Repository navigation
Mattermost, Open WebUI, RustDesk, Vikunja, NetBox, SearXNG and 6 more: small fixes - #375
Open
jackspiering wants to merge 4 commits into
Open
jackspiering wants to merge 4 commits into
jackspiering wants to merge 4 commits into
Conversation
…older SearXNG makes its own user the owner of ./searxng at each start. An existing user's git pull then fails with 'unable to unlink old services/searxng/searxng/settings.yml: Permission denied' and leaves the clone half updated. The Upgrading section now gives the chown step to run before the update, the steps to recover after a failed pull, and the restart that loads the new file.
…t the upgrade notes SearXNG: FORCE_OWNERSHIP=false stops the image from making its own user the owner of ./searxng, so later changes to settings.yml no longer break git pull and need no sudo. The chown before the update is now a one-time step. The Upgrading note also says that the request method is GET now and how to keep POST. Vikunja: logins already ended at every restart before the secret was set, so the note now says they end one last time.
SearXNG: the step that recreates the application container stood before the recovery steps, so a reader who recovered from a failed pull never reached it. Without it the old container takes the folder again at its next start. Sure: the README states the effect of TS_ACCEPT_DNS, not a reason that was never recorded.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Small stack fixes from an external review (section 3.3).
SERVICEPORT=8065, and the commented LANportsblock maps to 8065 (Calls lines kept). RemovesHTTP_PORT/HTTPS_PORTand the inaccurate comments.host.docker.internaldid not resolve on Linux. Addsextra_hosts: host.docker.internal:host-gatewayto thetailscaleservice, and the README explains that a native Ollama must listen beyond loopback.VIKUNJA_SERVICE_SECRET, so it is no longer regenerated at every start. "Upgrading" note added: existing logins end one last time.REDIS_HOSTnow points to the persistentrediscontainer, not the cache. "Upgrading" note added.settings.ymlwas a 2761-line copy of upstream's file that referenced engines upstream has removed. It is nowuse_default_settings: trueplussecret_key. "Upgrading" note added. The note also says how to update a clone when the container owns the settings folder. Without that step,git pullstops withunable to unlink old 'services/searxng/searxng/settings.yml': Permission deniedand leaves the clone half updated. The stack now setsFORCE_OWNERSHIP=false, so the folder stays with the host user and that step is needed only once.DISABLE_AUTHdefaults tofalseinstead of being required.TS_ACCEPT_DNSis explained for Sure and commented out for MeTube.Related Issues
Verification
docker compose config --quietpasses in all 12 changed directories with dummy values for required variables, and Vikunja without its secret fails with the expected error.rumdl check --config .markdownlint.yml .(0.2.78) andgit diff --check origin/mainare clean. The six NetBox config files parse with Python'sast.searx/settings.ymlat the commit nearest the stack's copy. The only real difference wassecret_key.main, then updated with each path in the "Upgrading" note (chownbefore the pull, recovery after a failed pull, and an editedsettings.yml). Tailscale Serve answers 200 before and after. The log has 19Cannot load enginelines with the old file and none with the new one.FORCE_OWNERSHIP=false: the folder stays with the host user, an edit ofsettings.ymlwithoutsudotakes effect afterdocker compose restart application, and Tailscale Serve answers 200. A folder that an earlier version gave to user977keeps working. On a stub stack started frommain, the "Upgrading" note was followed step by step:docker compose up -drecreatesapplication, and a later change tosettings.ymlpulls withoutchown. With folder mode700the stack fails with and without the setting.rqkeys are inredisand none are inredis-cache. A queued job completes.main, a login token returns 401 after the application restarts. With the secret, it stays valid after a restart and after the container is recreated.tailscalecontainer started,host.docker.internal:11434reaches a stand-in listener on the Docker host.Checklist
Additional Context
GET, which is SearXNG's default. The stack's oldmethod: "POST"was upstream's default when the file was copied. The search form of the running stack usesGET. The "Upgrading" note says so, and how to keepPOST(tested).TS_ACCEPT_DNS=true(an OIDC provider on the Tailnet) is the review's suggestion, not confirmed.