tandoor: PostgreSQL 16 -> 17, converted by the box (09 decision 42)
gates / gates (push) Successful in 2s

Written by upgrade-test.py --write-ladder: bench converted in 23.6 s, check equal over 100 tables, seed read back, memory watch anon peak 78.7 % (the app, not the engine), 0 kills; box 9202 converted through the guarded Update in 52.3 s, seed read back. The superseded 16 step keeps its definition in steps/. Evidence felhom.eu/documentation/audits/version-travel-2026-09-26/B/.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-27 12:08:57 +02:00
parent 46affe00d4
commit 53b84cadb9
4 changed files with 202 additions and 2 deletions
+2 -1
View File
@@ -10,7 +10,7 @@ subdomain: "recipes"
slug: "tandoor"
# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that
# changes an image: line must set this to the same day (see CLAUDE.md).
catalog_since: "2026-09-22"
catalog_since: "2026-09-27"
# --- Resource hints (displayed on deploy screen) ---
resources:
@@ -114,3 +114,4 @@ i18n:
# gated by scripts/check-test-record.py. An image: move without a proven entry here is refused.
update_ladder:
- {"from": {"tandoor": "ghcr.io/tandoorrecipes/recipes:2.6.13", "tandoor-postgres": "postgres:16-alpine"}, "to": {"tandoor": "ghcr.io/tandoorrecipes/recipes:2.6.15", "tandoor-postgres": "postgres:16-alpine"}, "digest": {"tandoor": "sha256:2e759dd1478a2ed119ee474e28522079fb1cfa50b3fd25cba89f6b9a67abad72", "tandoor-postgres": "sha256:721873c34ceb9f8d8fc265984940dc982404c105f19ad51be9fdc5970a6080ea"}, "verdict": "proven", "tested_at": "2026-09-22T08:52:42.724401+00:00", "harness_version": 1, "evidence": "felhom.eu/documentation/audits/update-night-2026-09-21/apps/tandoor/verdict.json", "memory_peak_pct": null, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "backfilled": "2026-09-23", "note": "backfilled from catalog commit c3807c7; box walk only (harness v1, no memory watch); digest = what the registry served on 2026-09-23, not a measurement of the tested image"}
- {"from": {"tandoor": "ghcr.io/tandoorrecipes/recipes:2.6.15", "tandoor-postgres": "postgres:16-alpine"}, "to": {"tandoor": "ghcr.io/tandoorrecipes/recipes:2.6.15", "tandoor-postgres": "postgres:17-alpine"}, "digest": {"tandoor": "sha256:2e759dd1478a2ed119ee474e28522079fb1cfa50b3fd25cba89f6b9a67abad72", "tandoor-postgres": "sha256:b0f9560a2de083e2cc7382e75f808c7381a32852a7ec49117deedb300e552b24"}, "verdict": "proven", "tested_at": "2026-09-27T10:07:25Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/version-travel-2026-09-26/B/apps/tandoor/bench/evidence/MV-tandoor/verdict.json", "box_evidence": "felhom.eu/documentation/audits/version-travel-2026-09-26/B/apps/tandoor/box/box-verdict-tandoor.json", "memory_peak_pct": 78.7, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 97.8, "engine_conversion": {"service": "tandoor-postgres", "engine": "postgres", "from": 16, "to": 17}}
+1 -1
View File
@@ -55,7 +55,7 @@ services:
- "traefik.http.services.tandoor.loadbalancer.server.port=80"
tandoor-postgres:
image: postgres:16-alpine
image: postgres:17-alpine
container_name: tandoor-postgres
restart: unless-stopped
environment:
@@ -0,0 +1,110 @@
# =============================================================================
# .felhom.yml - App metadata for felhom-controller
# =============================================================================
# --- Display info (shown on dashboard) ---
display_name: "Tandoor Recipes"
description: "Receptkezelő és étkezés tervező"
category: "home"
subdomain: "recipes"
slug: "tandoor"
# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that
# changes an image: line must set this to the same day (see CLAUDE.md).
catalog_since: "2026-09-22"
# --- Resource hints (displayed on deploy screen) ---
resources:
mem_request: "512M"
mem_limit: "1280M"
pi_compatible: true
needs_hdd: false
# --- Deploy fields (first deployment only) ---
deploy_fields:
- env_var: DOMAIN
label: "Domain"
type: domain
description: "A szerver domain neve"
locked_after_deploy: true
- env_var: SUBDOMAIN
label: "Aldomain"
type: subdomain
default: "recipes"
required: true
locked_after_deploy: true
description: "Az alkalmazás aldomainje"
- env_var: SECRET_KEY
label: "Titkosítási kulcs"
type: secret
generate: "hex:32"
locked_after_deploy: true
- env_var: DB_PASSWORD
label: "Adatbázis jelszó"
type: secret
generate: "password:24"
locked_after_deploy: true
# --- App info (info page content) ---
app_info:
tagline: "Receptkezelő és étkezés tervező a családnak"
docs_url: "https://docs.tandoor.dev/"
use_cases:
- 'Receptek gyűjtése és rendszerezése egy helyen'
- 'Receptek importálása weboldalakról egy kattintással'
- 'Heti étkezés tervezés és bevásárlólista generálás'
- 'Több felhasználó - a család együtt tervezhet'
- 'Receptek megosztása linkkel családtagokkal, barátokkal'
first_steps:
- 'Nyisd meg a recipes.DOMAIN címet a böngészőben'
- 'Hozd létre az admin fiókot'
- 'Importáld az első receptet egy weboldalról (Bookmarklet)'
- 'Próbáld ki az étkezés tervezőt'
- 'Hívd meg a családtagokat'
# --- Controller-side health probe ---
healthcheck:
checks:
- type: http
# 80, not 8080: the probe dials the container from INSIDE the compose
# network, so this is the port the process LISTENS on. tandoor's own compose healthcheck
# dials 127.0.0.1:80 (R-618).
port: 80
path: "/accounts/login/"
# --- English copy (localisation slice 5, R-560) --------------------------------------------
# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing
# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely.
i18n:
en:
description: 'A recipe manager and meal planner'
app_info:
tagline: 'A recipe manager and meal planner for the household'
use_cases:
- 'Keep all your recipes in one place'
- 'Import a recipe from a web page with one click'
- 'Plan the week''s meals and get a shopping list out of it'
- 'Several people - the household can plan together'
- 'Share a recipe by link with family and friends'
first_steps:
- 'Open recipes.DOMAIN in your browser'
- 'Create the admin account'
- 'Import your first recipe from a web page (Bookmarklet)'
- 'Try the meal planner'
- 'Invite the household'
deploy_fields:
- env_var: DOMAIN
label: 'Domain'
description: 'The server domain name'
- env_var: SUBDOMAIN
label: 'Subdomain'
description: 'The subdomain this app answers on'
- env_var: DB_PASSWORD
label: 'Database password'
- env_var: SECRET_KEY
label: 'Encryption key'
@@ -0,0 +1,89 @@
# Tandoor Recipes - Receptkezelő és étkezés tervező
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: postgres
# RAM: ~150M (mem_limit: 512M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# SECRET_KEY - Titkosítási kulcs (auto-generated)
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
services:
tandoor:
image: ghcr.io/tandoorrecipes/recipes:2.6.15
container_name: tandoor
restart: unless-stopped
depends_on:
tandoor-postgres:
condition: service_healthy
environment:
- SECRET_KEY=${SECRET_KEY}
# A tandoor 2.x Django-ja ALLOWED_HOSTS nélkül MINDEN kérésre 400-at ad
# (a healthcheck-re is), a konténer így soha nem lesz healthy.
- ALLOWED_HOSTS=${SUBDOMAIN}.${DOMAIN},127.0.0.1,localhost
- DB_ENGINE=django.db.backends.postgresql
- POSTGRES_HOST=tandoor-postgres
- POSTGRES_PORT=5432
- POSTGRES_USER=tandoor
- POSTGRES_PASSWORD=${DB_PASSWORD}
- POSTGRES_DB=tandoor
- TZ=Europe/Budapest
volumes:
- tandoor_static:/opt/recipes/staticfiles
- tandoor_media:/opt/recipes/mediafiles
networks:
- traefik-public
- tandoor-internal
deploy:
resources:
limits:
memory: 1024M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:80/accounts/login/"]
interval: 30s
timeout: 5s
retries: 3
# A tandoor (django-vite + migrációk) lassan bindol: 30s alatt még
# "Connection refused" jött, és a próbák elfogytak, mielőtt elindult.
start_period: 240s
labels:
- "traefik.enable=true"
- "traefik.http.routers.tandoor.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.tandoor.entrypoints=websecure"
- "traefik.http.routers.tandoor.tls=true"
- "traefik.http.routers.tandoor.tls.certresolver=letsencrypt"
- "traefik.http.services.tandoor.loadbalancer.server.port=80"
tandoor-postgres:
image: postgres:16-alpine
container_name: tandoor-postgres
restart: unless-stopped
environment:
- POSTGRES_USER=tandoor
- POSTGRES_PASSWORD=${DB_PASSWORD}
- POSTGRES_DB=tandoor
- TZ=Europe/Budapest
volumes:
- tandoor_postgres_data:/var/lib/postgresql/data
networks:
- tandoor-internal
deploy:
resources:
limits:
memory: 256M
healthcheck:
test: ["CMD-SHELL", "pg_isready -U tandoor -d tandoor"]
interval: 10s
timeout: 5s
retries: 5
start_period: 20s
volumes:
tandoor_media:
tandoor_postgres_data:
tandoor_static:
networks:
traefik-public:
external: true
tandoor-internal: