{'komga': 'gotson/komga:1.27.1'} -> {'komga': 'gotson/komga:1.28.0'}
The ONLY image move in this commit. Written by upgrade-test.py --write-ladder (catalog gates rc=0):
- bench LXC 9401 (harness v4): the seed read back before and after; 10-minute memory watch:
komga anon 64.5 % (cgroup 67.5 %); 0 kills, 0 restarts; the abort starts and serves the data;
- box 9202 (controller 0.283.1, the product's guarded Update, drill catalog): done in 44.2 s, the seed
read back through the app's own front door.
Evidence: felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/ and .../box/komga/
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -10,7 +10,7 @@ subdomain: "comics"
|
||||
slug: "komga"
|
||||
# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that
|
||||
# changes an image: line must set this to the same day (see CLAUDE.md).
|
||||
catalog_since: "2026-09-23"
|
||||
catalog_since: "2026-09-30"
|
||||
|
||||
# --- Resource hints (displayed on deploy screen) ---
|
||||
resources:
|
||||
@@ -131,3 +131,4 @@ i18n:
|
||||
# gated by scripts/check-test-record.py. An image: move without a proven entry here is refused.
|
||||
update_ladder:
|
||||
- {"from": {"komga": "gotson/komga:1.25.0"}, "to": {"komga": "gotson/komga:1.27.1"}, "digest": {"komga": "sha256:9cf102f5fb78e2e020700c53eca757e4f4d4e347121b0a16380822760337cca9"}, "verdict": "proven", "tested_at": "2026-09-23T19:46:46Z", "harness_version": 3, "evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/komga/bench/evidence/MV-komga/verdict.json", "box_evidence": "felhom.eu/documentation/audits/night-2026-09-23/apps/komga/verdict.json", "memory_peak_pct": 60.0, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 76.8}
|
||||
- {"from": {"komga": "gotson/komga:1.27.1"}, "to": {"komga": "gotson/komga:1.28.0"}, "digest": {"komga": "sha256:19764751d501495b021530c9426f25d8f9f8748dc38ab3ba48eb62d7df2cd92e"}, "verdict": "proven", "tested_at": "2026-09-30T12:30:04Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/apps/komga/bench/evidence/MV-komga/verdict.json", "box_evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/box/komga/box-verdict-komga.json", "memory_peak_pct": 64.5, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 67.5}
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
|
||||
services:
|
||||
komga:
|
||||
image: gotson/komga:1.27.1
|
||||
image: gotson/komga:1.28.0
|
||||
container_name: komga
|
||||
restart: unless-stopped
|
||||
# Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege
|
||||
|
||||
@@ -0,0 +1,127 @@
|
||||
# =============================================================================
|
||||
# .felhom.yml - App metadata for felhom-controller
|
||||
# =============================================================================
|
||||
|
||||
# --- Display info (shown on dashboard) ---
|
||||
display_name: "Komga"
|
||||
description: "Képregény és manga szerver OPDS támogatással"
|
||||
category: "media"
|
||||
subdomain: "comics"
|
||||
slug: "komga"
|
||||
# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that
|
||||
# changes an image: line must set this to the same day (see CLAUDE.md).
|
||||
catalog_since: "2026-09-23"
|
||||
|
||||
# --- Resource hints (displayed on deploy screen) ---
|
||||
resources:
|
||||
mem_request: "200M"
|
||||
mem_limit: "768M"
|
||||
pi_compatible: true
|
||||
needs_hdd: true
|
||||
|
||||
# --- Backup classification (referential coupling; see felhom.eu documentation/audits/SPIKE-backup-classification-2026-07-14.md) ---
|
||||
backup:
|
||||
userdata:
|
||||
- path: media/comics
|
||||
class: optional # ruled: precious-decoupled (re-scanned, hand-curated)
|
||||
|
||||
# --- Deploy fields (first deployment only) ---
|
||||
deploy_fields:
|
||||
- env_var: DOMAIN
|
||||
label: "Domain"
|
||||
type: domain
|
||||
description: "A szerver domain neve"
|
||||
locked_after_deploy: true
|
||||
|
||||
- env_var: SUBDOMAIN
|
||||
label: "Aldomain"
|
||||
type: subdomain
|
||||
default: "comics"
|
||||
required: true
|
||||
locked_after_deploy: true
|
||||
description: "Az alkalmazás aldomainje"
|
||||
|
||||
- env_var: HDD_PATH
|
||||
label: "Képregénytár útvonal"
|
||||
type: path
|
||||
required: true
|
||||
placeholder: "/mnt/felhom-drives/hdd_1"
|
||||
description: "A külső merevlemez elérési útja"
|
||||
locked_after_deploy: true
|
||||
|
||||
# --- The setup gate (controller >= 0.281.0, `09` §3 decisions 46-47) ---
|
||||
# The first visitor would create the admin; a fresh install is closed to everyone but the household until the first setup is done.
|
||||
setup_gate: true
|
||||
# measured on 9202 2026-09-29: isClaimed false -> true once the admin claimed it.
|
||||
setup_done_probe:
|
||||
url: http://komga:25600/api/v1/claim
|
||||
field: isClaimed
|
||||
done: "true"
|
||||
|
||||
# --- App info (info page content) ---
|
||||
app_info:
|
||||
tagline: "Képregény, manga és könyv szerver webes olvasóval"
|
||||
docs_url: "https://komga.org/docs/"
|
||||
|
||||
use_cases:
|
||||
- 'Képregények és mangák rendszerezése és olvasása böngészőben'
|
||||
- 'Automatikus metaadat szkennelés és borítókép generálás'
|
||||
- 'OPDS feed kompatibilis olvasó alkalmazásokhoz'
|
||||
- 'Olvasási haladás szinkronizálás eszközök között'
|
||||
- 'Több felhasználó külön könyvtárral'
|
||||
|
||||
first_steps:
|
||||
- 'Nyisd meg a comics.DOMAIN címet a böngészőben'
|
||||
- 'Hozd létre az admin fiókot az első megnyitáskor'
|
||||
- 'Add hozzá a könyvtárat (/data)'
|
||||
- 'Várd meg az automatikus szkennelést'
|
||||
- 'Használj OPDS-kompatibilis alkalmazást mobilon (pl. Tachiyomi)'
|
||||
|
||||
prerequisites:
|
||||
- 'Külső HDD szükséges a képregények tárolásához'
|
||||
- 'Támogatott formátumok: CBZ, CBR, PDF, EPUB'
|
||||
|
||||
# --- Controller-side health probe ---
|
||||
healthcheck:
|
||||
checks:
|
||||
- type: api
|
||||
port: 25600
|
||||
# /actuator/health is unauthenticated (200); the /api/v1 prefix is auth-gated (401).
|
||||
path: "/actuator/health"
|
||||
expect:
|
||||
status: 200
|
||||
|
||||
# --- English copy (localisation slice 5, R-560) --------------------------------------------
|
||||
# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing
|
||||
# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely.
|
||||
i18n:
|
||||
en:
|
||||
description: 'A comic and manga server with OPDS support'
|
||||
app_info:
|
||||
tagline: 'A comic, manga and book server with a web reader'
|
||||
use_cases:
|
||||
- 'Sort and read comics and manga in your browser'
|
||||
- 'Details are scanned in and covers made on their own'
|
||||
- 'An OPDS feed for reader apps'
|
||||
- 'Your reading position follows you between devices'
|
||||
- 'Several people, each with their own library'
|
||||
first_steps:
|
||||
- 'Open comics.DOMAIN in your browser'
|
||||
- 'Create the admin account the first time you open it'
|
||||
- 'Add the library (/data)'
|
||||
- 'Wait for the first scan to finish'
|
||||
- 'Use an OPDS-compatible app on your phone (Tachiyomi, for example)'
|
||||
prerequisites:
|
||||
- 'An external hard drive is needed to keep the comics on'
|
||||
- 'Formats it reads: CBZ, CBR, PDF, EPUB'
|
||||
deploy_fields:
|
||||
- env_var: DOMAIN
|
||||
label: 'Domain'
|
||||
description: 'The server domain name'
|
||||
- env_var: SUBDOMAIN
|
||||
label: 'Subdomain'
|
||||
description: 'The subdomain this app answers on'
|
||||
- env_var: HDD_PATH
|
||||
label: 'Comic library path'
|
||||
description: 'The path to the external hard drive'
|
||||
placeholder: '/mnt/felhom-drives/hdd_1'
|
||||
@@ -0,0 +1,63 @@
|
||||
# Komga - Képregény és manga szerver OPDS támogatással
|
||||
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
||||
# Database: None (file-based)
|
||||
# RAM: ~460M under load on 1.27 (mem_limit: 768M) | Pi-compatible: Yes
|
||||
#
|
||||
# Environment variables:
|
||||
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
||||
# USERDATA_PATH - Ügyfél-tartalom gyökér (<namespace>/userdata)
|
||||
#
|
||||
# Storage layout (felhom userdata convention):
|
||||
# Képregénytár → ${USERDATA_PATH}/media/comics (írható)
|
||||
# Run-identity: ROOT (fallback). user "1000:1000" was tried but the gotson/komga image creates its
|
||||
# SQLite /config DB as root at init and cannot open it when pinned to 1000 (no PUID-style chown) —
|
||||
# the container crash-loops. So it runs as root and relies on the setgid 2775 userdata dirs: files it
|
||||
# writes land group 1000 so FileBrowser + group members can READ/browse them. (Verified live; see REPORT.)
|
||||
|
||||
services:
|
||||
komga:
|
||||
image: gotson/komga:1.27.1
|
||||
container_name: komga
|
||||
restart: unless-stopped
|
||||
# Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege
|
||||
# escalation. Full cap_drop is NOT applied — the image's root-init needs CHOWN/SETUID/SETGID to
|
||||
# set up /config, and dropping them crash-loops it (the same failure we hit pinning user:1000).
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
environment:
|
||||
- TZ=Europe/Budapest
|
||||
volumes:
|
||||
- komga_config:/config
|
||||
- ${USERDATA_PATH}/media/comics:/data
|
||||
networks:
|
||||
- traefik-public
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
# 768M, MEASURED 2026-09-23 night: 1.27.1 used 94.6 % of 512M (its own memory, anon) under ten
|
||||
# minutes of light load — memory_tight; at 768M 60 %, 0 kills. The JVM grows into what it is given.
|
||||
memory: 768M
|
||||
# HC override: komga's actuator lives at /actuator/health (unauthenticated, 200), NOT under the
|
||||
# auth-gated /api/v1 API prefix — the old /api/v1/actuator/health returns 401 so `curl -f` failed
|
||||
# (exit 22) and the container reported "unhealthy" despite serving fine. The gotson/komga image
|
||||
# ships curl (verified), so curl -f on the unauthenticated endpoint is the correct probe.
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://127.0.0.1:25600/actuator/health"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.komga.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
||||
- "traefik.http.routers.komga.entrypoints=websecure"
|
||||
- "traefik.http.routers.komga.tls=true"
|
||||
- "traefik.http.routers.komga.tls.certresolver=letsencrypt"
|
||||
- "traefik.http.services.komga.loadbalancer.server.port=25600"
|
||||
|
||||
volumes:
|
||||
komga_config:
|
||||
|
||||
networks:
|
||||
traefik-public:
|
||||
external: true
|
||||
Reference in New Issue
Block a user