3.4 KiB
REPORT — crafty-controller: seed a felhom-generated admin password (gokapi pattern)
Date: 2026-06-26 · Repo: app-catalog-felhom.eu (catalog-only) · Commit: 5a403d1
Guest: 9201 (demo-felhom) on felhom-pve · Controller: v0.84.0 (unchanged — reuses its initial_credentials reader)
Goal
Replace Crafty's auto-generated, ugly random admin password with a clean felhom-generated one, using the same seeding pattern as gokapi (consistency), while keeping it visible on the app page.
Root mechanism (discovered in Crafty source)
main_models.default_settings reads app/config/default.json on fresh install; the image ships
config_original/default.json = {"username":"admin","password":"crafty"} — 6 chars, below Crafty's
8-char minimum, so Crafty rejected it and generated a random password into default-creds.txt. We can't
"lengthen" that internal fallback — we seed a valid default.json instead.
Change (catalog-only)
docker-compose.yml: newCRAFTY_PASSWORDenv + an entrypoint wrapper that overwritesconfig_original/default.jsonwith{"username":"admin","password":"$CRAFTY_PASSWORD"}before exec'ing the image launcher (/crafty/docker_launcher.sh -d -i). On fresh install the launcher copies our template into the config volume → Crafty createsadminwith our password..felhom.yml: newCRAFTY_PASSWORDdeploy field (type: password,generate: password:24,locked_after_deploy— mirrors gokapi'sGOKAPI_PASSWORD, alphanumeric so JSON/shell-safe). Repointedinitial_credentials.filedefault-creds.txt→default.jsonso the controller's "Kezdeti belépési adatok" card shows the seeded password.- No controller change: the deploy flow already injects/decrypts password deploy-fields into the compose
env (
stackEnv), and v0.84.0'sinitial_credentialsreader already parsesdefault.json.
Live validation (guest 9201 — fresh install via the real pipeline)
Removed crafty + wiped its volumes, then deployed via POST /api/stacks/crafty-controller/deploy with
{DOMAIN, SUBDOMAIN, CRAFTY_PASSWORD} (clean 24-char alphanumeric).
| Check | Result |
|---|---|
| Fresh install, no "Default password too short" | ✅ Crafty used our seeded password |
default.json in volume |
{"username":"admin","password":"<seeded>"} |
Crafty API login admin/seeded |
HTTP 200 + token (gold standard) |
Stray default-creds.txt random pw |
401 rejected — non-functional artifact (see note) |
app.yaml |
CRAFTY_PASSWORD: ENC:… (encrypted at rest) + in locked_fields |
| App-page card | shows the seeded password (from default.json) |
Public URL minecraft.demo-felhom.eu |
302 |
Known quirk (documented, low-risk)
Crafty still writes default-creds.txt with a different random password during init even though it
used our default.json. That password is non-functional (login → 401) and the file is not shown
anywhere in the felhom UI (the card reads default.json; FileBrowser is scoped to userdata, not
/crafty/app/config). Left as-is — a post-boot cleanup would be a racy entrypoint hack for an invisible
file. The canonical, working password is the seeded one shown on the app page.
Consistency
crafty now matches gokapi: a felhom-generated, locked, password-type deploy field set at deploy time —
plus the app-page card (v0.84.0 reader) so the initial login is also visible there.