1 Commits
Author SHA1 Message Date
sneak bead5134c2 Add docker-compose.yml for deploying upaas (closes #223)
Check / check (pull_request) Skipped
The compose file builds the image from this repo, mounts the Docker
socket and HOST_DATA_DIR (passed to upaas as UPAAS_HOST_DATA_DIR),
reads settings from .env, and restarts unless stopped. The port is
published on 127.0.0.1 only, for a TLS-terminating proxy in front, and
UPAAS_PLAINTEXT_HTTP is left unset. A healthcheck against /health uses
the runtime image's busybox wget.

The README's plain-HTTP Compose example becomes a short deploy section
that points at the file. .env is added to .dockerignore so settings are
not copied into the build.

Model: opus-5-5
2026-09-28 09:28:36 +00:00
5 changed files with 7 additions and 55 deletions
+6 -7
View File
@@ -229,16 +229,15 @@ settings from a `.env` file next to it, which needs at least:
HOST_DATA_DIR=/srv/upaas/data
```
Other settings from [Configuration](#configuration) go in the same file, except
`PORT`: the compose file sets it to 8080, overriding `.env`, to match its port
mapping and healthcheck. Then run `docker compose up -d` from the repo root;
`docker compose ps` shows the container as healthy once `/health` answers.
Other settings from [Configuration](#configuration) go in the same file. Then
run `docker compose up -d` from the repo root; `docker compose ps` shows the
container as healthy once `/health` answers.
**Important**: `HOST_DATA_DIR` **must** be an **absolute path** on the host. It
is bind-mounted into the container and passed as `UPAAS_HOST_DATA_DIR` so that
Docker bind mounts during builds resolve correctly, because the Docker daemon
resolves paths on the host, not in the container. upaas refuses to start when
`UPAAS_HOST_DATA_DIR` is a relative path such as `./data`.
Docker bind mounts during builds resolve correctly. Relative paths (e.g.
`./data`) will break container builds because the Docker daemon resolves paths
relative to the host, not the container.
The port is published on `127.0.0.1:8080` only, for a TLS-terminating reverse
proxy in front of it. Leave `UPAAS_PLAINTEXT_HTTP` unset behind that proxy.
+1 -2
View File
@@ -23,8 +23,7 @@ regress.
- 2026-09-28: Added `docker-compose.yml` for deploying upaas: settings from
`.env`, the port published on `127.0.0.1` only for a TLS proxy in front, and a
healthcheck against `/health`; the README's plain-HTTP Compose example is
replaced by a short deploy section. upaas now refuses to start when
`UPAAS_HOST_DATA_DIR` is set to a relative path (#223).
replaced by a short deploy section (#223).
- 2026-09-23: Apps are now built with BuildKit, so the stages of a multi-stage
build stay in Docker's size-limited build cache instead of piling up as
-3
View File
@@ -7,9 +7,6 @@ services:
# Every line of .env is passed to upaas as an environment variable.
env_file: .env
environment:
# Overrides any PORT in .env, so upaas listens where the port mapping
# and healthcheck below expect it.
PORT: "8080"
# The Docker daemon resolves app bind mounts on the host, so upaas must
# know the host path of its data directory.
UPAAS_HOST_DATA_DIR: ${HOST_DATA_DIR:?set HOST_DATA_DIR in .env to an absolute host path}
-10
View File
@@ -32,12 +32,6 @@ const (
filePermissions = 0o600
)
// errHostDataDirNotAbsolute is returned when UPAAS_HOST_DATA_DIR is set to a
// relative path, which the Docker daemon cannot resolve for app bind mounts.
var errHostDataDirNotAbsolute = errors.New(
"UPAAS_HOST_DATA_DIR must be an absolute path",
)
// Params contains dependencies for Config.
type Params struct {
fx.In
@@ -130,10 +124,6 @@ func buildConfig(log *slog.Logger, params *Params) (*Config, error) {
dataDir := viper.GetString("DATA_DIR")
hostDataDir := viper.GetString("HOST_DATA_DIR")
if hostDataDir != "" && !filepath.IsAbs(hostDataDir) {
return nil, fmt.Errorf("%w, got %q", errHostDataDirNotAbsolute, hostDataDir)
}
if hostDataDir == "" {
hostDataDir = dataDir
}
-33
View File
@@ -1,33 +0,0 @@
package config //nolint:testpackage // tests unexported buildConfig
import (
"errors"
"log/slog"
"testing"
)
func TestBuildConfigRejectsRelativeHostDataDir(t *testing.T) {
t.Setenv("UPAAS_HOST_DATA_DIR", "./data")
setupViper("upaas")
_, err := buildConfig(slog.Default(), &Params{})
if !errors.Is(err, errHostDataDirNotAbsolute) {
t.Fatalf("expected errHostDataDirNotAbsolute, got %v", err)
}
}
func TestBuildConfigHostDataDirDefaultsToDataDir(t *testing.T) {
t.Setenv("UPAAS_DATA_DIR", "./data")
t.Setenv("UPAAS_HOST_DATA_DIR", "")
t.Setenv("UPAAS_SESSION_SECRET", "test-secret")
setupViper("upaas")
cfg, err := buildConfig(slog.Default(), &Params{})
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
if cfg.HostDataDir != "./data" {
t.Errorf("expected HostDataDir ./data, got %q", cfg.HostDataDir)
}
}