5 Commits
Author SHA1 Message Date
clawbot 0a94484795 Set UPAAS_PORT as well as PORT in docker-compose.yml (closes #230)
Check / check (pull_request) Successful in 5m13s
upaas reads UPAAS_PORT before PORT, so a UPAAS_PORT line in .env made it
listen on another port than the one the compose file's port mapping and
healthcheck use, and the container never became healthy. The compose file
now sets both to 8080, and its comment and the README's Docker Compose
section say that both are set.

Model: opus-5-5
2026-09-29 05:26:51 +02:00
clawbot 884abf8512 List every setting upaas reads in the README Configuration table (closes #229)
Check / check (pull_request) Successful in 4m1s
The table left out UPAAS_MAINTENANCE_MODE, UPAAS_SESSION_SECRET and
UPAAS_CORS_ORIGINS, and several rows gave the wrong default or effect.
Each row now matches internal/config/config.go and the code that uses
the value: UPAAS_PORT is also read and wins over PORT, UPAAS_DATA_DIR
must be absolute for deploys unless UPAAS_HOST_DATA_DIR is set,
UPAAS_HOST_DATA_DIR falls back to UPAAS_DATA_DIR and must be absolute
when set, UPAAS_DEBUG also drops the session cookie's Secure flag,
UPAAS_SENTRY_DSN is not used, and /metrics exists only when
UPAAS_METRICS_USERNAME is set. A sentence under the table names the
standard Docker client variables. TODO.md records the step.

Model: opus-5-5
Co-authored-by: clawbot <sneak+clawbot@sneak.cloud>
2026-09-29 04:50:31 +02:00
clawbot 194390b61f Merge next into main: UPAAS_ setting names in the README (#228)
Check / check (push) Successful in 7s
On `next`: the README's Configuration table now names the settings upaas actually reads, `UPAAS_DEBUG`, `UPAAS_SENTRY_DSN`, `UPAAS_METRICS_USERNAME` and `UPAAS_METRICS_PASSWORD`, instead of the unprefixed names it ignores (#224). Docs only; no code changes.

For deploying: nothing changes. Anyone who set `DEBUG`, `SENTRY_DSN` or `METRICS_USERNAME`/`METRICS_PASSWORD` as the old table said got no effect and needs the `UPAAS_` names.

The table still leaves out `UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET` and `UPAAS_CORS_ORIGINS`, which upaas also reads.

Model: opus-5-5
Reviewed-on: #228
Co-authored-by: clawbot <35+clawbot@noreply.example.org>
2026-09-29 02:58:45 +02:00
sneak 09d839a4c5 Merge next into main: docker-compose.yml for deploying upaas (#226)
Check / check (push) Successful in 5s
Reviewed-on: #226
2026-09-29 01:41:34 +02:00
clawbot 7319cf4158 Add docker-compose.yml for deploying upaas (closes #223)
Check / check (pull_request) Successful in 3m19s
The compose file builds the image from this repo, mounts the Docker
socket and HOST_DATA_DIR (passed to upaas as UPAAS_HOST_DATA_DIR),
reads settings from .env, and restarts unless stopped. The port is
published on 127.0.0.1 only, for a TLS-terminating proxy in front.
PORT and UPAAS_DATA_DIR are pinned so .env cannot move upaas off the
port mapping, the healthcheck (busybox wget) or the data mount.

upaas now refuses to start when UPAAS_HOST_DATA_DIR is set to a
relative path; when unset it still falls back to the data directory.

The README's plain-HTTP Compose example becomes a short deploy section
that points at the file. .env is added to .dockerignore.

Model: opus-5-5
2026-09-28 12:11:36 +02:00
3 changed files with 44 additions and 17 deletions
+21 -13
View File
@@ -192,16 +192,23 @@ This ensures the main branch always contains clean, tested, working code.
Environment variables: Environment variables:
| Variable | Description | Default | | Variable | Description | Default |
| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- | | ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- |
| `PORT` | HTTP listen port | 8080 | | `PORT` | HTTP listen port. `UPAAS_PORT` is also read and wins when both are set. | 8080 |
| `UPAAS_DATA_DIR` | Data directory for SQLite and keys | `./data` (local dev only — use absolute path for Docker) | | `UPAAS_DATA_DIR` | Directory for the SQLite database, session key, builds and deployment logs. Deploys need it to be an absolute path unless `UPAAS_HOST_DATA_DIR` is set. | `./data` (the Docker image sets `/var/lib/upaas`) |
| `UPAAS_HOST_DATA_DIR` | Host path for DATA_DIR (when running in container) | _(none — must be set to an absolute path)_ | | `UPAAS_HOST_DATA_DIR` | Host path of `UPAAS_DATA_DIR`, needed when upaas runs in a container so the bind mounts it passes to Docker point at the right host directory. When set, it must be absolute, or upaas refuses to start. | the value of `UPAAS_DATA_DIR` |
| `UPAAS_DOCKER_HOST` | Docker socket path | unix:///var/run/docker.sock | | `UPAAS_DOCKER_HOST` | Docker daemon address | unix:///var/run/docker.sock |
| `UPAAS_PLAINTEXT_HTTP` | Set when µPaaS is reached over plain HTTP (no TLS-terminating proxy in front) so CSRF origin checks use `http://`. Leave unset behind a TLS-terminating reverse proxy. | false | | `UPAAS_PLAINTEXT_HTTP` | Set when µPaaS is reached over plain HTTP (no TLS-terminating proxy in front) so CSRF origin checks use `http://`. Leave unset behind a TLS-terminating reverse proxy. | false |
| `DEBUG` | Enable debug logging | false | | `UPAAS_DEBUG` | Enable debug logging. Also sends the session cookie without the `Secure` flag. | false |
| `SENTRY_DSN` | Sentry error reporting DSN | "" | | `UPAAS_SENTRY_DSN` | Read but not used: upaas sends nothing to Sentry | "" |
| `METRICS_USERNAME` | Basic auth for /metrics | "" | | `UPAAS_METRICS_USERNAME` | When set, `/metrics` is served behind basic auth with this username. When unset, there is no `/metrics`. | "" |
| `METRICS_PASSWORD` | Basic auth for /metrics | "" | | `UPAAS_METRICS_PASSWORD` | Basic auth password for `/metrics` | "" |
| `UPAAS_MAINTENANCE_MODE` | Only shown as `maintenanceMode` in the `/health` response; it blocks nothing | false |
| `UPAAS_SESSION_SECRET` | Key that signs the session and CSRF cookies. When unset, a random key is generated once and kept in `$UPAAS_DATA_DIR/session.key`. | "" |
| `UPAAS_CORS_ORIGINS` | Comma-separated origins allowed to make cross-origin requests with cookies. When unset, no CORS headers are sent. | "" |
The Docker client also reads the standard `DOCKER_API_VERSION`,
`DOCKER_CERT_PATH` and `DOCKER_TLS_VERIFY` variables; `UPAAS_DOCKER_HOST`, which
has a default, always overrides `DOCKER_HOST`.
## Running with Docker ## Running with Docker
@@ -230,10 +237,11 @@ HOST_DATA_DIR=/srv/upaas/data
``` ```
Other settings from [Configuration](#configuration) go in the same file, except Other settings from [Configuration](#configuration) go in the same file, except
`PORT` and `UPAAS_DATA_DIR`: the compose file sets them to 8080 and `PORT`, `UPAAS_PORT` and `UPAAS_DATA_DIR`: the compose file sets both port
`/var/lib/upaas`, overriding `.env`, to match its port mapping, healthcheck and settings to 8080 and `UPAAS_DATA_DIR` to `/var/lib/upaas`, overriding `.env`, to
data directory mount. Then run `docker compose up -d` from the repo root; match its port mapping, healthcheck and data directory mount. Then run
`docker compose ps` shows the container as healthy once `/health` answers. `docker compose up -d` from the repo root; `docker compose ps` shows the
container as healthy once `/health` answers.
**Important**: `HOST_DATA_DIR` **must** be an **absolute path** on the host. It **Important**: `HOST_DATA_DIR` **must** be an **absolute path** on the host. It
is bind-mounted into the container and passed as `UPAAS_HOST_DATA_DIR` so that is bind-mounted into the container and passed as `UPAAS_HOST_DATA_DIR` so that
+17
View File
@@ -20,6 +20,23 @@ regress.
# Completed Steps # Completed Steps
- 2026-09-29: `docker-compose.yml` now sets `UPAAS_PORT` to 8080 as well as
`PORT`, since upaas reads `UPAAS_PORT` first and a `UPAAS_PORT` in `.env` made
it listen away from the port mapping and healthcheck; the README's Compose
section names both (#230).
- 2026-09-29: The README Configuration table now lists every setting upaas
reads, adding `UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET` and
`UPAAS_CORS_ORIGINS`, and gives the real default and effect of each:
`UPAAS_PORT` wins over `PORT`, `UPAAS_HOST_DATA_DIR` falls back to
`UPAAS_DATA_DIR`, `UPAAS_DEBUG` drops the session cookie's `Secure` flag, and
`UPAAS_SENTRY_DSN` is not used (#229).
- 2026-09-28: The README Configuration table now names `UPAAS_DEBUG`,
`UPAAS_SENTRY_DSN`, `UPAAS_METRICS_USERNAME` and `UPAAS_METRICS_PASSWORD`, the
names upaas actually reads (the unprefixed names it listed were ignored), and
the `UPAAS_HOST_DATA_DIR` row refers to `UPAAS_DATA_DIR` (#224).
- 2026-09-28: Added `docker-compose.yml` for deploying upaas: settings from - 2026-09-28: Added `docker-compose.yml` for deploying upaas: settings from
`.env`, the port published on `127.0.0.1` only for a TLS proxy in front, and a `.env`, the port published on `127.0.0.1` only for a TLS proxy in front, and a
healthcheck against `/health`; the README's plain-HTTP Compose example is healthcheck against `/health`; the README's plain-HTTP Compose example is
+4 -2
View File
@@ -7,9 +7,11 @@ services:
# Every line of .env is passed to upaas as an environment variable. # Every line of .env is passed to upaas as an environment variable.
env_file: .env env_file: .env
environment: environment:
# Overrides any PORT in .env, so upaas listens where the port mapping # Override any PORT or UPAAS_PORT in .env, so upaas listens where the
# and healthcheck below expect it. # port mapping and healthcheck below expect it. Both are set because
# upaas reads UPAAS_PORT first.
PORT: "8080" PORT: "8080"
UPAAS_PORT: "8080"
# Overrides any UPAAS_DATA_DIR in .env, so the database stays on the # Overrides any UPAAS_DATA_DIR in .env, so the database stays on the
# HOST_DATA_DIR mount below instead of inside the container. # HOST_DATA_DIR mount below instead of inside the container.
UPAAS_DATA_DIR: /var/lib/upaas UPAAS_DATA_DIR: /var/lib/upaas