test: expand server protocol scenario coverage

This commit is contained in:
2026-09-11 05:55:42 +00:00
parent c709b27e5e
commit 51fa88d05b
9 changed files with 74 additions and 65 deletions
+6 -7
View File
@@ -4,12 +4,10 @@ This directory is intentionally separate from the development/toolchain Compose
files. It starts only the Linux server and nginx TLS terminator; Windows clients
connect through nginx at `/v1/agent`.
Before the first start, create `server.toml` from the authoritative example and
prepare writable state directories for the runtime image UID/GID `65532`:
Before the first start, create `server.toml` from the authoritative example:
```sh
cp ../../docs/examples/server.toml server.toml
install -d -m 0700 -o 65532 -g 65532 state run
chmod 0640 server.toml
```
@@ -22,7 +20,8 @@ docker compose -f compose.yaml config
docker compose -f compose.yaml up -d
```
Only `state/` and `run/` are persistent/owned deployment data. Back up the
whole `state/` directory while the server is stopped; `run/` contains only the
ephemeral local control socket. Do not publish, proxy, or enable JSON-RPC except
for intentional loopback debugging.
The stack's `init` container creates the two named volumes with the runtime
ownership required by the non-root server. `server-data` is the sole persistent
data volume and must be backed up as a whole while the server is stopped;
`server-run` contains only the ephemeral local control socket. Do not publish,
proxy, or enable JSON-RPC except for intentional loopback debugging.
+30 -4
View File
@@ -6,6 +6,25 @@
name: rvbox-server
services:
init:
image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}"
user: "0:0"
entrypoint: ["/bin/sh", "-ec"]
command: >-
mkdir -p /var/lib/rvbox-server /run/rvbox &&
chown 65532:65532 /var/lib/rvbox-server /run/rvbox &&
chmod 0700 /var/lib/rvbox-server /run/rvbox
read_only: true
tmpfs:
- /tmp:mode=1777,size=8m
volumes:
- server-data:/var/lib/rvbox-server
- server-run:/run/rvbox
security_opt:
- no-new-privileges:true
cap_drop: ["ALL"]
cap_add: ["CHOWN", "FOWNER"]
server:
image: "${RVBOX_SERVER_IMAGE:?set RVBOX_SERVER_IMAGE to a pinned rvbox-server image}"
restart: unless-stopped
@@ -18,11 +37,11 @@ services:
source: ./server.toml
target: /etc/rvbox/server.toml
read_only: true
- type: bind
source: ./state
- type: volume
source: server-data
target: /var/lib/rvbox-server
- type: bind
source: ./run
- type: volume
source: server-run
target: /run/rvbox
expose:
- "6899"
@@ -36,6 +55,9 @@ services:
security_opt:
- no-new-privileges:true
cap_drop: ["ALL"]
depends_on:
init:
condition: service_completed_successfully
nginx:
image: nginx:1.27.5-alpine
@@ -66,3 +88,7 @@ services:
- no-new-privileges:true
cap_drop: ["ALL"]
cap_add: ["NET_BIND_SERVICE"]
volumes:
server-data:
server-run:
-34
View File
@@ -1,34 +0,0 @@
[Unit]
Description=RVBox server
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=rvbox
Group=rvbox
ExecStartPre=/usr/local/bin/rvbox-server --check-config --config /etc/rvbox/server.toml
ExecStart=/usr/local/bin/rvbox-server --config /etc/rvbox/server.toml
Restart=on-failure
RestartSec=5s
TimeoutStopSec=35s
WorkingDirectory=/var/lib/rvbox-server
StateDirectory=rvbox-server
RuntimeDirectory=rvbox
RuntimeDirectoryMode=0750
UMask=0077
LimitNOFILE=65536
NoNewPrivileges=yes
PrivateTmp=yes
ProtectSystem=strict
ProtectHome=yes
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectControlGroups=yes
RestrictSUIDSGID=yes
LockPersonality=yes
MemoryDenyWriteExecute=yes
ReadWritePaths=/var/lib/rvbox-server /run/rvbox
[Install]
WantedBy=multi-user.target