Stage B of review fixes: daemon state lock, image build check, RIPEstat retries

Job state is changed under one RLock, the Dockerfile copies all root
modules and imports them at build time, RIPEstat requests go through a
retrying session with the sourceapp parameter (ripestat_sourceapp) and a
capped Retry-After. Adds the summary and marks review findings 5-10 fixed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
ayurishchevandClaude Sonnet 5 committed 2026-09-21 10:12:48 +03:00
1 parent d6b69d0842
commit aaf41adc79
8 files changed
+164 -28

No files matched your search

+4 -1
View File
@@ -9,7 +9,10 @@ WORKDIR /app
COPY requirements.txt constraints.txt ./
RUN pip install --no-cache-dir -c constraints.txt -r requirements.txt
COPY api_server.py cidr_collector.py collector_daemon.py db.py formatters.py storage.py healthcheck.py ./
# Все модули приложения из корня (тесты и прочее лежат в подкаталогах или исключены .dockerignore)
COPY *.py ./
# Забытый или сломанный модуль ломает сборку, а не запуск
RUN python -c "import api_server, collector_daemon, db, healthcheck"
# Без root; том /data создаётся с владельцем ripe (именованный том наследует его при первом создании)
RUN useradd --system --uid 10001 --no-create-home ripe \