docs: stop advertising the read-only image variants - #468
Conversation
The read-only build targets are commented out in docker-bake.hcl, so nginx-read-only and nginx-alpine-read-only have never been pushed, and neither registry serves them. The tag format sections had the same problem: no published tag carries a writable or read-only marker, because the writable variant adds no suffix. Refs #172
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited) Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review. 📝 WalkthroughWalkthroughREADME.md updates image tag and nginx base-image documentation. It also adds or revises Apache and CRS environment-variable details. ChangesREADME documentation
Priority: ⚪ Not assessed Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Suggested labels: Merge Risk: ⚪ Minimal · up to The README’s image and environment-variable details match the repository configuration; no actionable merge-blocking issue remains. 🚥 Pre-merge checks | ✅ 17 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (17 passed)
Full details: Ai Contribution DisclosureExplanation The PR body has no Resolution Add the required lowercase
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Refs #172.
The README promises images that are not published.
docker-bake.hclhas the read-only matrix entry commented out:so no read-only target is ever built or pushed. Confirmed against both registries:
The section now says so and points at #172, while noting that the machinery is still in the tree — the
READ_ONLY_FSbuild argument innginx/Dockerfileandnginx/docker-entrypoint.d/0-move-writables.sh— so re-enabling it later is a bake change rather than a rewrite.The tag format sections had the same problem from the other direction: they document a
[-<writable>]component, but the writable variant adds no suffix and the read-only one is not built, so no published tag has ever carried it.owasp/modsecurity-crs:nginx-writabledoes not resolve either. Removed from both the stable and rolling tag descriptions.This documents the current state; whether the variants come back is the decision still open in #172.
Summary by CodeRabbit
HSTS_MAX_AGE,X_FRAME_OPTIONS, andSKIP_RESPONSE_ANALYSIS.SERVER_TOKENSandSSL_HONOR_CIPHER_ORDER.