mirror of
https://github.com/ajisaacs/OpenNest.git
synced 2026-10-06 01:52:10 -04:00
- Run as the .NET image's non-root app user (UID 1654) with root-owned application files and an app-owned /app/data that fresh named volumes inherit. - Add a curl HEALTHCHECK on /healthz (30s/5s/10s/3, 2s start interval), keep the explicit 8090 URL and clear the base image's 8080 port default. - Parameterize VERSION/SOURCE_REVISION and base images; add OCI labels with development defaults. - Add an image-only Compose example (required image and bind address, named volume, cap_drop ALL, no-new-privileges) and an env template. - Document deployment, the upload limit, scoped ownership preparation, and checked backup/restore/upgrade functions that refuse existing destinations and verify the metadata list and every archive hash before switching volumes. - Extend the container smoke: image user/healthcheck/label contract, PID 1 UID, capabilities and writable paths, Docker-reported health, near-limit and oversized uploads, stopped-service backup restored into a second volume, and startup failure on read-only and root-owned data mounts.
18 lines
231 B
Plaintext
18 lines
231 B
Plaintext
**
|
|
!OpenNest.Server/
|
|
!OpenNest.Server/**
|
|
!OpenNest.Data/
|
|
!OpenNest.Data/**
|
|
!OpenNest.Core/
|
|
!OpenNest.Core/**
|
|
**/bin/**
|
|
**/obj/**
|
|
**/data/**
|
|
**/*.db
|
|
**/*.db-*
|
|
**/.env*
|
|
**/*.env
|
|
**/*.env.*
|
|
**/*.user
|
|
**/Properties/launchSettings.json
|