test: add production compose smoke harness

This commit is contained in:
2026-09-11 06:28:11 +00:00
parent 110a329652
commit 248c41c7e1
9 changed files with 259 additions and 12 deletions
+12 -7
View File
@@ -10,10 +10,10 @@ services:
image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}"
user: "0:0"
entrypoint: ["/bin/sh", "-ec"]
command: >-
mkdir -p /var/lib/rvbox-server /run/rvbox &&
chown 65532:65532 /var/lib/rvbox-server /run/rvbox &&
chmod 0700 /var/lib/rvbox-server /run/rvbox
# Compose does not turn a scalar `command` into one shell script argument.
# Preserve this whole program as $0 for /bin/sh -c rather than passing
# `mkdir` followed by its words as separate shell positional arguments.
command: ["mkdir -p /var/lib/rvbox-server /run/rvbox && chown 65532:65532 /var/lib/rvbox-server /run/rvbox && chmod 0700 /var/lib/rvbox-server /run/rvbox"]
read_only: true
tmpfs:
- /tmp:mode=1777,size=8m
@@ -34,7 +34,7 @@ services:
- /tmp:mode=1777,size=32m
volumes:
- type: bind
source: ./server.toml
source: ${RVBOX_SERVER_CONFIG:-./server.toml}
target: /etc/rvbox/server.toml
read_only: true
- type: volume
@@ -67,7 +67,7 @@ services:
server:
condition: service_healthy
ports:
- "${RVBOX_HTTPS_PORT:-443}:443"
- "${RVBOX_HTTPS_BIND:-0.0.0.0}:${RVBOX_HTTPS_PORT:-443}:443"
tmpfs:
- /var/cache/nginx:uid=101,gid=101,mode=0755,size=16m
- /var/run:uid=101,gid=101,mode=0755,size=4m
@@ -87,7 +87,12 @@ services:
security_opt:
- no-new-privileges:true
cap_drop: ["ALL"]
cap_add: ["NET_BIND_SERVICE"]
# The nginx master creates worker-owned temporary directories beneath its
# explicitly mounted tmpfs paths, then drops workers to UID/GID 101. These
# are the exact bootstrap capabilities required for that lifecycle,
# including Docker user-namespace-remapping hosts; it retains no network,
# process, mount, or broad administration capability.
cap_add: ["NET_BIND_SERVICE", "DAC_OVERRIDE", "CHOWN", "SETUID", "SETGID"]
volumes:
server-data: