Repository navigation
Start the box image under tini - #97
Merged
Merged
Conversation
The box and login containers got their init from Docker's `Init: true`. Anything else that runs the image has to know to add one, or the entrypoint's `sleep` is PID 1: it ignores SIGTERM, so every stop waits out the grace period, and it reaps nothing, so every process orphaned in the box stays a zombie and counts against the pids limit. The image now installs tini and starts its entrypoint under it, and the box and login containers drop `Init: true`. Both have to change together: under docker-init, tini is not PID 1 and reaps nothing without `-s`. The root helper in `oneShot` replaces the entrypoint, so it keeps `Init: true`. The gateway already reads `tini` as a box's init. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
9 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Split out of #94, as suggested there.
What changed
box-image/Dockerfileinstallstini(Ubuntu's package,/usr/bin/tini, 0.19.0) and starts the entrypoint under it:ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/entrypoint.sh"].docker.tsdropsInit: truefor the box container and the login container. Both run the image's entrypoint, so tini is their PID 1 now.oneShotkeepsInit: true, because it replaces the entrypoint and tini with it.ARCHITECTURE.mdsays where the init comes from now.background.test.tshas a case for a box held open under tini.BOX_INITalready matchedtini, so the gateway needs no change.The two changes have to go together. With
Init: trueand tini in the entrypoint, tini is not PID 1, and without-sit reaps nothing.Why
The init is now part of the image, so anything that runs the image gets it, not only a caller that knows to ask Docker for one. Without an init, the entrypoint's
sleepis PID 1. It never sees SIGTERM, and it never reaps the processes orphaned in the box.Compatibility
A container keeps the
HostConfigit was created with. A box created before this change keepsInit: trueand the old image until it is recreated. When the image changes, the box is recreated with both the new image and noInit. A deployment that pinsBOX_IMAGEto an image from before this change, with a newer orchestrator, would run its boxes without an init.Testing
npm run checkandnpm testinorchestrator. One test,review/fs.test.ts, fails on macOS because of the/var→/private/varsymlink. It fails the same way onmain.ghcr.io/splitbrain/boxes/box:latest(apt-get install tiniand the newENTRYPOINT) and ran it without--init, with a read-only root filesystem and--cap-drop ALL:/usr/bin/tini -- /usr/local/bin/entrypoint.sh, withsleep infinityas its child.docker execis reaped. The current image without an init leaves it as a zombie.docker stoptakes 0.1 s, against 3.1 s for the current image without an init.🤖 Generated with Claude Code