Files
app-catalog-felhom.eu/templates/komga/steps/f7c491acf8f39ff8.yml
T
admin 403a8f537a
gates / gates (push) Successful in 2s
komga: within-major step, both venues proven (R-462, Part F)
{'komga': 'gotson/komga:1.27.1'} -> {'komga': 'gotson/komga:1.28.0'}
The ONLY image move in this commit. Written by upgrade-test.py --write-ladder (catalog gates rc=0):
- bench LXC 9401 (harness v4): the seed read back before and after; 10-minute memory watch:
  komga anon 64.5 % (cgroup 67.5 %); 0 kills, 0 restarts; the abort starts and serves the data;
- box 9202 (controller 0.283.1, the product's guarded Update, drill catalog): done in 44.2 s, the seed
  read back through the app's own front door.
Evidence: felhom.eu/documentation/audits/pg-last-six-2026-09-30/F/ and .../box/komga/

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-30 14:30:27 +02:00

64 lines
2.7 KiB
YAML

# Komga - Képregény és manga szerver OPDS támogatással
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~460M under load on 1.27 (mem_limit: 768M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# USERDATA_PATH - Ügyfél-tartalom gyökér (<namespace>/userdata)
#
# Storage layout (felhom userdata convention):
# Képregénytár → ${USERDATA_PATH}/media/comics (írható)
# Run-identity: ROOT (fallback). user "1000:1000" was tried but the gotson/komga image creates its
# SQLite /config DB as root at init and cannot open it when pinned to 1000 (no PUID-style chown) —
# the container crash-loops. So it runs as root and relies on the setgid 2775 userdata dirs: files it
# writes land group 1000 so FileBrowser + group members can READ/browse them. (Verified live; see REPORT.)
services:
komga:
image: gotson/komga:1.27.1
container_name: komga
restart: unless-stopped
# Runs as root (see note above). Restore an escalation boundary: block SUID-based privilege
# escalation. Full cap_drop is NOT applied — the image's root-init needs CHOWN/SETUID/SETGID to
# set up /config, and dropping them crash-loops it (the same failure we hit pinning user:1000).
security_opt:
- no-new-privileges:true
environment:
- TZ=Europe/Budapest
volumes:
- komga_config:/config
- ${USERDATA_PATH}/media/comics:/data
networks:
- traefik-public
deploy:
resources:
limits:
# 768M, MEASURED 2026-09-23 night: 1.27.1 used 94.6 % of 512M (its own memory, anon) under ten
# minutes of light load — memory_tight; at 768M 60 %, 0 kills. The JVM grows into what it is given.
memory: 768M
# HC override: komga's actuator lives at /actuator/health (unauthenticated, 200), NOT under the
# auth-gated /api/v1 API prefix — the old /api/v1/actuator/health returns 401 so `curl -f` failed
# (exit 22) and the container reported "unhealthy" despite serving fine. The gotson/komga image
# ships curl (verified), so curl -f on the unauthenticated endpoint is the correct probe.
healthcheck:
test: ["CMD", "curl", "-f", "http://127.0.0.1:25600/actuator/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.komga.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.komga.entrypoints=websecure"
- "traefik.http.routers.komga.tls=true"
- "traefik.http.routers.komga.tls.certresolver=letsencrypt"
- "traefik.http.services.komga.loadbalancer.server.port=25600"
volumes:
komga_config:
networks:
traefik-public:
external: true