Files
noitu/docs/deployment.md
T
tiennm99 39ef45730f feat(dict): derive the corpus from undertheseanlp's wiktionary rows
Replace the 179 MB minhqnd SQLite aggregate with the 4.8 MB
undertheseanlp/dictionary JSONL, pinned by commit and SHA-256, reading
only rows tagged "wiktionary". The two other wordlists in that file are
never read: hongocduc is GPL and would force a relicense, tudientv is an
unlicensed derivative of a commercial dictionary.

build-dictionary gains --merged and --sources (names validated, default
wiktionary), a shared finish() tail, and meta rows for the source commit
and the sources kept and excluded. The SQLite --in path, its schema
auto-detection and their tests are removed. Fixture builds now record
that they carry no upstream data instead of inheriting a licence string.
The --min-words floor moves from 40,000 to 20,000; the corpus is 26,845
words, down from 48,216, all of the loss being words absent from the
2018 Wiktionary scrape. Capitalization is not a filter.

The data licence follows the source text: CC BY-SA 3.0 Unported, which
is what vi.wiktionary.org carried in 2018. LICENSE, NOTICE, ATTRIBUTION,
the README, the image docs, the builder's meta string and the in-game
footer all name Wiktionary tiếng Việt's contributors as the authors and
undertheseanlp as the intermediary. The Makefile/Dockerfile pin test now
also checks the commit the builder stamps into the database.
2026-09-08 16:37:34 +07:00

5.6 KiB

Deployment

The whole game is one binary. It serves the WebSocket API, the built frontend, and a health check, and it reads a single database file at startup. The supported shape is the container image behind a reverse proxy that terminates TLS.

Configuration

Every setting is an environment variable and every one has a working default, so the image runs with nothing set.

Variable Default Meaning
NOITU_ADDR :8080 Listen address
NOITU_DB_PATH data/noitu.db Derived dictionary, opened read-only at startup
NOITU_TURN_LIMIT 20s Turn deadline, identical for bot and online games
NOITU_GRACE 30s How long a disconnected player's seat is held for a reconnect
NOITU_ALLOWED_ORIGINS (unset) Comma-separated origin allowlist. Unset means same-origin only
NOITU_WEB_DIR (unset) Built frontend to serve. Unset serves the API alone

An invalid duration is logged and ignored rather than silently changing the rules of the game.

One timing is not configurable: an online room closes after 10 minutes in its lobby with no game started. It is a fixed constant because nothing about a deployment should change how long two people have to agree on a game, and a running game is bounded by the turn clock rather than by this. Chatting deliberately does not reset that window — talking is not playing, or a room could be held open for the life of the process by one message every nine minutes.

Chat's own bounds are fixed constants for the same reason: a room keeps its last 20 messages and one message is capped at 200 runes (server/internal/wsapi/room.go).

The image sets NOITU_ADDR, NOITU_DB_PATH and NOITU_WEB_DIR for you.

Origins

Leave NOITU_ALLOWED_ORIGINS unset when the binary serves the frontend, which is the normal case: the page and the socket share an origin and the browser's own check is enough. Set it only when the frontend is served from somewhere else, and then list exactly those origins. An allowlist that is wrong in the permissive direction lets any page open a socket as one of your players.

The image

docker build -t noitu:latest .
docker run -p 8080:8080 noitu:latest

The build downloads the 4.8 MB upstream wordlist in a builder stage and derives the ~1.7 MB database the game uses. Only the derived file is copied into the final image, so the upstream wordlist never ships. The result is a distroless image of about 25 MB running as a non-root user.

Passing --build-arg FIXTURE_DICT=1 builds the same image against the checked-in word sample instead. It produces a playable but tiny dictionary and exists so the image can be tested without the download; do not ship it.

What travels with the data

The derived wordlist is CC BY-SA 3.0 while the code is Apache-2.0, so the image carries data/LICENSE, data/ATTRIBUTION.md and NOTICE alongside it. CI asserts all three are present, and that the upstream file is not. Removing them would put the image out of compliance.

Behind a reverse proxy

The socket is a normal HTTP upgrade, but three settings are easy to get wrong and each one breaks the game in a way that looks like something else.

Forward the upgrade. Without Upgrade and Connection the handshake returns 400 or 502 and the page sits on "Đang kết nối…" forever.

Set a read timeout longer than the keepalive. The server pings every 20 seconds. A proxy that closes idle connections sooner will cut players off mid game, and it will look like a client bug because the server logs a clean close.

Turn response buffering off. A proxy that buffers will hold frames until it has enough to flush, which turns a 20-second turn into a guess.

nginx:

location /ws {
    proxy_pass http://127.0.0.1:8080;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    proxy_set_header Host $host;
    proxy_read_timeout 120s;
    proxy_send_timeout 120s;
    proxy_buffering off;
}

location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_set_header Host $host;
}

Caddy needs none of this: it forwards upgrades and streams by default.

noitu.example {
    reverse_proxy 127.0.0.1:8080
}

The client's own address

Rate limiting counts against RemoteAddr and deliberately ignores X-Forwarded-For, because that header is attacker-controlled unless the proxy overwrites it. Behind a proxy every player therefore shares one bucket. If that becomes a problem, the fix is to make the proxy the only source of the header and teach the server to trust it — not to trust it as things stand.

Health check

GET /healthz returns 200 once the dictionary has loaded. It does not report on live games, so it is a liveness check rather than a readiness one.

curl -fsS https://noitu.example/healthz

A post-deploy check worth having is a real socket open, because the health check passes whether or not the proxy forwards upgrades. Opening the site and starting a game against the bot is the shortest version of that.

What a restart costs

Rooms are in memory. A restart ends every live game, and players are told the server is restarting rather than being left waiting. Deploy when the game is quiet, or accept that the games in flight are lost — there is no session persistence, by design, in this version.

Updating the dictionary

The wordlist is a build artifact, not runtime state. A new upstream release means a new image:

  1. Update DICT_URL and DICT_SHA256 in the Dockerfile, and the matching values in the Makefile.
  2. Record what changed in data/ATTRIBUTION.md.
  3. Rebuild and redeploy.

Nothing migrates, because nothing persists.