Compare commits
1
Commits
next
..
bf3048aaae
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bf3048aaae |
@@ -192,23 +192,16 @@ This ensures the main branch always contains clean, tested, working code.
|
||||
Environment variables:
|
||||
|
||||
| Variable | Description | Default |
|
||||
| ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- |
|
||||
| `PORT` | HTTP listen port. `UPAAS_PORT` is also read and wins when both are set. | 8080 |
|
||||
| `UPAAS_DATA_DIR` | Directory for the SQLite database, session key, builds and deployment logs. Deploys need it to be an absolute path unless `UPAAS_HOST_DATA_DIR` is set. | `./data` (the Docker image sets `/var/lib/upaas`) |
|
||||
| `UPAAS_HOST_DATA_DIR` | Host path of `UPAAS_DATA_DIR`, needed when upaas runs in a container so the bind mounts it passes to Docker point at the right host directory. When set, it must be absolute, or upaas refuses to start. | the value of `UPAAS_DATA_DIR` |
|
||||
| `UPAAS_DOCKER_HOST` | Docker daemon address | unix:///var/run/docker.sock |
|
||||
| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
|
||||
| `PORT` | HTTP listen port | 8080 |
|
||||
| `UPAAS_DATA_DIR` | Data directory for SQLite and keys | `./data` (local dev only — use absolute path for Docker) |
|
||||
| `UPAAS_HOST_DATA_DIR` | Host path for DATA_DIR (when running in container) | _(none — must be set to an absolute path)_ |
|
||||
| `UPAAS_DOCKER_HOST` | Docker socket path | unix:///var/run/docker.sock |
|
||||
| `UPAAS_PLAINTEXT_HTTP` | Set when µPaaS is reached over plain HTTP (no TLS-terminating proxy in front) so CSRF origin checks use `http://`. Leave unset behind a TLS-terminating reverse proxy. | false |
|
||||
| `UPAAS_DEBUG` | Enable debug logging. Also sends the session cookie without the `Secure` flag. | false |
|
||||
| `UPAAS_SENTRY_DSN` | Read but not used: upaas sends nothing to Sentry | "" |
|
||||
| `UPAAS_METRICS_USERNAME` | When set, `/metrics` is served behind basic auth with this username. When unset, there is no `/metrics`. | "" |
|
||||
| `UPAAS_METRICS_PASSWORD` | Basic auth password for `/metrics` | "" |
|
||||
| `UPAAS_MAINTENANCE_MODE` | Only shown as `maintenanceMode` in the `/health` response; it blocks nothing | false |
|
||||
| `UPAAS_SESSION_SECRET` | Key that signs the session and CSRF cookies. When unset, a random key is generated once and kept in `$UPAAS_DATA_DIR/session.key`. | "" |
|
||||
| `UPAAS_CORS_ORIGINS` | Comma-separated origins allowed to make cross-origin requests with cookies. When unset, no CORS headers are sent. | "" |
|
||||
|
||||
The Docker client also reads the standard `DOCKER_API_VERSION`,
|
||||
`DOCKER_CERT_PATH` and `DOCKER_TLS_VERIFY` variables; `UPAAS_DOCKER_HOST`, which
|
||||
has a default, always overrides `DOCKER_HOST`.
|
||||
| `DEBUG` | Enable debug logging | false |
|
||||
| `SENTRY_DSN` | Sentry error reporting DSN | "" |
|
||||
| `METRICS_USERNAME` | Basic auth for /metrics | "" |
|
||||
| `METRICS_PASSWORD` | Basic auth for /metrics | "" |
|
||||
|
||||
## Running with Docker
|
||||
|
||||
@@ -237,11 +230,9 @@ HOST_DATA_DIR=/srv/upaas/data
|
||||
```
|
||||
|
||||
Other settings from [Configuration](#configuration) go in the same file, except
|
||||
`PORT`, `UPAAS_PORT` and `UPAAS_DATA_DIR`: the compose file sets both port
|
||||
settings to 8080 and `UPAAS_DATA_DIR` to `/var/lib/upaas`, overriding `.env`, to
|
||||
match its port mapping, healthcheck and data directory mount. Then run
|
||||
`docker compose up -d` from the repo root; `docker compose ps` shows the
|
||||
container as healthy once `/health` answers.
|
||||
`PORT`: the compose file sets it to 8080, overriding `.env`, to match its port
|
||||
mapping and healthcheck. Then run `docker compose up -d` from the repo root;
|
||||
`docker compose ps` shows the container as healthy once `/health` answers.
|
||||
|
||||
**Important**: `HOST_DATA_DIR` **must** be an **absolute path** on the host. It
|
||||
is bind-mounted into the container and passed as `UPAAS_HOST_DATA_DIR` so that
|
||||
|
||||
@@ -20,26 +20,6 @@ regress.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: An app's deployments page now lists only its 10 most recent
|
||||
deployments, newest first, instead of 50 (#238).
|
||||
|
||||
- 2026-09-29: `docker-compose.yml` now sets `UPAAS_PORT` to 8080 as well as
|
||||
`PORT`, since upaas reads `UPAAS_PORT` first and a `UPAAS_PORT` in `.env` made
|
||||
it listen away from the port mapping and healthcheck; the README's Compose
|
||||
section names both (#230).
|
||||
|
||||
- 2026-09-29: The README Configuration table now lists every setting upaas
|
||||
reads, adding `UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET` and
|
||||
`UPAAS_CORS_ORIGINS`, and gives the real default and effect of each:
|
||||
`UPAAS_PORT` wins over `PORT`, `UPAAS_HOST_DATA_DIR` falls back to
|
||||
`UPAAS_DATA_DIR`, `UPAAS_DEBUG` drops the session cookie's `Secure` flag, and
|
||||
`UPAAS_SENTRY_DSN` is not used (#229).
|
||||
|
||||
- 2026-09-28: The README Configuration table now names `UPAAS_DEBUG`,
|
||||
`UPAAS_SENTRY_DSN`, `UPAAS_METRICS_USERNAME` and `UPAAS_METRICS_PASSWORD`, the
|
||||
names upaas actually reads (the unprefixed names it listed were ignored), and
|
||||
the `UPAAS_HOST_DATA_DIR` row refers to `UPAAS_DATA_DIR` (#224).
|
||||
|
||||
- 2026-09-28: Added `docker-compose.yml` for deploying upaas: settings from
|
||||
`.env`, the port published on `127.0.0.1` only for a TLS proxy in front, and a
|
||||
healthcheck against `/health`; the README's plain-HTTP Compose example is
|
||||
|
||||
+2
-7
@@ -7,14 +7,9 @@ services:
|
||||
# Every line of .env is passed to upaas as an environment variable.
|
||||
env_file: .env
|
||||
environment:
|
||||
# Override any PORT or UPAAS_PORT in .env, so upaas listens where the
|
||||
# port mapping and healthcheck below expect it. Both are set because
|
||||
# upaas reads UPAAS_PORT first.
|
||||
# Overrides any PORT in .env, so upaas listens where the port mapping
|
||||
# and healthcheck below expect it.
|
||||
PORT: "8080"
|
||||
UPAAS_PORT: "8080"
|
||||
# Overrides any UPAAS_DATA_DIR in .env, so the database stays on the
|
||||
# HOST_DATA_DIR mount below instead of inside the container.
|
||||
UPAAS_DATA_DIR: /var/lib/upaas
|
||||
# The Docker daemon resolves app bind mounts on the host, so upaas must
|
||||
# know the host path of its data directory.
|
||||
UPAAS_HOST_DATA_DIR: ${HOST_DATA_DIR:?set HOST_DATA_DIR in .env to an absolute host path}
|
||||
|
||||
@@ -28,7 +28,7 @@ const (
|
||||
// recentDeploymentsLimit is the number of recent deployments to show.
|
||||
recentDeploymentsLimit = 5
|
||||
// deploymentsHistoryLimit is the number of deployments to show in history.
|
||||
deploymentsHistoryLimit = 10
|
||||
deploymentsHistoryLimit = 50
|
||||
)
|
||||
|
||||
// redirectToApp issues a SeeOther redirect to the page for the given
|
||||
|
||||
@@ -8,7 +8,6 @@ import (
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/go-chi/chi/v5"
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -1149,73 +1148,6 @@ func TestHandleCancelDeployReturns404ForUnknownApp(t *testing.T) {
|
||||
assert.Equal(t, http.StatusNotFound, recorder.Code)
|
||||
}
|
||||
|
||||
// TestHandleAppDeploymentsShowsTenNewest verifies the deployments page
|
||||
// lists only the 10 most recent deployments, newest first.
|
||||
func TestHandleAppDeploymentsShowsTenNewest(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
testCtx := setupTestHandlers(t)
|
||||
createdApp := createTestApp(t, testCtx, "deployments-page-app")
|
||||
|
||||
// Create 12 deployments, each started one minute after the one before.
|
||||
firstStart := time.Date(2026, 1, 1, 0, 0, 0, 0, time.UTC)
|
||||
|
||||
ids := make([]int64, 0, 12)
|
||||
|
||||
for idx := range 12 {
|
||||
deployment := models.NewDeployment(testCtx.database)
|
||||
deployment.AppID = createdApp.ID
|
||||
deployment.Status = models.DeploymentStatusSuccess
|
||||
require.NoError(t, deployment.Save(context.Background()))
|
||||
|
||||
_, err := testCtx.database.Exec(
|
||||
context.Background(),
|
||||
"UPDATE deployments SET started_at = ? WHERE id = ?",
|
||||
firstStart.Add(time.Duration(idx)*time.Minute),
|
||||
deployment.ID,
|
||||
)
|
||||
require.NoError(t, err)
|
||||
|
||||
ids = append(ids, deployment.ID)
|
||||
}
|
||||
|
||||
request := httptest.NewRequestWithContext(
|
||||
t.Context(),
|
||||
http.MethodGet,
|
||||
"/apps/"+createdApp.ID+"/deployments",
|
||||
nil,
|
||||
)
|
||||
request = addChiURLParams(request, map[string]string{"id": createdApp.ID})
|
||||
recorder := httptest.NewRecorder()
|
||||
|
||||
handler := testCtx.handlers.HandleAppDeployments()
|
||||
handler.ServeHTTP(recorder, request)
|
||||
|
||||
require.Equal(t, http.StatusOK, recorder.Code)
|
||||
|
||||
body := recorder.Body.String()
|
||||
card := func(id int64) string {
|
||||
return `data-deployment-id="` + strconv.FormatInt(id, 10) + `"`
|
||||
}
|
||||
|
||||
assert.Equal(t, 10, strings.Count(body, `data-deployment-id="`))
|
||||
|
||||
// The two oldest are left out.
|
||||
assert.NotContains(t, body, card(ids[0]))
|
||||
assert.NotContains(t, body, card(ids[1]))
|
||||
|
||||
// The ten newest are shown, newest first.
|
||||
previous := -1
|
||||
|
||||
for idx := len(ids) - 1; idx >= 2; idx-- {
|
||||
position := strings.Index(body, card(ids[idx]))
|
||||
require.Greater(t, position, previous,
|
||||
"deployment %d missing or out of order", ids[idx])
|
||||
|
||||
previous = position
|
||||
}
|
||||
}
|
||||
|
||||
func TestHandleWebhookReturns404ForUnknownSecret(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user