write a docker-compose for upaas asap and get it on 'main' or 'prod' or whatever we're using because i'm going to deploy it in prod now
Urgent: he is deploying upaas on fsn1app1 now (issue 181). He merged the milestone, PR 207, into main at 09:20 UTC, and next was deleted with it. next has been recreated from main (97a17e56a7) as the base for this PR.
Definition of done:
A docker-compose.yml at the repo root runs upaas as the README describes: the image built from this repo's Dockerfile, the Docker socket and data mounts upaas needs to deploy apps, settings from an .env file, and restart: unless-stopped.
It follows the rehearsal's advice (comment 102392): the upaas port is published on 127.0.0.1 only, for the TLS proxy in front, and UPAAS_PLAINTEXT_HTTP is left unset.
It works: docker compose up -d from a fresh clone brings upaas up healthy, and the web UI answers on the published port. The worker checks this and then removes everything it started.
The README gets a short "Deploying with Docker Compose" section.
make check is green; the PR to next passes an independent review and is merged. The next to main PR is open, mergeable, and assigned to sneak.
As soon as the review passes, sneak gets the file's raw URL in chat, so he can deploy before the merge to main.
Model: opus-5-5
sneak's order, 09:2x UTC 2026-09-28, verbatim:
> write a docker-compose for upaas asap and get it on 'main' or 'prod' or whatever we're using because i'm going to deploy it in prod now
**Urgent:** he is deploying upaas on fsn1app1 now ([issue 181](https://git.eeqj.de/sneak/upaas/issues/181)). He merged the milestone, [PR 207](https://git.eeqj.de/sneak/upaas/pulls/207), into `main` at 09:20 UTC, and `next` was deleted with it. `next` has been recreated from `main` (`97a17e56a7`) as the base for this PR.
Definition of done:
- A `docker-compose.yml` at the repo root runs upaas as the README describes: the image built from this repo's `Dockerfile`, the Docker socket and data mounts upaas needs to deploy apps, settings from an `.env` file, and `restart: unless-stopped`.
- It follows the rehearsal's advice ([comment 102392](https://git.eeqj.de/sneak/upaas/issues/181#issuecomment-102392)): the upaas port is published on `127.0.0.1` only, for the TLS proxy in front, and `UPAAS_PLAINTEXT_HTTP` is left unset.
- It works: `docker compose up -d` from a fresh clone brings upaas up healthy, and the web UI answers on the published port. The worker checks this and then removes everything it started.
- The README gets a short "Deploying with Docker Compose" section.
- `make check` is green; the PR to `next` passes an independent review and is merged. The `next` to `main` PR is open, mergeable, and assigned to sneak.
- As soon as the review passes, sneak gets the file's raw URL in chat, so he can deploy before the merge to `main`.
Model: opus-5-5
Plan: one PR to next, done by one worker, then an independent review.
docker-compose.yml at the repo root: build: ., restart: unless-stopped, the Docker socket mounted, ${HOST_DATA_DIR} (an absolute host path) mounted at /var/lib/upaas and passed as UPAAS_HOST_DATA_DIR, settings read from .env, port published as 127.0.0.1:8080:8080, UPAAS_PLAINTEXT_HTTP not set, and a healthcheck against /health so docker compose ps shows the container as healthy.
README: the existing Docker Compose example (which serves plain HTTP on every interface) becomes a short "Deploying with Docker Compose" section that points at the file and lists the .env settings, so the two can't drift apart.
Proof: docker compose up -d from a fresh clone under a unique project name, the container becomes healthy, and the UI answers on 127.0.0.1. Then the worker removes every container, volume, network and image that run created, and nothing else.
As soon as the review passes, the raw URL of the file on the PR branch is posted here so the deploy doesn't have to wait for the merge.
Model: opus-5-5
Plan: one PR to `next`, done by one worker, then an independent review.
- `docker-compose.yml` at the repo root: `build: .`, `restart: unless-stopped`, the Docker socket mounted, `${HOST_DATA_DIR}` (an absolute host path) mounted at `/var/lib/upaas` and passed as `UPAAS_HOST_DATA_DIR`, settings read from `.env`, port published as `127.0.0.1:8080:8080`, `UPAAS_PLAINTEXT_HTTP` not set, and a healthcheck against `/health` so `docker compose ps` shows the container as healthy.
- README: the existing Docker Compose example (which serves plain HTTP on every interface) becomes a short "Deploying with Docker Compose" section that points at the file and lists the `.env` settings, so the two can't drift apart.
- Proof: `docker compose up -d` from a fresh clone under a unique project name, the container becomes healthy, and the UI answers on `127.0.0.1`. Then the worker removes every container, volume, network and image that run created, and nothing else.
- As soon as the review passes, the raw URL of the file on the PR branch is posted here so the deploy doesn't have to wait for the merge.
Model: opus-5-5
HOST_DATA_DIR must be an absolute path. upaas is published on 127.0.0.1:8080 for the TLS proxy. Settings in .env use the UPAAS_ prefix (UPAAS_SENTRY_DSN and so on).
Model: opus-5-5
The review of https://git.eeqj.de/sneak/upaas/pulls/225 has passed. The file:
https://git.eeqj.de/sneak/upaas/raw/branch/docker-compose/docker-compose.yml
It builds the image from the repo, so run it from a clone, not from the file alone:
```sh
git clone -b docker-compose https://git.eeqj.de/sneak/upaas.git && cd upaas
echo HOST_DATA_DIR=/srv/upaas/data > .env
docker compose up -d
```
`HOST_DATA_DIR` must be an absolute path. upaas is published on `127.0.0.1:8080` for the TLS proxy. Settings in `.env` use the `UPAAS_` prefix (`UPAAS_SENTRY_DSN` and so on).
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
sneak's order, 09:2x UTC 2026-09-28, verbatim:
Urgent: he is deploying upaas on fsn1app1 now (issue 181). He merged the milestone, PR 207, into
mainat 09:20 UTC, andnextwas deleted with it.nexthas been recreated frommain(97a17e56a7) as the base for this PR.Definition of done:
docker-compose.ymlat the repo root runs upaas as the README describes: the image built from this repo'sDockerfile, the Docker socket and data mounts upaas needs to deploy apps, settings from an.envfile, andrestart: unless-stopped.127.0.0.1only, for the TLS proxy in front, andUPAAS_PLAINTEXT_HTTPis left unset.docker compose up -dfrom a fresh clone brings upaas up healthy, and the web UI answers on the published port. The worker checks this and then removes everything it started.make checkis green; the PR tonextpasses an independent review and is merged. ThenexttomainPR is open, mergeable, and assigned to sneak.main.Model: opus-5-5
Plan: one PR to
next, done by one worker, then an independent review.docker-compose.ymlat the repo root:build: .,restart: unless-stopped, the Docker socket mounted,${HOST_DATA_DIR}(an absolute host path) mounted at/var/lib/upaasand passed asUPAAS_HOST_DATA_DIR, settings read from.env, port published as127.0.0.1:8080:8080,UPAAS_PLAINTEXT_HTTPnot set, and a healthcheck against/healthsodocker compose psshows the container as healthy..envsettings, so the two can't drift apart.docker compose up -dfrom a fresh clone under a unique project name, the container becomes healthy, and the UI answers on127.0.0.1. Then the worker removes every container, volume, network and image that run created, and nothing else.Model: opus-5-5
The review of #225 has passed. The file:
https://git.eeqj.de/sneak/upaas/raw/branch/docker-compose/docker-compose.yml
It builds the image from the repo, so run it from a clone, not from the file alone:
HOST_DATA_DIRmust be an absolute path. upaas is published on127.0.0.1:8080for the TLS proxy. Settings in.envuse theUPAAS_prefix (UPAAS_SENTRY_DSNand so on).Model: opus-5-5