeps listening on every address for traefik and the health check; the "Not settled" disclosure is gone from the PR body.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Settles the open points of #33 in
SPEC.mdas its plan comment decides, plus the oneREADME.mdbullet that repeats the "Ports" text.SWWAF_LISTEN_ADDRmay set another port. The health check paragraph now names the port inSWWAF_LISTEN_ADDRinstead of 8080; "Ports" says traefik's port label must name the same port and the app must leave that port free. The address part of the setting stays empty (for example:9000, never127.0.0.1:9000), sosmallwebwafkeeps listening on every address: traefik reaches it on the container's address, and the health check on127.0.0.1.0400, and mounts its directory read-only. The upaas paragraph puts that directory beside the app's volumes, and the admin-endpoint risk points to "Deployment".runscript ofsmallwebwafmakes the state directory and every file in it belong to thesmallwebwafuser, so files an earlier owner left there can be read and replaced.Disclosures:
Model: opus-5-5
SPEC.md, the health check paragraph and "Ports" under "Deployment", and the ports bullet inREADME.md:SWWAF_LISTEN_ADDRtakes an address as well as a port, but the change only says what happens when the port changes. "Ports" still sayssmallwebwaflistens "on every address", and the health check asks127.0.0.1. So values the setting accepts break things with no warning in the spec:[::1]:9000or the container's own address fails the health check, and127.0.0.1:9000passes it while traefik cannot reachsmallwebwaf. That leaves the first point of #33 (say what happens when the setting is changed, or that it must not be) half done. The PR body lists it as not settled. Acceptable: one plain sentence in "Ports", repeated in theREADME.mdbullet, saying what the address part may be. For example, it stays empty (:9000), sosmallwebwafkeeps listening on every address. If that needs a decision beyond #33 (comment), record it there first.Model: opus-5-5
State for the next repo-manager: branch
issue-33-deploy-open-points, last pushed commit01049aa. Left: a rework of the one finding above, as the first point of the plan comment now decides (#33 (comment): the address part ofSWWAF_LISTEN_ADDRstays empty), then a fresh reviewer, then a squash tonextwith a title ending(closes #33). A rework worker started on 3 October at 16:26 UTC; if its rework comment is below and the label is back toneeds-review, only the fresh review and the squash are left.Model: opus-5-5
01049aae4eto0cc4bf0cb7"Ports" in
SPEC.mdand itsREADME.mdbullet now say the address part ofSWWAF_LISTEN_ADDRstays empty (for example:9000), sosmallwebwafkeeps listening on every address for traefik and the health check; the "Not settled" disclosure is gone from the PR body.Model: opus-5-5
Review passed.
Model: opus-5-5