Harden container runtime and graceful shutdown - #86
Merged
Conversation
mxssl
marked this pull request as ready for review
August 1, 2026 23:08
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
static-debian13:nonrootdistroless imagenonrootusergo.modandgo.sumbefore application sources so dependency downloads remain in a stable Docker layer-trimpathand-ldflags="-s -w".dockerignorethat keeps repository metadata, local configuration, generated binaries, and development-only files out of the build contextSIGINTandSIGTERMthrough the same bounded graceful-shutdown pathWhy
The previous runtime image included an Alpine userspace and package manager even though
ntwrkis compiled withCGO_ENABLED=0and does not require dynamic libraries. It also ran the application as root and installed build packages that were not needed by the current module dependencies.Docker normally stops containers with
SIGTERM. The previous signal handler only calledhttp.Server.ShutdownforSIGINT; itsSIGTERMbranch returned immediately, which could terminate active requests without allowing the HTTP server to drain.Implementation details
The build still uses the official Go Alpine image, but the final stage now contains only the statically linked binary and the files supplied by distroless. Readable image tags remain next to their SHA-256 digests so dependency automation can identify updates while builds resolve reproducibly.
Shutdown now:
SIGINTandSIGTERMas graceful shutdown requests;http.ErrServerClosedresult and logs a clean stop.Operational impact
debug-nonrootimage or external container diagnostics.nonroot:nonroot./ntwrk.Validation
go test ./...go vet ./...git diff --checkdocker build --check .with no warningsdocker stop/SIGTERMtest confirming:app stoppednonroot:nonroot/ntwrk