From 403a8f537a02808c7ed759f70718bc1f591b4814 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 30 Sep 2026 14:30:27 +0200 Subject: [PATCH] komga: within-major step, both venues proven (R-462, Part F) {'komga': 'gotson/komga:1.27.1'} -> {'komga': 'gotson/komga:1.28.0'} The ONLY image move in this commit. Written by upgrade-test.py --write-ladder (catalog gates rc=0): - bench LXC 9401 (harness v4): the seed read back before and after; 10-minute memory watch: komga anon 64.5 % (cgroup 67.5 %); 0 kills, 0 restarts; the abort starts and serves the data; - box 9202 (controller 0.283.1, the product's guarded Update, drill catalog): done in 44.2 s, the seed read back through the app's own front door. Evidence: felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/ and .../box/komga/ Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- templates/komga/.felhom.yml | 3 +- templates/komga/docker-compose.yml | 2 +- .../komga/steps/f7c491acf8f39ff8.felhom.yml | 127 ++++++++++++++++++ templates/komga/steps/f7c491acf8f39ff8.yml | 63 +++++++++ 4 files changed, 193 insertions(+), 2 deletions(-) create mode 100644 templates/komga/steps/f7c491acf8f39ff8.felhom.yml create mode 100644 templates/komga/steps/f7c491acf8f39ff8.yml diff --git a/templates/komga/.felhom.yml b/templates/komga/.felhom.yml index 4c9d91f..134f6c9 100644 --- a/templates/komga/.felhom.yml +++ b/templates/komga/.felhom.yml @@ -10,7 +10,7 @@ subdomain: "comics" slug: "komga" # catalog_since: the date THIS repo last changed this app's pinned images. Any commit that # changes an image: line must set this to the same day (see CLAUDE.md). -catalog_since: "2026-09-23" +catalog_since: "2026-09-30" # --- Resource hints (displayed on deploy screen) --- resources: @@ -131,3 +131,4 @@ i18n: # gated by scripts/check-test-record.py. An image: move without a proven entry here is refused. update_ladder: - {"from": {"komga": "gotson/komga:1.25.0"}, "to": {"komga": "gotson/komga:1.27.1"}, "digest": {"komga": "sha256:9cf102f5fb78e2e020700c53eca757e4f4d4e347121b0a16380822760337cca9"}, "verdict": "proven", "tested_at": "2026-09-23T19:46:46Z", "harness_version": 3, "evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/komga/bench/evidence/MV-komga/verdict.json", "box_evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/komga/verdict.json", "memory_peak_pct": 60.0, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 76.8} + - {"from": {"komga": "gotson/komga:1.27.1"}, "to": {"komga": "gotson/komga:1.28.0"}, "digest": {"komga": "sha256:19764751d501495b021530c9426f25d8f9f8748dc38ab3ba48eb62d7df2cd92e"}, "verdict": "proven", "tested_at": "2026-09-30T12:30:04Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/apps/komga/bench/evidence/MV-komga/verdict.json", "box_evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/box/komga/box-verdict-komga.json", "memory_peak_pct": 64.5, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 67.5} diff --git a/templates/komga/docker-compose.yml b/templates/komga/docker-compose.yml index ce86bb6..6798694 100644 --- a/templates/komga/docker-compose.yml +++ b/templates/komga/docker-compose.yml @@ -16,7 +16,7 @@ services: komga: - image: gotson/komga:1.27.1 + image: gotson/komga:1.28.0 container_name: komga restart: unless-stopped # Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege diff --git a/templates/komga/steps/f7c491acf8f39ff8.felhom.yml b/templates/komga/steps/f7c491acf8f39ff8.felhom.yml new file mode 100644 index 0000000..5ecc9cc --- /dev/null +++ b/templates/komga/steps/f7c491acf8f39ff8.felhom.yml @@ -0,0 +1,127 @@ +# ============================================================================= +# .felhom.yml - App metadata for felhom-controller +# ============================================================================= + +# --- Display info (shown on dashboard) --- +display_name: "Komga" +description: "Képregény és manga szerver OPDS támogatással" +category: "media" +subdomain: "comics" +slug: "komga" +# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that +# changes an image: line must set this to the same day (see CLAUDE.md). +catalog_since: "2026-09-23" + +# --- Resource hints (displayed on deploy screen) --- +resources: + mem_request: "200M" + mem_limit: "768M" + pi_compatible: true + needs_hdd: true + +# --- Backup classification (referential coupling; see felhom.eu documentation/audits/SPIKE-backup-classification-2026-07-14.md) --- +backup: + userdata: + - path: media/comics + class: optional # ruled: precious-decoupled (re-scanned, hand-curated) + +# --- Deploy fields (first deployment only) --- +deploy_fields: + - env_var: DOMAIN + label: "Domain" + type: domain + description: "A szerver domain neve" + locked_after_deploy: true + + - env_var: SUBDOMAIN + label: "Aldomain" + type: subdomain + default: "comics" + required: true + locked_after_deploy: true + description: "Az alkalmazás aldomainje" + + - env_var: HDD_PATH + label: "Képregénytár útvonal" + type: path + required: true + placeholder: "/mnt/felhom-drives/hdd_1" + description: "A külső merevlemez elérési útja" + locked_after_deploy: true + +# --- The setup gate (controller >= 0.281.0, `09` §3 decisions 46-47) --- +# The first visitor would create the admin; a fresh install is closed to everyone but the household until the first setup is done. +setup_gate: true +# measured on 9202 2026-09-29: isClaimed false -> true once the admin claimed it. +setup_done_probe: + url: http://komga:25600/api/v1/claim + field: isClaimed + done: "true" + +# --- App info (info page content) --- +app_info: + tagline: "Képregény, manga és könyv szerver webes olvasóval" + docs_url: "https://komga.org/docs/" + + use_cases: + - 'Képregények és mangák rendszerezése és olvasása böngészőben' + - 'Automatikus metaadat szkennelés és borítókép generálás' + - 'OPDS feed kompatibilis olvasó alkalmazásokhoz' + - 'Olvasási haladás szinkronizálás eszközök között' + - 'Több felhasználó külön könyvtárral' + + first_steps: + - 'Nyisd meg a comics.DOMAIN címet a böngészőben' + - 'Hozd létre az admin fiókot az első megnyitáskor' + - 'Add hozzá a könyvtárat (/data)' + - 'Várd meg az automatikus szkennelést' + - 'Használj OPDS-kompatibilis alkalmazást mobilon (pl. Tachiyomi)' + + prerequisites: + - 'Külső HDD szükséges a képregények tárolásához' + - 'Támogatott formátumok: CBZ, CBR, PDF, EPUB' + +# --- Controller-side health probe --- +healthcheck: + checks: + - type: api + port: 25600 + # /actuator/health is unauthenticated (200); the /api/v1 prefix is auth-gated (401). + path: "/actuator/health" + expect: + status: 200 + +# --- English copy (localisation slice 5, R-560) -------------------------------------------- +# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing +# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely. +i18n: + en: + description: 'A comic and manga server with OPDS support' + app_info: + tagline: 'A comic, manga and book server with a web reader' + use_cases: + - 'Sort and read comics and manga in your browser' + - 'Details are scanned in and covers made on their own' + - 'An OPDS feed for reader apps' + - 'Your reading position follows you between devices' + - 'Several people, each with their own library' + first_steps: + - 'Open comics.DOMAIN in your browser' + - 'Create the admin account the first time you open it' + - 'Add the library (/data)' + - 'Wait for the first scan to finish' + - 'Use an OPDS-compatible app on your phone (Tachiyomi, for example)' + prerequisites: + - 'An external hard drive is needed to keep the comics on' + - 'Formats it reads: CBZ, CBR, PDF, EPUB' + deploy_fields: + - env_var: DOMAIN + label: 'Domain' + description: 'The server domain name' + - env_var: SUBDOMAIN + label: 'Subdomain' + description: 'The subdomain this app answers on' + - env_var: HDD_PATH + label: 'Comic library path' + description: 'The path to the external hard drive' + placeholder: '/mnt/felhom-drives/hdd_1' diff --git a/templates/komga/steps/f7c491acf8f39ff8.yml b/templates/komga/steps/f7c491acf8f39ff8.yml new file mode 100644 index 0000000..ce86bb6 --- /dev/null +++ b/templates/komga/steps/f7c491acf8f39ff8.yml @@ -0,0 +1,63 @@ +# Komga - Képregény és manga szerver OPDS támogatással +# Domain: ${SUBDOMAIN}.${DOMAIN} +# Database: None (file-based) +# RAM: ~460M under load on 1.27 (mem_limit: 768M) | Pi-compatible: Yes +# +# Environment variables: +# DOMAIN - Your domain (e.g., demo-felhom.eu) +# USERDATA_PATH - Ügyfél-tartalom gyökér (/userdata) +# +# Storage layout (felhom userdata convention): +# Képregénytár → ${USERDATA_PATH}/media/comics (írható) +# Run-identity: ROOT (fallback). user "1000:1000" was tried but the gotson/komga image creates its +# SQLite /config DB as root at init and cannot open it when pinned to 1000 (no PUID-style chown) — +# the container crash-loops. So it runs as root and relies on the setgid 2775 userdata dirs: files it +# writes land group 1000 so FileBrowser + group members can READ/browse them. (Verified live; see REPORT.) + +services: + komga: + image: gotson/komga:1.27.1 + container_name: komga + restart: unless-stopped + # Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege + # escalation. Full cap_drop is NOT applied — the image's root-init needs CHOWN/SETUID/SETGID to + # set up /config, and dropping them crash-loops it (the same failure we hit pinning user:1000). + security_opt: + - no-new-privileges:true + environment: + - TZ=Europe/Budapest + volumes: + - komga_config:/config + - ${USERDATA_PATH}/media/comics:/data + networks: + - traefik-public + deploy: + resources: + limits: + # 768M, MEASURED 2026-09-23 night: 1.27.1 used 94.6 % of 512M (its own memory, anon) under ten + # minutes of light load — memory_tight; at 768M 60 %, 0 kills. The JVM grows into what it is given. + memory: 768M + # HC override: komga's actuator lives at /actuator/health (unauthenticated, 200), NOT under the + # auth-gated /api/v1 API prefix — the old /api/v1/actuator/health returns 401 so `curl -f` failed + # (exit 22) and the container reported "unhealthy" despite serving fine. The gotson/komga image + # ships curl (verified), so curl -f on the unauthenticated endpoint is the correct probe. + healthcheck: + test: ["CMD", "curl", "-f", "http://127.0.0.1:25600/actuator/health"] + interval: 30s + timeout: 5s + retries: 3 + start_period: 30s + labels: + - "traefik.enable=true" + - "traefik.http.routers.komga.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" + - "traefik.http.routers.komga.entrypoints=websecure" + - "traefik.http.routers.komga.tls=true" + - "traefik.http.routers.komga.tls.certresolver=letsencrypt" + - "traefik.http.services.komga.loadbalancer.server.port=25600" + +volumes: + komga_config: + +networks: + traefik-public: + external: true