From 8d3a35a720016f0599143fa4715cc4ea44593c4f Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Wed, 30 Sep 2026 19:18:24 +0200 Subject: [PATCH] rallly: 4.11.1 -> 4.15.3, within-major step, both venues proven (R-462) The app half only; PostgreSQL 18 does not move. Bench 9401 (harness v4, swap 0): sign-up with the e-mail code from its own table, a poll seeded and read back before and after, 10-min watch 0 kills (anon peak 60.6 %); putting 4.11.1 back after the migration loses the poll (recorded; the box's undo restores the pre-update copy). Box 9202: done in 64.7 s through the setup gate, the poll read back. Written by upgrade-test.py --write-ladder. Evidence: felhom.eu/documentation/audits/more-night-apps-2026-09-30/ Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- templates/rallly/.felhom.yml | 1 + templates/rallly/docker-compose.yml | 2 +- .../rallly/steps/076e355244f444f9.felhom.yml | 123 ++++++++++++++++++ templates/rallly/steps/076e355244f444f9.yml | 92 +++++++++++++ 4 files changed, 217 insertions(+), 1 deletion(-) create mode 100644 templates/rallly/steps/076e355244f444f9.felhom.yml create mode 100644 templates/rallly/steps/076e355244f444f9.yml diff --git a/templates/rallly/.felhom.yml b/templates/rallly/.felhom.yml index a1f8c00..38b9a4f 100644 --- a/templates/rallly/.felhom.yml +++ b/templates/rallly/.felhom.yml @@ -127,3 +127,4 @@ i18n: # gated by scripts/check-test-record.py. An image: move without a proven entry here is refused. update_ladder: - {"from": {"rallly": "lukevella/rallly:4.11.1", "rallly-postgres": "postgres:16-alpine"}, "to": {"rallly": "lukevella/rallly:4.11.1", "rallly-postgres": "postgres:18-alpine"}, "digest": {"rallly": "sha256:b2acb78afb1e2e88445e78cec4393cd8b8cc63f9268cf1defe19f96d0db945b0", "rallly-postgres": "sha256:77f585114c32fbca283dc835b0596f4e52b51b4c6662d7810b2f4084f60a1873"}, "verdict": "proven", "tested_at": "2026-09-30T10:40:06Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/bench/apps/rallly/bench/evidence/MV-rallly/verdict.json", "box_evidence": "felhom.eu/documentation/audits/pg-last-six-2026-09-30/box/rallly/box-verdict-rallly.json", "memory_peak_pct": 61.6, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 68.5, "engine_conversion": {"service": "rallly-postgres", "engine": "postgres", "from": 16, "to": 18}} + - {"from": {"rallly": "lukevella/rallly:4.11.1", "rallly-postgres": "postgres:18-alpine"}, "to": {"rallly": "lukevella/rallly:4.15.3", "rallly-postgres": "postgres:18-alpine"}, "digest": {"rallly": "sha256:8cd979aefe8d06e1822bc67054eb2d31088cdb831aa3f7b5615b3768f35431d9", "rallly-postgres": "sha256:77f585114c32fbca283dc835b0596f4e52b51b4c6662d7810b2f4084f60a1873"}, "verdict": "proven", "tested_at": "2026-09-30T17:17:40Z", "harness_version": 4, "evidence": "felhom.eu/documentation/audits/more-night-apps-2026-09-30/bench/apps/rallly/bench/evidence/MV-rallly/verdict.json", "box_evidence": "felhom.eu/documentation/audits/more-night-apps-2026-09-30/box/rallly/step.txt", "memory_peak_pct": 60.6, "marks": {"files_may_change": false, "needs_person": null, "memory_tight": false}, "memory_basis": "anon", "memory_cgroup_peak_pct": 65.8} diff --git a/templates/rallly/docker-compose.yml b/templates/rallly/docker-compose.yml index 0072635..9ff77b7 100644 --- a/templates/rallly/docker-compose.yml +++ b/templates/rallly/docker-compose.yml @@ -10,7 +10,7 @@ services: rallly: - image: lukevella/rallly:4.11.1 + image: lukevella/rallly:4.15.3 container_name: rallly restart: unless-stopped depends_on: diff --git a/templates/rallly/steps/076e355244f444f9.felhom.yml b/templates/rallly/steps/076e355244f444f9.felhom.yml new file mode 100644 index 0000000..ac16d00 --- /dev/null +++ b/templates/rallly/steps/076e355244f444f9.felhom.yml @@ -0,0 +1,123 @@ +# ============================================================================= +# .felhom.yml - App metadata for felhom-controller +# ============================================================================= + +# --- Display info (shown on dashboard) --- +display_name: "Rallly" +description: "Időpont szavazás (Doodle alternatíva)" +category: "productivity" +subdomain: "poll" +slug: "rallly" +# catalog_since: the date THIS repo last changed this app's pinned images. Any commit that +# changes an image: line must set this to the same day (see CLAUDE.md). +catalog_since: "2026-09-30" + +# --- Resource hints (displayed on deploy screen) --- +resources: + mem_request: "384M" + mem_limit: "1024M" + pi_compatible: true + needs_hdd: false + +# --- Deploy fields (first deployment only) --- +deploy_fields: + - env_var: DOMAIN + label: "Domain" + type: domain + description: "A szerver domain neve" + locked_after_deploy: true + + - env_var: SUBDOMAIN + label: "Aldomain" + type: subdomain + default: "poll" + required: true + locked_after_deploy: true + description: "Az alkalmazás aldomainje" + + - env_var: SECRET_PASSWORD + label: "Titkosítási kulcs" + type: secret + generate: "hex:32" + locked_after_deploy: true + + - env_var: DB_PASSWORD + label: "Adatbázis jelszó" + type: secret + generate: "password:24" + locked_after_deploy: true + +# --- The setup gate (controller >= 0.281.0, `09` §3 decisions 46-47) --- +# The first visitor would create the admin; a fresh install is closed to everyone but the household until the first setup is done. +setup_gate: true + +# --- App info (info page content) --- +app_info: + tagline: "Időpont szavazás - Doodle alternatíva a saját szerveren" + docs_url: "https://support.rallly.co/" + + use_cases: + - 'Közös időpont egyeztetés szavazással' + - 'Találkozók, események szervezése' + - 'Résztvevők regisztráció nélkül szavazhatnak' + - 'Email értesítések és emlékeztetők' + - 'Egyszerű, tiszta felület' + + first_steps: + - 'Nyisd meg a poll.DOMAIN címet a böngészőben' + - 'Hozz létre egy új szavazást' + - 'Add meg a lehetséges időpontokat' + - 'Oszd meg a linket a résztvevőkkel' + + +# --- Controller-side health probe --- +healthcheck: + checks: + - type: http + port: 3000 + +# --- App-email mapping (apps → in-controller shim → hub → Resend) --- +# Rallly (Nodemailer) uses STARTTLS to the shim (SMTP_SECURE=false) and accepts the shim's self-signed +# cert (SMTP_REJECT_UNAUTHORIZED=false on v4; v3.x accepts by default). From = Rallly's single +# NOREPLY_EMAIL; SMTP_USER/SMTP_PWD stay unset (the shim accepts no-auth). +smtp_mapping: + host_var: SMTP_HOST + port_var: SMTP_PORT + security_var: SMTP_SECURE + security_value: "false" + from_var: NOREPLY_EMAIL + from_name_var: NOREPLY_EMAIL_NAME + from_local: rallly + extra: + SMTP_REJECT_UNAUTHORIZED: "false" + +# --- English copy (localisation slice 5, R-560) -------------------------------------------- +# The Hungarian above is UNCHANGED. A box on English reads this block field by field; a missing +# field shows the Hungarian one; a controller older than 0.257.0 ignores the block entirely. +i18n: + en: + description: 'Vote on a date (a Doodle alternative)' + app_info: + tagline: 'Vote on a date - a Doodle alternative on your own server' + use_cases: + - 'Agree on a time together, by voting' + - 'Organise meetings and events' + - 'People can vote without signing up' + - 'E-mail notices and reminders' + - 'A simple, clean interface' + first_steps: + - 'Open poll.DOMAIN in your browser' + - 'Create a new poll' + - 'Enter the possible dates' + - 'Share the link with everybody' + deploy_fields: + - env_var: DOMAIN + label: 'Domain' + description: 'The server domain name' + - env_var: SUBDOMAIN + label: 'Subdomain' + description: 'The subdomain this app answers on' + - env_var: DB_PASSWORD + label: 'Database password' + - env_var: SECRET_PASSWORD + label: 'Encryption key' diff --git a/templates/rallly/steps/076e355244f444f9.yml b/templates/rallly/steps/076e355244f444f9.yml new file mode 100644 index 0000000..0072635 --- /dev/null +++ b/templates/rallly/steps/076e355244f444f9.yml @@ -0,0 +1,92 @@ +# Rallly - Időpont szavazás (Doodle alternatíva) +# Domain: ${SUBDOMAIN}.${DOMAIN} +# Database: postgres +# RAM: ~50M (mem_limit: 256M) | Pi-compatible: Yes +# +# Environment variables: +# DOMAIN - Your domain (e.g., demo-felhom.eu) +# SECRET_PASSWORD - Titkosítási kulcs (auto-generated) +# DB_PASSWORD - Adatbázis jelszó (auto-generated) + +services: + rallly: + image: lukevella/rallly:4.11.1 + container_name: rallly + restart: unless-stopped + depends_on: + rallly-postgres: + condition: service_healthy + environment: + - TZ=Europe/Budapest + - DATABASE_URL=postgresql://rallly:${DB_PASSWORD}@rallly-postgres:5432/rallly + - SECRET_PASSWORD=${SECRET_PASSWORD} + - NEXT_PUBLIC_BASE_URL=https://${SUBDOMAIN}.${DOMAIN} + # App-email (managed relay). Injected by the controller only when app-email is on (global + + # per-app); empty SMTP_HOST keeps Rallly mail disabled. Rallly (Nodemailer) reads these at send + # time. SMTP_SECURE=false → STARTTLS to the shim; SMTP_REJECT_UNAUTHORIZED=false accepts the + # shim's self-signed cert (v4 flag; v3.x accepts self-signed by default). See .felhom.yml smtp_mapping. + - SMTP_HOST=${SMTP_HOST:-} + - SMTP_PORT=${SMTP_PORT:-587} + - SMTP_SECURE=${SMTP_SECURE:-false} + - SMTP_REJECT_UNAUTHORIZED=${SMTP_REJECT_UNAUTHORIZED:-true} + # NOREPLY_EMAIL + SUPPORT_EMAIL are REQUIRED by Rallly at boot (it refuses to start without valid + # emails), independent of whether mail can actually send. Default them to valid addresses so Rallly + # boots with app-email OFF; the relay overrides NOREPLY_EMAIL to rallly@felhom.eu when ON. + - NOREPLY_EMAIL=${NOREPLY_EMAIL:-noreply@${DOMAIN}} + - NOREPLY_EMAIL_NAME=${NOREPLY_EMAIL_NAME:-Felhom} + - SUPPORT_EMAIL=${SUPPORT_EMAIL:-noreply@${DOMAIN}} + networks: + - traefik-public + - rallly-internal + deploy: + resources: + limits: + memory: 768M + # The rallly image has NO wget/curl — the old wget healthcheck always failed (exit 127), marking the + # container unhealthy, which made Traefik refuse to publish a route to it. Use Node (always present). + # rallly's "/" returns 307 → /login, so accept any status < 500. + healthcheck: + test: ["CMD", "node", "-e", "require('http').get('http://127.0.0.1:3000',r=>process.exit(r.statusCode<500?0:1)).on('error',()=>process.exit(1))"] + interval: 30s + timeout: 5s + retries: 3 + start_period: 30s + labels: + - "traefik.enable=true" + - "traefik.http.routers.rallly.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)" + - "traefik.http.routers.rallly.entrypoints=websecure" + - "traefik.http.routers.rallly.tls=true" + - "traefik.http.routers.rallly.tls.certresolver=letsencrypt" + - "traefik.http.services.rallly.loadbalancer.server.port=3000" + + rallly-postgres: + image: postgres:18-alpine + container_name: rallly-postgres + restart: unless-stopped + environment: + - POSTGRES_USER=rallly + - POSTGRES_PASSWORD=${DB_PASSWORD} + - POSTGRES_DB=rallly + - TZ=Europe/Budapest + volumes: + - rallly_postgres_data:/var/lib/postgresql + networks: + - rallly-internal + deploy: + resources: + limits: + memory: 256M + healthcheck: + test: ["CMD-SHELL", "pg_isready -U rallly -d rallly"] + interval: 10s + timeout: 5s + retries: 5 + start_period: 20s + +volumes: + rallly_postgres_data: + +networks: + traefik-public: + external: true + rallly-internal: