From 73a9bc48073058dcb5b79c1277844e36f0ea5057 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Tue, 15 Sep 2026 11:28:51 +0200 Subject: [PATCH] vaultwarden: compose header matches invite-first; live proof lines (R-512/R-514) Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- CHANGELOG.md | 6 ++++++ templates/vaultwarden/docker-compose.yml | 10 +++++----- 2 files changed, 11 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index cf33c5d..fc14e0c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,12 @@ templates changed. Now 1 × 1 and `memory: 1280M` (peak × 1.5, rounded up to 256M); `mem_limit` hint 1664M. Caveat recorded: the test PDFs carried text, so OCR on scanned images may need more — the controller's new OOM line (controller v0.243.0) makes that visible if it happens. +- **Vaultwarden compose header** no longer tells the reader to "Set SIGNUPS_ALLOWED=false via the + controller" (settings are read-only after install); it describes the invite-first steps. **Proven + live 2026-09-15 on scratch 9202:** deployed from the catalog through the controller API, container + `SIGNUPS_ALLOWED=false`, a stranger's `send-verification-email` through traefik → **400 „Registration + not allowed"**; Paperless deployed the same way: 20 PDFs at once → **20/20 SUCCESS**, `memory.peak` + 772 370 432 B under the 1280M cap, no OOM. - **R-515 — the Paperless card no longer says `admin / admin`.** That login never existed (the password is generated). `default_creds` removed; first steps point at „Automatikusan generált értékek", the gokapi wording. diff --git a/templates/vaultwarden/docker-compose.yml b/templates/vaultwarden/docker-compose.yml index 94b45f4..1a58165 100644 --- a/templates/vaultwarden/docker-compose.yml +++ b/templates/vaultwarden/docker-compose.yml @@ -6,12 +6,12 @@ # Environment variables: # DOMAIN - Your domain (e.g., demo-felhom.eu) # ADMIN_TOKEN - Admin panel token (auto-generated) -# SIGNUPS_ALLOWED - Set to "false" after creating your account(s) +# SIGNUPS_ALLOWED - "false" by default (R-512): only invited addresses can register # -# First-time setup: -# 1. Visit https://${SUBDOMAIN}.${DOMAIN} and create an account -# 2. Set SIGNUPS_ALLOWED=false via the controller -# 3. Admin panel at https://${SUBDOMAIN}.${DOMAIN}/admin (if ADMIN_TOKEN set) +# First-time setup (invite-first; settings are read-only after install): +# 1. Open https://${SUBDOMAIN}.${DOMAIN}/admin with the generated ADMIN_TOKEN +# 2. Invite the household's addresses (Users → Invite User; works without mail) +# 3. Visit https://${SUBDOMAIN}.${DOMAIN} and create the account with an invited address # # Clients: # Use any Bitwarden client (desktop, mobile, browser extension)