Author SHA1 Message Date
clawbot f01637d62c List every setting upaas reads in the README Configuration table (closes #229)
Check / check (pull_request) Skipped
The table left out UPAAS_MAINTENANCE_MODE, UPAAS_SESSION_SECRET and
UPAAS_CORS_ORIGINS, and several rows gave the wrong default or effect.
Each row now matches internal/config/config.go and the code that uses
the value: UPAAS_PORT is also read and wins over PORT, UPAAS_DATA_DIR
must be absolute for deploys unless UPAAS_HOST_DATA_DIR is set,
UPAAS_HOST_DATA_DIR falls back to UPAAS_DATA_DIR and must be absolute
when set, UPAAS_DEBUG also drops the session cookie's Secure flag,
UPAAS_SENTRY_DSN is not used, and /metrics exists only when
UPAAS_METRICS_USERNAME is set. A sentence under the table names the
standard Docker client variables. TODO.md records the step.

Model: opus-5-5
2026-09-29 02:15:00 +00:00
clawbot 194390b61f Merge next into main: UPAAS_ setting names in the README (#228)
Check / check (push) Successful in 7s
On `next`: the README's Configuration table now names the settings upaas actually reads, `UPAAS_DEBUG`, `UPAAS_SENTRY_DSN`, `UPAAS_METRICS_USERNAME` and `UPAAS_METRICS_PASSWORD`, instead of the unprefixed names it ignores (#224). Docs only; no code changes.

For deploying: nothing changes. Anyone who set `DEBUG`, `SENTRY_DSN` or `METRICS_USERNAME`/`METRICS_PASSWORD` as the old table said got no effect and needs the `UPAAS_` names.

The table still leaves out `UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET` and `UPAAS_CORS_ORIGINS`, which upaas also reads.

Model: opus-5-5
Reviewed-on: #228
Co-authored-by: clawbot <35+clawbot@noreply.example.org>
2026-09-29 02:58:45 +02:00
sneak 09d839a4c5 Merge next into main: docker-compose.yml for deploying upaas (#226)
Check / check (push) Successful in 5s
Reviewed-on: #226
2026-09-29 01:41:34 +02:00
clawbot 7319cf4158 Add docker-compose.yml for deploying upaas (closes #223)
Check / check (pull_request) Successful in 3m19s
The compose file builds the image from this repo, mounts the Docker
socket and HOST_DATA_DIR (passed to upaas as UPAAS_HOST_DATA_DIR),
reads settings from .env, and restarts unless stopped. The port is
published on 127.0.0.1 only, for a TLS-terminating proxy in front.
PORT and UPAAS_DATA_DIR are pinned so .env cannot move upaas off the
port mapping, the healthcheck (busybox wget) or the data mount.

upaas now refuses to start when UPAAS_HOST_DATA_DIR is set to a
relative path; when unset it still falls back to the data directory.

The README's plain-HTTP Compose example becomes a short deploy section
that points at the file. .env is added to .dockerignore.

Model: opus-5-5
2026-09-28 12:11:36 +02:00
6 changed files with 130 additions and 40 deletions
+1
View File
@@ -1,4 +1,5 @@
.git
.env
bin/
.editorconfig
.vscode/
+36 -38
View File
@@ -192,16 +192,23 @@ This ensures the main branch always contains clean, tested, working code.
Environment variables:
| Variable | Description | Default |
| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
| `PORT` | HTTP listen port | 8080 |
| `UPAAS_DATA_DIR` | Data directory for SQLite and keys | `./data` (local dev only — use absolute path for Docker) |
| `UPAAS_HOST_DATA_DIR` | Host path for DATA_DIR (when running in container) | _(none — must be set to an absolute path)_ |
| `UPAAS_DOCKER_HOST` | Docker socket path | unix:///var/run/docker.sock |
| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- |
| `PORT` | HTTP listen port. `UPAAS_PORT` is also read and wins when both are set. | 8080 |
| `UPAAS_DATA_DIR` | Directory for the SQLite database, session key, builds and deployment logs. Deploys need it to be an absolute path unless `UPAAS_HOST_DATA_DIR` is set. | `./data` (the Docker image sets `/var/lib/upaas`) |
| `UPAAS_HOST_DATA_DIR` | Host path of `UPAAS_DATA_DIR`, needed when upaas runs in a container so the bind mounts it passes to Docker point at the right host directory. When set, it must be absolute, or upaas refuses to start. | the value of `UPAAS_DATA_DIR` |
| `UPAAS_DOCKER_HOST` | Docker daemon address | unix:///var/run/docker.sock |
| `UPAAS_PLAINTEXT_HTTP` | Set when µPaaS is reached over plain HTTP (no TLS-terminating proxy in front) so CSRF origin checks use `http://`. Leave unset behind a TLS-terminating reverse proxy. | false |
| `DEBUG` | Enable debug logging | false |
| `SENTRY_DSN` | Sentry error reporting DSN | "" |
| `METRICS_USERNAME` | Basic auth for /metrics | "" |
| `METRICS_PASSWORD` | Basic auth for /metrics | "" |
| `UPAAS_DEBUG` | Enable debug logging. Also sends the session cookie without the `Secure` flag. | false |
| `UPAAS_SENTRY_DSN` | Read but not used: upaas sends nothing to Sentry | "" |
| `UPAAS_METRICS_USERNAME` | When set, `/metrics` is served behind basic auth with this username. When unset, there is no `/metrics`. | "" |
| `UPAAS_METRICS_PASSWORD` | Basic auth password for `/metrics` | "" |
| `UPAAS_MAINTENANCE_MODE` | Only shown as `maintenanceMode` in the `/health` response; it blocks nothing | false |
| `UPAAS_SESSION_SECRET` | Key that signs the session and CSRF cookies. When unset, a random key is generated once and kept in `$UPAAS_DATA_DIR/session.key`. | "" |
| `UPAAS_CORS_ORIGINS` | Comma-separated origins allowed to make cross-origin requests with cookies. When unset, no CORS headers are sent. | "" |
The Docker client also reads the standard `DOCKER_API_VERSION`,
`DOCKER_CERT_PATH` and `DOCKER_TLS_VERIFY` variables; `UPAAS_DOCKER_HOST`, which
has a default, always overrides `DOCKER_HOST`.
## Running with Docker
@@ -219,39 +226,30 @@ This recipe serves plain HTTP, so `UPAAS_PLAINTEXT_HTTP=true` is required for
setup and every other form to pass the CSRF origin check. Behind a
TLS-terminating reverse proxy, drop that line.
### Docker Compose
### Deploying with Docker Compose
```yaml
services:
upaas:
build: .
restart: unless-stopped
ports:
- "8080:8080"
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ${HOST_DATA_DIR}:/var/lib/upaas
environment:
- UPAAS_HOST_DATA_DIR=${HOST_DATA_DIR}
# Set when serving plain HTTP (no TLS-terminating proxy); drop behind one
- UPAAS_PLAINTEXT_HTTP=true
# Optional: uncomment to enable debug logging
# - DEBUG=true
# Optional: Sentry error reporting
# - SENTRY_DSN=https://...
# Optional: Prometheus metrics auth
# - METRICS_USERNAME=prometheus
# - METRICS_PASSWORD=secret
[`docker-compose.yml`](docker-compose.yml) builds the image from this repo and
runs it with the Docker socket and the data directory mounted. It reads its
settings from a `.env` file next to it, which needs at least:
```bash
HOST_DATA_DIR=/srv/upaas/data
```
**Important**: You **must** set `HOST_DATA_DIR` to an **absolute path** on the
host before running `docker compose up`. This value is bind-mounted into the
container and passed as `UPAAS_HOST_DATA_DIR` so that Docker bind mounts during
builds resolve correctly. Relative paths (e.g. `./data`) will break container
builds because the Docker daemon resolves paths relative to the host, not the
container.
Other settings from [Configuration](#configuration) go in the same file, except
`PORT` and `UPAAS_DATA_DIR`: the compose file sets them to 8080 and
`/var/lib/upaas`, overriding `.env`, to match its port mapping, healthcheck and
data directory mount. Then run `docker compose up -d` from the repo root;
`docker compose ps` shows the container as healthy once `/health` answers.
Example: `HOST_DATA_DIR=/srv/upaas/data docker compose up -d`
**Important**: `HOST_DATA_DIR` **must** be an **absolute path** on the host. It
is bind-mounted into the container and passed as `UPAAS_HOST_DATA_DIR` so that
Docker bind mounts during builds resolve correctly, because the Docker daemon
resolves paths on the host, not in the container. upaas refuses to start when
`UPAAS_HOST_DATA_DIR` is a relative path such as `./data`.
The port is published on `127.0.0.1:8080` only, for a TLS-terminating reverse
proxy in front of it. Leave `UPAAS_PLAINTEXT_HTTP` unset behind that proxy.
Apps are built with BuildKit, so the stages of a multi-stage build are kept in
Docker's build cache rather than as untagged images. Docker Engine 28.2 and
+18
View File
@@ -20,6 +20,24 @@ regress.
# Completed Steps
- 2026-09-29: The README Configuration table now lists every setting upaas
reads, adding `UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET` and
`UPAAS_CORS_ORIGINS`, and gives the real default and effect of each:
`UPAAS_PORT` wins over `PORT`, `UPAAS_HOST_DATA_DIR` falls back to
`UPAAS_DATA_DIR`, `UPAAS_DEBUG` drops the session cookie's `Secure` flag, and
`UPAAS_SENTRY_DSN` is not used (#229).
- 2026-09-28: The README Configuration table now names `UPAAS_DEBUG`,
`UPAAS_SENTRY_DSN`, `UPAAS_METRICS_USERNAME` and `UPAAS_METRICS_PASSWORD`, the
names upaas actually reads (the unprefixed names it listed were ignored), and
the `UPAAS_HOST_DATA_DIR` row refers to `UPAAS_DATA_DIR` (#224).
- 2026-09-28: Added `docker-compose.yml` for deploying upaas: settings from
`.env`, the port published on `127.0.0.1` only for a TLS proxy in front, and a
healthcheck against `/health`; the README's plain-HTTP Compose example is
replaced by a short deploy section. upaas now refuses to start when
`UPAAS_HOST_DATA_DIR` is set to a relative path (#223).
- 2026-09-23: Apps are now built with BuildKit, so the stages of a multi-stage
build stay in Docker's size-limited build cache instead of piling up as
untagged images; build progress is still written to the deployment log as
+30
View File
@@ -0,0 +1,30 @@
# Runs upaas. Put settings in .env next to this file; see "Deploying with
# Docker Compose" in README.md.
services:
upaas:
build: .
restart: unless-stopped
# Every line of .env is passed to upaas as an environment variable.
env_file: .env
environment:
# Overrides any PORT in .env, so upaas listens where the port mapping
# and healthcheck below expect it.
PORT: "8080"
# Overrides any UPAAS_DATA_DIR in .env, so the database stays on the
# HOST_DATA_DIR mount below instead of inside the container.
UPAAS_DATA_DIR: /var/lib/upaas
# The Docker daemon resolves app bind mounts on the host, so upaas must
# know the host path of its data directory.
UPAAS_HOST_DATA_DIR: ${HOST_DATA_DIR:?set HOST_DATA_DIR in .env to an absolute host path}
volumes:
- /var/run/docker.sock:/var/run/docker.sock
- ${HOST_DATA_DIR:?set HOST_DATA_DIR in .env to an absolute host path}:/var/lib/upaas
# Loopback only, for a TLS-terminating reverse proxy in front. Leave
# UPAAS_PLAINTEXT_HTTP unset behind that proxy.
ports:
- "127.0.0.1:8080:8080"
healthcheck:
test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/health"]
interval: 30s
timeout: 5s
retries: 3
+10
View File
@@ -32,6 +32,12 @@ const (
filePermissions = 0o600
)
// errHostDataDirNotAbsolute is returned when UPAAS_HOST_DATA_DIR is set to a
// relative path, which the Docker daemon cannot resolve for app bind mounts.
var errHostDataDirNotAbsolute = errors.New(
"UPAAS_HOST_DATA_DIR must be an absolute path",
)
// Params contains dependencies for Config.
type Params struct {
fx.In
@@ -124,6 +130,10 @@ func buildConfig(log *slog.Logger, params *Params) (*Config, error) {
dataDir := viper.GetString("DATA_DIR")
hostDataDir := viper.GetString("HOST_DATA_DIR")
if hostDataDir != "" && !filepath.IsAbs(hostDataDir) {
return nil, fmt.Errorf("%w, got %q", errHostDataDirNotAbsolute, hostDataDir)
}
if hostDataDir == "" {
hostDataDir = dataDir
}
+33
View File
@@ -0,0 +1,33 @@
package config //nolint:testpackage // tests unexported buildConfig
import (
"errors"
"log/slog"
"testing"
)
func TestBuildConfigRejectsRelativeHostDataDir(t *testing.T) {
t.Setenv("UPAAS_HOST_DATA_DIR", "./data")
setupViper("upaas")
_, err := buildConfig(slog.Default(), &Params{})
if !errors.Is(err, errHostDataDirNotAbsolute) {
t.Fatalf("expected errHostDataDirNotAbsolute, got %v", err)
}
}
func TestBuildConfigHostDataDirDefaultsToDataDir(t *testing.T) {
t.Setenv("UPAAS_DATA_DIR", "./data")
t.Setenv("UPAAS_HOST_DATA_DIR", "")
t.Setenv("UPAAS_SESSION_SECRET", "test-secret")
setupViper("upaas")
cfg, err := buildConfig(slog.Default(), &Params{})
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
if cfg.HostDataDir != "./data" {
t.Errorf("expected HostDataDir ./data, got %q", cfg.HostDataDir)
}
}