catalog: re-pin wanderer to the current upstream shape, retire plant-it, add the resolvability gate

wanderer: ghcr.io/flomp/wanderer:0.16.0 is a ghost - upstream split the app
into web+db images, moved registry and renamed the org. Restructured to
upstream's own v0.20.0 compose (3 services, new /data/plugins volume, second
public hostname for PocketBase, meilisearch pinned DOWN to upstream's v1.36.0
per the R-42 ruling).

plant-it: retired. The repo name was wrong (plant-it-server) but upstream has
DELETED self-hosting; last server image is 2024-12-10 and it needs MySQL+Redis
the template never had. Moved to retired/ rather than deleted - reversible.

R-41 slice 1: check-image-resolvable.py. Encodes two traps - manifest inspect
exits 0 while printing toomanyrequests, and the inverse, where the first sweep
called 24 of 65 pins dead because Hub throttled it. Ambiguity is INCONCLUSIVE,
never an accusation.
This commit is contained in:
2026-07-21 15:30:15 +02:00
parent 34d50a33ac
commit b3eabfd611
12 changed files with 575 additions and 71 deletions
+17
View File
@@ -0,0 +1,17 @@
# Retired templates
Apps that were removed from `templates/` and are therefore **no longer offered to customers**.
The controller discovers apps by directory name under `templates/` (`internal/sync/sync.go`
`copyTemplates`), so anything here is invisible to the catalog sync. The files are kept rather than
deleted so a retirement is reversible: `git mv retired/<app> templates/<app>` puts it back, and the
full history of the template is intact either way.
**Note on boxes that already synced the app:** the sync only ADDS and UPDATES — it never removes a
stack directory it previously copied. Retiring a template therefore stops it being offered to NEW
boxes and freezes it on existing ones; it does not reach out and delete anything. For every app
retired so far this is moot, because none of them was ever successfully deployable.
| App | Retired | Why |
|---|---|---|
| `plant-it` | 2026-07-21 | **Upstream discontinued self-hosting.** The pinned `msdeluise/plant-it:0.10.0` never resolved because the image repository is `msdeluise/plant-it-server` — but fixing the name was not the real answer. The `backend/` and `deployment/` directories have been DELETED from upstream `main`; the project is now an Android app distributed via F-Droid/Obtainium, with a maintainer note that active development has slowed. The last server image, `msdeluise/plant-it-server:0.10.0`, was pushed **2024-12-10** and is a security-frozen Spring Boot 3.4.0. It also requires **MySQL 8.0 + Redis**, which the template never had — its header claimed "Database: None (file-based)", which was wrong from the start. Operator ruling 2026-07-21: do not ship unmaintained software to customers. Revive only if upstream restores a maintained server edition. |
+67
View File
@@ -0,0 +1,67 @@
# =============================================================================
# .felhom.yml - App metadata for felhom-controller
# =============================================================================
# --- Display info (shown on dashboard) ---
display_name: "Plant-it"
description: "Növénynapló és gondozás emlékeztető"
category: "home"
subdomain: "plants"
slug: "plant-it"
# --- Resource hints (displayed on deploy screen) ---
resources:
mem_request: "50M"
mem_limit: "256M"
pi_compatible: true
needs_hdd: false
# --- Deploy fields (first deployment only) ---
deploy_fields:
- env_var: DOMAIN
label: "Domain"
type: domain
description: "A szerver domain neve"
locked_after_deploy: true
- env_var: SUBDOMAIN
label: "Aldomain"
type: subdomain
default: "plants"
required: true
locked_after_deploy: true
description: "Az alkalmazás aldomainje"
- env_var: JWT_SECRET
label: "JWT titkosítási kulcs"
type: secret
generate: "hex:32"
locked_after_deploy: true
# --- App info (info page content) ---
app_info:
tagline: "Növénynapló - emlékeztetők öntözésre, trágyázásra és fotónapló"
docs_url: "https://docs.plant-it.org/"
use_cases:
- 'Szobanövények és kerti növények nyilvántartása'
- 'Emlékeztetők öntözésre, trágyázásra, átültetésre'
- 'Fotónapló a növények fejlődéséről'
- 'Statisztikák és gondozási előzmények'
- 'Több felhasználó - a család együtt gondozhat'
first_steps:
- 'Nyisd meg a plants.DOMAIN címet a böngészőben'
- 'Hozd létre a fiókodat'
- 'Add hozzá az első növényt fotóval'
- 'Állíts be gondozási emlékeztetőket'
# --- Controller-side health probe ---
healthcheck:
checks:
- type: api
port: 8080
path: "/api/info"
expect:
status: 200
+50
View File
@@ -0,0 +1,50 @@
# Plant-it - Növénynapló és gondozás emlékeztető
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~50M (mem_limit: 256M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# JWT_SECRET - JWT titkosítási kulcs (auto-generated)
services:
plant-it:
image: msdeluise/plant-it:0.10.0
container_name: plant-it
restart: unless-stopped
environment:
- TZ=Europe/Budapest
- JWT_SECRET=${JWT_SECRET}
- USERS_LIMIT=-1
- UPLOAD_DIR=/upload-dir
- API_PORT=8080
volumes:
- plantit_data:/upload-dir
- plantit_db:/app/db
networks:
- traefik-public
deploy:
resources:
limits:
memory: 256M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:8080/api/info"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.plant-it.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.plant-it.entrypoints=websecure"
- "traefik.http.routers.plant-it.tls=true"
- "traefik.http.routers.plant-it.tls.certresolver=letsencrypt"
- "traefik.http.services.plant-it.loadbalancer.server.port=8080"
volumes:
plantit_data:
plantit_db:
networks:
traefik-public:
external: true