Adds a "Running under upaas" section to the README, after "Running with Docker", for #323. It lists what the upaas app needs: no port mapping, with the app on the reverse proxy's Docker network, where the proxy reaches it at upaas- plus the app name on port 8080; one volume at /var/lib/webhooker and the commands that create it; WEBHOOKER_ENVIRONMENT=prod and TRUSTED_PROXIES; the health check; and the first-run steps (docker logs for the banner, a resetpw command for a lost password).
Every statement about upaas comes from its README or code on main: an app volume is a bind mount of a host path upaas never creates (internal/docker/client.go, buildMounts); every mapped port is published on all host interfaces (buildPortConfig; sneak/upaas#113, closed WONTFIX); the app's Docker network setting is the container's network, and the container is named upaas- plus the app name (internal/service/deploy/deploy.go); a deploy fails unless the container is healthy 60 seconds after it starts (checkHealthAfterDelay). upaas's pages offer no stop button, so the reset steps stop and start the container with docker on the host.
#322 was not on next at rebase, so the section gives prod as the value to set, not as the default.
Judgement call: a host directory made by root stops the container at its data directory lock. This PR removes that obstacle in the README (create the directory owned by UID 1000 before the first deploy) rather than by changing the image.
Model: opus-5-5
Adds a "Running under upaas" section to the README, after "Running with Docker", for https://git.eeqj.de/sneak/webhooker/issues/323. It lists what the upaas app needs: no port mapping, with the app on the reverse proxy's Docker network, where the proxy reaches it at `upaas-` plus the app name on port `8080`; one volume at `/var/lib/webhooker` and the commands that create it; `WEBHOOKER_ENVIRONMENT=prod` and `TRUSTED_PROXIES`; the health check; and the first-run steps (`docker logs` for the banner, a `resetpw` command for a lost password).
Every statement about upaas comes from its README or code on `main`: an app volume is a bind mount of a host path upaas never creates (`internal/docker/client.go`, `buildMounts`); every mapped port is published on all host interfaces (`buildPortConfig`; https://git.eeqj.de/sneak/upaas/issues/113, closed WONTFIX); the app's Docker network setting is the container's network, and the container is named `upaas-` plus the app name (`internal/service/deploy/deploy.go`); a deploy fails unless the container is `healthy` 60 seconds after it starts (`checkHealthAfterDelay`). upaas's pages offer no stop button, so the reset steps stop and start the container with `docker` on the host.
https://git.eeqj.de/sneak/webhooker/pulls/322 was not on `next` at rebase, so the section gives `prod` as the value to set, not as the default.
Judgement call: a host directory made by root stops the container at its data directory lock. This PR removes that obstacle in the README (create the directory owned by UID 1000 before the first deploy) rather than by changing the image.
Model: opus-5-5
Adds a short "Running under upaas" section to the README, next to
"Running with Docker": the container port, the data volume and the
commands that create it, the environment variables upaas should set,
the health check upaas reads after a deploy, and where the first-run
admin password appears and how to reset it.
upaas bind-mounts a host directory it does not create, and a
directory made by root stops the container at its data directory
lock. The section has the operator create the directory owned by
UID 1000 before the first deploy; the image is unchanged.
Model: opus-5-5
README.md line 739, "Running under upaas", the Port bullet. In upaas, the only place to enter a container port is a port mapping, and upaas publishes every mapped port on all host interfaces (0.0.0.0; sneak/upaas#113, closed WONTFIX). An operator who follows "container port 8080" therefore exposes webhooker's plain-HTTP admin UI and receiver on every interface of the host. "Running with Docker" says never to do that. Acceptable: the section says to add no port mapping and to set the app's Docker Network in upaas to the reverse proxy's Docker network. It also says the proxy then reaches the app at upaas-<app name>:8080, and to leave PORT unset.
README.md lines 755-758, the TRUSTED_PROXIES bullet. It says the remoteIP field of each http request log line shows the proxy's address. But every 30 seconds the image's health check writes an http request line whose remoteIP is ::1. An operator who reads the latest line would set TRUSTED_PROXIES=::1. Acceptable: TRUSTED_PROXIES is the reverse proxy's address on that Docker network. If the section keeps the log as the way to find that address, it says to read a line for a request that came through the proxy, not a health-check line.
Model: opus-5-5
1. `README.md` line 739, "Running under upaas", the **Port** bullet. In upaas, the only place to enter a container port is a port mapping, and upaas publishes every mapped port on all host interfaces (`0.0.0.0`; https://git.eeqj.de/sneak/upaas/issues/113, closed WONTFIX). An operator who follows "container port `8080`" therefore exposes webhooker's plain-HTTP admin UI and receiver on every interface of the host. "Running with Docker" says never to do that. Acceptable: the section says to add no port mapping and to set the app's Docker Network in upaas to the reverse proxy's Docker network. It also says the proxy then reaches the app at `upaas-<app name>:8080`, and to leave `PORT` unset.
2. `README.md` lines 755-758, the `TRUSTED_PROXIES` bullet. It says the `remoteIP` field of each `http request` log line shows the proxy's address. But every 30 seconds the image's health check writes an `http request` line whose `remoteIP` is `::1`. An operator who reads the latest line would set `TRUSTED_PROXIES=::1`. Acceptable: `TRUSTED_PROXIES` is the reverse proxy's address on that Docker network. If the section keeps the log as the way to find that address, it says to read a line for a request that came through the proxy, not a health-check line.
Model: opus-5-5
upaas publishes every mapped port on all host interfaces, which would
expose the plain-HTTP admin UI and receiver. The section now says to
add no port mapping, to put the app on the reverse proxy's Docker
network, and that the proxy reaches it at the upaas container name on
port 8080.
TRUSTED_PROXIES is the proxy's address on that network; the log hint
now points at a proxied request's line, since health-check lines show
::1.
Model: opus-5-5
Port: the section now says to add no port mapping (sneak/upaas#113), to set the app's Docker Network in upaas to the reverse proxy's Docker network, that the proxy reaches the app at upaas- plus the app name on port 8080, and to leave PORT unset.
TRUSTED_PROXIES: now the reverse proxy's address on that Docker network; the log hint points at the line for a request that came through the proxy and notes that health-check lines show ::1.
#322 is still not on next, so the WEBHOOKER_ENVIRONMENT line is unchanged.
Model: opus-5-5
Rework pushed.
1. Port: the section now says to add no port mapping (https://git.eeqj.de/sneak/upaas/issues/113), to set the app's Docker Network in upaas to the reverse proxy's Docker network, that the proxy reaches the app at `upaas-` plus the app name on port `8080`, and to leave `PORT` unset.
2. `TRUSTED_PROXIES`: now the reverse proxy's address on that Docker network; the log hint points at the line for a request that came through the proxy and notes that health-check lines show `::1`.
https://git.eeqj.de/sneak/webhooker/pulls/322 is still not on `next`, so the `WEBHOOKER_ENVIRONMENT` line is unchanged.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Adds a "Running under upaas" section to the README, after "Running with Docker", for #323. It lists what the upaas app needs: no port mapping, with the app on the reverse proxy's Docker network, where the proxy reaches it at
upaas-plus the app name on port8080; one volume at/var/lib/webhookerand the commands that create it;WEBHOOKER_ENVIRONMENT=prodandTRUSTED_PROXIES; the health check; and the first-run steps (docker logsfor the banner, aresetpwcommand for a lost password).Every statement about upaas comes from its README or code on
main: an app volume is a bind mount of a host path upaas never creates (internal/docker/client.go,buildMounts); every mapped port is published on all host interfaces (buildPortConfig; sneak/upaas#113, closed WONTFIX); the app's Docker network setting is the container's network, and the container is namedupaas-plus the app name (internal/service/deploy/deploy.go); a deploy fails unless the container ishealthy60 seconds after it starts (checkHealthAfterDelay). upaas's pages offer no stop button, so the reset steps stop and start the container withdockeron the host.#322 was not on
nextat rebase, so the section givesprodas the value to set, not as the default.Judgement call: a host directory made by root stops the container at its data directory lock. This PR removes that obstacle in the README (create the directory owned by UID 1000 before the first deploy) rather than by changing the image.
Model: opus-5-5
README.mdline 739, "Running under upaas", the Port bullet. In upaas, the only place to enter a container port is a port mapping, and upaas publishes every mapped port on all host interfaces (0.0.0.0; sneak/upaas#113, closed WONTFIX). An operator who follows "container port8080" therefore exposes webhooker's plain-HTTP admin UI and receiver on every interface of the host. "Running with Docker" says never to do that. Acceptable: the section says to add no port mapping and to set the app's Docker Network in upaas to the reverse proxy's Docker network. It also says the proxy then reaches the app atupaas-<app name>:8080, and to leavePORTunset.README.mdlines 755-758, theTRUSTED_PROXIESbullet. It says theremoteIPfield of eachhttp requestlog line shows the proxy's address. But every 30 seconds the image's health check writes anhttp requestline whoseremoteIPis::1. An operator who reads the latest line would setTRUSTED_PROXIES=::1. Acceptable:TRUSTED_PROXIESis the reverse proxy's address on that Docker network. If the section keeps the log as the way to find that address, it says to read a line for a request that came through the proxy, not a health-check line.Model: opus-5-5
Rework pushed.
upaas-plus the app name on port8080, and to leavePORTunset.TRUSTED_PROXIES: now the reverse proxy's address on that Docker network; the log hint points at the line for a request that came through the proxy and notes that health-check lines show::1.#322 is still not on
next, so theWEBHOOKER_ENVIRONMENTline is unchanged.Model: opus-5-5
Review passed.
Model: opus-5-5