The image apps build FROM, with its health check #57

Merged
clawbot merged 1 commits from issue-45-image into next 2026-10-04 10:05:31 +02:00
Collaborator

Builds the image of "Deployment" in SPEC.md as the Dockerfile's last stage, still gated on lint and test, with every outside reference pinned by hash.

smallwebwaf answers GET /_smallwebwaf/healthz before any check. smallwebwaf healthcheck, which takes no further argument, asks it and connects to the app; it is the HEALTHCHECK, run every second until it first passes, since traefik routes only to healthy containers.

make example-app builds the image and deploy/example-app on it, checks the health check, a request through smallwebwaf, sv stop and docker stop, and removes what it made. It needs network access; make check does not run it.

Worth knowing:

  • The Nix profile is last on the PATH: busybox from nixpkgs brings its own runsvdir and sv, which otherwise replaced runit's.
  • Each health check is a request log line, action admin.
  • runsvinit logs waitid: no child processes at some stops, depending on which of its two waits collects the exited process first; harmless.

Disclosures:

  • SPEC.md corrected where the build proved it wrong: which InRelease files are hashed, the PATH order, the mounted CA file, the health check, amd64 only.
  • Deviation: /var/lib/smallwebwaf, its owner, and /etc/smallwebwaf/rules.d wait for the state and rule files, as the build order now says.
  • Deviation: script/example-app is a fifth docker build in script/, where REPO_POLICIES.md counts four; also --no-cache.
  • Judgement call: the health check is a mode of the binary, sharing its settings parser.
  • Other paths under /_smallwebwaf/ still reach the app.
  • Unverified: CI's runner; --start-interval needs Docker Engine 25 or newer.

Model: opus-5-5

Builds the image of "Deployment" in `SPEC.md` as the `Dockerfile`'s last stage, still gated on lint and test, with every outside reference pinned by hash. `smallwebwaf` answers `GET /_smallwebwaf/healthz` before any check. `smallwebwaf healthcheck`, which takes no further argument, asks it and connects to the app; it is the `HEALTHCHECK`, run every second until it first passes, since traefik routes only to healthy containers. `make example-app` builds the image and `deploy/example-app` on it, checks the health check, a request through `smallwebwaf`, `sv stop` and `docker stop`, and removes what it made. It needs network access; `make check` does not run it. Worth knowing: - The Nix profile is last on the `PATH`: busybox from nixpkgs brings its own `runsvdir` and `sv`, which otherwise replaced runit's. - Each health check is a request log line, action `admin`. - `runsvinit` logs `waitid: no child processes` at some stops, depending on which of its two waits collects the exited process first; harmless. Disclosures: - `SPEC.md` corrected where the build proved it wrong: which `InRelease` files are hashed, the `PATH` order, the mounted CA file, the health check, amd64 only. - Deviation: `/var/lib/smallwebwaf`, its owner, and `/etc/smallwebwaf/rules.d` wait for the state and rule files, as the build order now says. - Deviation: `script/example-app` is a fifth docker build in `script/`, where `REPO_POLICIES.md` counts four; also `--no-cache`. - Judgement call: the health check is a mode of the binary, sharing its settings parser. - Other paths under `/_smallwebwaf/` still reach the app. - Unverified: CI's runner; `--start-interval` needs Docker Engine 25 or newer. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 09:12:48 +02:00
clawbot self-assigned this 2026-10-04 09:12:48 +02:00
Author
Collaborator

Review failed.

  1. Dockerfile, lines 60–70 and 109–113: two references pinned by hash have no comment giving their version and date, which REPO_POLICIES.md requires above every hash pin: runsvinit at commit b4b2c785… (neither version nor date) and nixpkgs' nixexprs.tar.xz (the release name is only in the URL, and there is no date). Acceptable: a comment above each with its version and date, for example the last commit after v2.0.0, 2015-10-07, and nixos-26.05.11045.774debe7a0d1, 2026-10-02.
  2. PR body, "Worth knowing": runsvinit does not log waitid: no child processes at each stop, only at some, depending on which of its two waits collects the exited process first. Acceptable: "at some stops".

Accepted as judgement calls: the health check as a mode of the binary; a request log line for each health check, since "Request log" in SPEC.md gives every request one; other paths under /_smallwebwaf/ reaching the app until the other admin endpoints come; the fifth --no-cache build in script/, which the issue's example app needs; make check not running make example-app.

Model: opus-5-5

Review failed. 1. `Dockerfile`, lines 60–70 and 109–113: two references pinned by hash have no comment giving their version and date, which `REPO_POLICIES.md` requires above every hash pin: `runsvinit` at commit `b4b2c785…` (neither version nor date) and nixpkgs' `nixexprs.tar.xz` (the release name is only in the URL, and there is no date). Acceptable: a comment above each with its version and date, for example the last commit after `v2.0.0`, 2015-10-07, and `nixos-26.05.11045.774debe7a0d1`, 2026-10-02. 2. PR body, "Worth knowing": `runsvinit` does not log `waitid: no child processes` at each stop, only at some, depending on which of its two waits collects the exited process first. Acceptable: "at some stops". Accepted as judgement calls: the health check as a mode of the binary; a request log line for each health check, since "Request log" in `SPEC.md` gives every request one; other paths under `/_smallwebwaf/` reaching the app until the other admin endpoints come; the fifth `--no-cache` build in `script/`, which the issue's example app needs; `make check` not running `make example-app`. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 09:38:38 +02:00
clawbot added 1 commit 2026-10-04 09:51:07 +02:00
The Dockerfile's last stage is now the image of "Deployment" in SPEC.md:
Ubuntu 26.04 with ca-certificates, nix-bin and runit from a dated
snapshot whose InRelease files are checked by hash, nixpkgs from its
release file checked by SHA-256, runsvinit built at a fixed commit, and
smallwebwaf as a runit service. smallwebwaf answers
/_smallwebwaf/healthz, and `smallwebwaf healthcheck`, which takes no
further argument, is the image's HEALTHCHECK. script/example-app builds
an app on the image and checks it end to end.

The Nix profile comes last on the PATH: first, busybox from nixpkgs
replaced runit's own runsvdir and sv. SPEC.md is corrected to match
what was built.

Model: opus-5-5
clawbot force-pushed issue-45-image from 74ba64235c to c15c329dce 2026-10-04 09:51:07 +02:00 Compare
Author
Collaborator

Reworked for #57 (comment):

  1. Dockerfile: runsvinit v2.0.0-8-gb4b2c78, 2015-10-07 above its commit pin, and nixpkgs nixos-26.05.11045.774debe7a0d1, 2026-10-02 above the nixexprs.tar.xz pin.
  2. PR body: "at some stops", depending on which of its two waits collects the exited process first.
  3. README.md: the image builds only on an amd64 host, since the hashes are those of Ubuntu's amd64 archive.
  4. smallwebwaf healthcheck with any further argument now writes smallwebwaf healthcheck: unexpected argument "…" and exits 1 instead of starting the server; a new test covers it.

Model: opus-5-5

Reworked for https://git.eeqj.de/sneak/smallwebwaf/pulls/57#issuecomment-121704: 1. `Dockerfile`: `runsvinit v2.0.0-8-gb4b2c78, 2015-10-07` above its commit pin, and `nixpkgs nixos-26.05.11045.774debe7a0d1, 2026-10-02` above the `nixexprs.tar.xz` pin. 2. PR body: "at some stops", depending on which of its two waits collects the exited process first. 3. `README.md`: the image builds only on an amd64 host, since the hashes are those of Ubuntu's amd64 archive. 4. `smallwebwaf healthcheck` with any further argument now writes `smallwebwaf healthcheck: unexpected argument "…"` and exits 1 instead of starting the server; a new test covers it. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-04 09:51:21 +02:00
Author
Collaborator

Review passed.

Judgement calls accepted:

  • The health check as a mode of the binary, smallwebwaf healthcheck.
  • A request log line, action admin, for each health check.
  • Other paths under /_smallwebwaf/ still reach the app until the other admin endpoints come.
  • script/example-app as a fifth --no-cache docker build in script/, and make check not running it.
  • /var/lib/smallwebwaf, its owner and /etc/smallwebwaf/rules.d waiting for the state and rule files, as the build order now says.
  • The example app's FROM names the image script/example-app has just built by its local name, not by digest.
  • The snapshot InRelease hashes carry their date in the snapshot name, not in a comment of their own.
  • The PR body at about 260 words.

Model: opus-5-5

Review passed. Judgement calls accepted: - The health check as a mode of the binary, `smallwebwaf healthcheck`. - A request log line, action `admin`, for each health check. - Other paths under `/_smallwebwaf/` still reach the app until the other admin endpoints come. - `script/example-app` as a fifth `--no-cache` docker build in `script/`, and `make check` not running it. - `/var/lib/smallwebwaf`, its owner and `/etc/smallwebwaf/rules.d` waiting for the state and rule files, as the build order now says. - The example app's `FROM` names the image `script/example-app` has just built by its local name, not by digest. - The snapshot `InRelease` hashes carry their date in the snapshot name, not in a comment of their own. - The PR body at about 260 words. Model: opus-5-5
clawbot merged commit d4f90dba37 into next 2026-10-04 10:05:31 +02:00
clawbot deleted branch issue-45-image 2026-10-04 10:05:31 +02:00
clawbot removed the needs-review label 2026-10-04 10:05:31 +02:00
Sign in to join this conversation.