Commit Graph

19 Commits

Author SHA1 Message Date
admin 95cb9bbfa7 romm: remove the client-written X-Forwarded-For chain on its router (R-753)
uvicorn --forwarded-allow-ips=* — leftmost XFF for its pair-code limits. Once traefik trusts the tunnel's fixed address (controller v0.286.0), the leftmost entry is what a
stranger writes; with the chain removed the app reads traefik's X-Real-Ip or its peer, as before — never forgeable.
Measured on 9202: a router with this middleware receives no X-Forwarded-For (felhom.eu audits/visitors-2026-10-01/A/P1).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 21:02:57 +02:00
admin 431cdecb9e romm: database engine mariadb 11.4 -> 11.8, its own edge (proven on the bench AND on 9202)
gates / gates (push) Successful in 2s
After tonight's 5.3.0 -> 5.3.1 step (a separate commit, R-450). The engine
says "already upgraded to 11.8.9-MariaDB". Bench: seed read back; memory
watch 11 332 requests: romm's own memory 78 % of 768M (cgroup 84 %) — just
under the 80 % line, 0 kills; romm-db 26 %. Abort starts-and-serves.
Box (9202): done, read back, R-626 clean. 09 decision 21.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-23 22:00:45 +02:00
admin 7ff4e68d8d romm: 5.3.0 -> 5.3.1 (proven on the bench AND on 9202, with its test record)
gates / gates (push) Successful in 2s
Bench (harness v3, 10-min memory watch): seed read back, peak 79.5 %,
0 kills, abort starts-and-serves. Box (9202, guarded Update, drill
catalog): done, seed read back, R-626 clean at +60 s. Entry written by
upgrade-test.py --write-ladder. 09 decision 21.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-23 21:32:45 +02:00
admin f4eb94f195 romm: two web workers, not four - the actual cause (R-635)
gates / gates (push) Successful in 1s
WEB_SERVER_CONCURRENCY=2, limit left at 768M. No image: line moved.

768M was still a guess and it was wrong: kills slowed from ~12/min to ~7/min and stopped nothing.
Measured instead - each warm uvicorn worker holds ~216 MiB, so four plus the master reach ~882 MiB,
and the cgroup's memory.peak read exactly 768 MiB.

/init:143 runs --workers "${WEB_SERVER_CONCURRENCY:-4}". Four is a server default; this is one
household on one small box. Two measure ~450 MiB, fit 768M with headroom, and halve the CPU churn.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-22 17:55:01 +02:00
admin 886956dcc7 romm: 768M, because 5.3.0 does not fit in 512M (R-635)
gates / gates (push) Successful in 1s
No image: line moved, so no catalog_since moved.

Measured on demo-hp after this morning's promotion: OOMKilled true, 4530 gunicorn worker SIGKILLs
in six hours, ~500% CPU in a permanent restart storm, host load 5.2 while otherwise idle. It ran
clean for two hours first, which is why the walk on the scratch guest did not catch it.

The update reported `done` and the app read `running` the whole time - nginx answers 200 while the
workers behind it die. Nothing alarmed; the operator heard the fans.

768M is a measured first step, not a final answer.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-22 17:46:24 +02:00
admin 15f9ebfb13 romm: 5.0.0 -> 5.3.0 (proven on 9202, R-462)
Walked through the product's own guarded Update on scratch guest 9202 during the
update night, seeded and read back through the app's own front door.
Evidence: felhom.eu/documentation/audits/update-night-2026-09-21/apps/romm/verdict.json
catalog_since -> 2026-09-22 (R-452).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-22 10:57:22 +02:00
admin eec1228dc8 MariaDB finishes its own conversion: MARIADB_AUTO_UPGRADE=1 on the four db services (R-459)
bookstack-db, kimai-db, nextcloud-db, romm-db each gain `MARIADB_AUTO_UPGRADE=1` in the db
service's environment list. Operator ruling 2026-09-13 on the measurement in
felhom.eu/documentation/audits/SPIKE-r459-mariadb-upgrade-2026-09-06.md: an unconverted datadir
is stable but never heals; the conversion costs ~7 s and the engine backs its system tables up
first. MARIADB_DISABLE_UPGRADE_BACKUP is deliberately left UNSET — that backup is the precaution.

NO `image:` line changed, so `catalog_since` does NOT move — the CLAUDE.md rule ties it to an
image change and this is not one. Do not "fix" that.

The setting is inert until an engine major actually moves, and none may until Slice 4 (R-448)
ships — see the engine-major rule in CLAUDE.md and scripts/check-engine-major.py (next commit).
The eleven PostgreSQL templates are untouched: R-463 is a different engine and a different
measurement.

REUSE.md: one convention row for the MariaDB sidecar env, same commit.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-13 09:40:22 +02:00
admin 52e03be3eb romm: 4.5.0 -> 5.0.0 [MAJOR]
Campaign 7 catalog sweep.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nn3VgQk9iwEGgyx6QJ2NvE
2026-07-18 23:27:05 +02:00
admin 8ddd3c9da5 fix(healthcheck): sweep localhost -> 127.0.0.1 across all 48 templates
BusyBox wget (+ node/python/curl one-shots, incl mealie's socket tuple) resolve
localhost -> IPv6 ::1 with no cross-family fallback; an IPv4-only-binding app
reads docker-unhealthy while serving (vaultwarden, re-run 2026-07-06). Escalates
that instance to the class. Scoped strictly to healthcheck test: lines
(diff-reviewed: no env/config/label changed; .felhom.yml already clean). New
REUSE.md convention row.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
2026-07-06 20:25:54 +02:00
admin 69611cec18 userdata layout: repoint customer-content mounts to ${USERDATA_PATH}
Move every shared-media + ingest mount off ${HDD_PATH}/media onto the new
${USERDATA_PATH}/... convention (controller injects USERDATA_PATH = <namespace>/userdata):
- jellyfin/emby/plex: media:/media:ro ; navidrome: media/music:ro
- audiobookshelf (user 1000:1000): media/{audiobooks,podcasts}
- komga (user 1000:1000): media/comics
- calibre-web (UMASK=002): library->media/books, ingest->import/calibre
- radarr/sonarr (UMASK=002): media/{movies,tv} + downloads (sibling, same FS)
- romm: ROM library -> userdata/roms (browsable); resources stay in appdata
- immich: + external library media/photos:/external/photos:ro (registration is a
  post-deploy admin step — flagged in compose + .felhom.yml)
- paperless: consume -> import/paperless (USERMAP 1000)
- nextcloud: unchanged (fully app-managed)
.felhom.yml first_steps updated for the new browsable drop-zones.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-14 21:46:23 +02:00
admin 7e6223190b fix: drop doubled felhom-data segment from HDD app compose templates
Model A binds the guest mount /mnt/<drive> directly onto the host's
<drive>/felhom-data namespace, so the guest mount already IS felhom-data.
The templates' ${HDD_PATH}/felhom-data/appdata/<app> therefore double-nested
to <drive>/felhom-data/felhom-data/appdata/<app> on disk, diverging from the
provenance-aware backup helpers (NamespaceRoot(drive,true) -> single-nested).

Change all four HDD app templates (romm, nextcloud, immich, paperless-ngx)
to ${HDD_PATH}/appdata/<app>, matching AppDataDir(NamespaceRoot(HDD_PATH,true)).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 09:23:48 +02:00
admin dbe92bad5c fix: use felhom-data/appdata/ path for HDD volume mounts
Compose templates were mounting app data at ${HDD_PATH}/appdata/ instead
of ${HDD_PATH}/felhom-data/appdata/ as designed in the v0.26.0+ path
structure. Affects: nextcloud, immich, paperless-ngx, romm.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-23 15:53:15 +01:00
admin 87d0e5e59d feat: use ${SUBDOMAIN} variable in all templates
All 51 docker-compose.yml: replaced hardcoded subdomain.${DOMAIN}
with ${SUBDOMAIN}.${DOMAIN} in Traefik labels, app env vars, and
comments.

All 51 .felhom.yml: added SUBDOMAIN deploy field (type: subdomain)
with default matching existing subdomain metadata value.

Works with felhom-controller v0.27.0 which validates and stores the
user-chosen subdomain in app.yaml. Existing deployed apps get
SUBDOMAIN auto-injected via InjectMissingFields() on next sync.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-22 15:06:44 +01:00
admin 1f9448027e Rename storage/ to appdata/ in all compose templates
Part of v0.14.0 storage architecture overhaul — standardize
app data paths under appdata/ instead of storage/.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-18 18:47:12 +01:00
admin feb36d708d RoMM: add app_info + optional_config metadata, add missing env vars
- Add app_info section: tagline, use cases, first steps, prerequisites, default creds
- Add optional_config: 6 metadata provider fields (IGDB, SteamGridDB, ScreenScraper, MobyGames)
- Add missing env vars to docker-compose.yml: SCREENSCRAPER_USER, SCREENSCRAPER_PASSWORD, MOBYGAMES_API_KEY
- Fix display_name: "ROMM" → "RomM"

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-14 20:14:08 +01:00
admin 6d7e64da93 updated app templates 2026-02-14 13:39:44 +01:00
admin 1ff89ab9da updated app templates to use letsencrypt 2026-02-12 14:09:54 +01:00
admin 872949c3d7 updated app catalog with storage path option 2026-02-12 07:35:56 +01:00
admin 82a8c8b6cf added app-catalog 2026-02-11 20:27:53 +01:00