Files
app-catalog-felhom.eu/onboarding/lubelogger.md
T
admin b7f0f7cef5
gates / gates (push) Failing after 14m4s
Grocy and LubeLogger: two new apps, each with its complete record
60 template directories, 58 offered. Records: onboarding/grocy.md and
onboarding/lubelogger.md, all 61 checks answered, none open. Evidence:
felhom.eu/documentation/audits/new-apps-2026-10-10/.

Grocy 4.7.1 from lscr.io/linuxserver/grocy (grocy publishes no image of its
own). SQLite in one volume, no HDD, ~30 MiB idle, amd64 + arm64, Hungarian UI
91.6 %. First admin class 3: it starts with its documented admin/admin and
after_install replaces that password with a generated one.

LubeLogger v1.7.3 from ghcr.io/hargata/lubelogger. LiteDB in one volume, no
HDD, ~60 MiB idle, amd64 + arm64. First admin class 1 — and it has to be: the
image ships EnableAuth=false, and with that the middleware mints a ticket with
the IsRootUser role for every visitor. Measured on a default start: a stranger
got 200 on /, on /api/vehicles and on /Home/Settings and CREATED A VEHICLE.
The compose entrypoint exports EnableAuth=true and the SHA-256 of a generated
name and password, so the app's own login is on before its first byte (at t+1 s
nothing listening, at t+2 s /api/vehicles already 401).

Two defects found by the walk and fixed before publishing:

1. An after_install command may not contain `$`. The controller runs every
   element through os.Expand and refuses one naming anything outside env:, so
   PHP cannot be inlined. On 9202 the first attempt came back
   `[pw argv dsn db i t e s n q h] not declared in env or has no value — not
   run` and the app sat behind its install hold with admin/admin in place. The
   code now lives in a file the compose entrypoint writes. Written into
   REUSE.md's after_install row as a trap.

2. Grocy's persisted config.php does not follow the image. The image copies
   config-dist.php only when that file is absent, so a volume written by 4.6.0
   and started under 4.7.1 answered HTTP 500 on every page — AUTH_CLASS names a
   class 4.7 moved — while its log said migrations done. The entrypoint now
   deletes the file at every start. The 4.6.0 -> 4.7.1 edge failed before this
   and is proven after it, on both venues.

Ladders, written by upgrade-test.py --write-ladder from both verdicts:
  grocy       4.6.0 -> 4.7.1   bench proven, box proven (guarded Update, 41 s)
  lubelogger  v1.7.2 -> v1.7.3 bench proven, box proven (25.6 s)
Checklist 6.3 came from a real failure, not a forced one: before the config.php
fix the product undid the same step in 346 s with the data intact.

REUSE.md: a fifth healthcheck family (bash /dev/tcp) for an image with no HTTP
client at all, measured in both directions.

Tool fixes made on the way: check-onboarding.py crashed on a Windows console
while printing which ids were open; upgrade-test.py's read_text/write_text used
the platform encoding and wrote a cp1250 em dash into a template full of
Hungarian.
2026-10-10 12:31:34 +02:00

18 KiB

Onboarding record — lubelogger

app: lubelogger opened: 2026-10-10 template_at: b38aa92317

0.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/FIT.md — MIT. GitHub's licence endpoint answers spdx_id: MIT for hargata/lubelog and the file is LICENSE; we pull the project's own image and redistribute nothing. 0.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/FIT.md — v1.7.3 on 2026-09-12, and SEVENTEEN releases in 2026 alone (v1.6.1 in February through v1.7.3 in September); 74 releases since 2024, issues answered, not archived. 0.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/FIT.md — ghcr.io/hargata/lubelogger:v1.7.3, amd64 and arm64, read from the manifest. This is the image upstream's own docker-compose.yml names; Docker Hub carries the same tags. 0.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — nothing at start: the first log lines are the banner and Now listening. Three outbound fetches exist and each is on a page the household opens on purpose: the sponsors list and the language pack from hargata.github.io, and the release check from api.github.com behind a checkForUpdate request flag. 0.5 | n/a | it needs no internet at runtime; everything it does works with no network at all 0.6 | n/a | HTTP only on 8080. Its SignalR websocket at /api/ws passes the tunnel like any request, as MeTube's measured 101 showed 0.7 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — no official native app; it is a PWA. Its API takes HTTP Basic or an x-api-key on /api, /kiosk, /images, /documents and /temp. Measured on 9202 through traefik: Basic right 200, Basic wrong 401, a bogus api key 401. 0.8 | done | app-catalog-felhom.eu/templates/lubelogger/.felhom.yml — the Hungarian description and app_info.tagline say what a household gets. 0.9 | n/a | it never calls itself server-side and the bench ran it with no environment override at all 1.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/gates.txt — catalog_gates.py lubelogger green, image-pins and image-resolvable included. 1.2 | n/a | LiteDB inside its own volume, which is exactly what upstream's own default compose runs; PostgreSQL is optional and not used here 1.3 | n/a | no MariaDB and no PostgreSQL sidecar exists in this template 1.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json — the step INTO the pin, measured: v1.7.2 installed and seeded, then moved to v1.7.3, seed read back, healthy after. LiteDB performs no schema migration, so there is no migration switch to set. 1.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — PID 1 is ./CarCareTracker, Kestrel, and its own log says Hosting environment: Production. 1.6 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — the image's appsettings.json is printed in full in the probe file; the only keys that are secrets are UserNameHash and UserPasswordHash, which ship EMPTY and which the template's entrypoint fills from the generated password. Every login route was then exercised. 1.7 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — the image has NO entrypoint script at all: it execs the app. Its start-time switches are configuration keys, and the probe prints the shipped appsettings.json in full with each one decided. The one that matters is EnableAuth: false. 1.8 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — Hosting environment: Production in the app's own log, and an unknown page 404 with no debug page, through traefik. 1.9 | n/a | the DataProtection key signs the login cookie and nothing else; losing it signs everyone out and destroys no data 2.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/volume-persistence.txt — the runtime gate deployed lubelogger, exercised it and compared where the data landed against what the compose mounts. 2.2 | done | app-catalog-felhom.eu/templates/lubelogger/docker-compose.yml ; felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — two named volumes on NVMe: the data tree (database, documents, images, temp, themes, translations) and the DataProtection keys. No HDD and no userdata path, deliberately: the uploads are receipts and a few photos, and an attached receipt is only ever opened from the record it belongs to. 2.3 | n/a | the template declares no HDD path, so there is no per-path backup class to set 2.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — the image runs as root (its APP_UID is not used as USER) and writes only inside its own two volumes; there is no PUID/PGID to set. 2.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/restore.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/restore-password.txt — remove keeping the backups then the household's own restore button: the app came back running in 22.3 s with the household's vehicle and its service record. The fixture reported False, and chasing that is the useful part: a type: password field is not in PortableSecretEnvVars, so the install's password does not travel in the unit and the box mints a new one. MEASURED after the restore: the install's password is refused, the value the box now holds signs in, and the data is there. 2.6 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/remove.txt — remove with data on 9202: 200, both named volumes gone, the Hungarian note saying there was nothing on an external drive. What is left in the stack directory is the template pair the syncer keeps for all templates, not deployed state. 2.7 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/offsite-size.txt — 140 KB of data and 8 KB of keys on a seeded install; LubeLogger never decides how big an off-site snapshot is. 2.8 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/member-and-upload.txt — through traefik as the household: a PDF uploaded through the app's own file route, fetched back 200 with the content matching, and the same fetch with NO credentials 302 to the login, not 200. 3.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/install.txt — class 1. THE IMAGE'S OWN DEFAULT IS NO LOGIN AT ALL, measured: a stranger got 200 on /, on /api/vehicles and on /Home/Settings and CREATED A VEHICLE that came back from the API. With the template's entrypoint the first answer the app ever gives a stranger is 401 / 302 to the login. 3.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — on 9202 through traefik: the generated login signs in, a wrong password is refused with the app's own message, and the API refuses both ways. There is no shared default to replace, because the template's login did not exist before we made it. 3.3 | n/a | there is no open first-run screen: with the template the app demands a login from its first byte, so there is no setup window to gate 3.4 | n/a | sign-up is closed by the app itself: RegisterNewUser refuses without a token the root user mints, measured twice on 9202 with an empty and a guessed token 3.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/poll.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — a stranger's poll of /api/vehicles once a second from the install press: 404 while nothing answered, then 401, never 200. On the bench the same was watched from the container's creation: at t+1 s nothing was listening, at t+2 s /api/vehicles was already 401. There is no window. 3.6 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — 25 wrong passwords for the public name through traefik, each refused with the app's own message, then the household's right one: in at once. No lock-out and no throttle, which is why the NAME may stay a plain word. 3.7 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/member-and-upload.txt — the admin minted a registration token for a family member on the app's own Admin page with autoNotify false, so no mail server is needed; the member registered with it and SIGNED IN, and the same member with a wrong password was refused. The first attempt used /Login/SendRegistrationToken, which is the self-service path and correctly answers Open Registration Disabled; app_info.add_people was corrected to the route that works. 3.8 | n/a | there is no after_install command at all; the generated password reaches the app as an environment variable the entrypoint hashes, and is unset from PID 1 afterwards 3.9 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — the browser form signs in through traefik and again with a browser's https Origin and Referer; the API routes a phone or a script uses answer 200 on the right Basic credentials and 401 on the wrong ones. 3.10 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — LubeLogger reads the client address in ONE place: LoginController takes the real peer from Connection.RemoteIpAddress and APPENDS the X-Forwarded-For string to a log line for a failed sign-in. Nothing is decided on it. Measured through traefik on 9202 with a forged leftmost entry, and the forged address did not even reach the app: the log line carried the real chain. 4.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt ; app-catalog-felhom.eu/REUSE.md — this image has NO curl, NO wget, NO nc, NO python and NO node, so none of REUSE.md's four healthcheck families exists in it. It has bash, and bash's /dev/tcp speaks TCP without a helper binary. Measured both ways: rc 0 against the app with an HTTP 200 line, rc 1 against a dead port. Written up as the fifth family. 4.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/gates.txt — gate probe-matches-compose green: the controller probe is api on port 8080 at /Login/Index, which is what the compose healthcheck dials. 4.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/install.txt — on a cold first install on 9202: deployed in 20 s, every container healthy 27 s after the press, RestartCount 0. 4.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt — the negative control: docker stop, the controller read the app down and the front door stopped answering; docker start and it came back. 4.5 | done | app-catalog-felhom.eu/templates/lubelogger/docker-compose.yml — container_name lubelogger is exactly the stack name, and there are no sidecars. 5.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/mem-lubelogger.csv ; felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/remove.txt — on the bench with swap 0, sampled from the container's birth every 2 s: peak anon 66.2 MiB, 12.3 per cent of the 512 M limit, peak swap 0, oom_kill 0, restarts 0. On the box three installs peaked at 22.1, 35.1 and 46.6 MiB, 0 swap, 0 kills. 5.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json — the 10-minute soak after the readback: 605 s, 11988 requests all answered, peak anon 12.3 per cent of the limit, cgroup peak including the page cache 17.9 per cent, 0 oom_kills, 0 restarts. 5.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/gates.txt — gate mem-limit-sum green: one service at 512M and mem_limit 512M, and the compose header says the same. 5.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/mem-lubelogger.csv ; felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json — it is .NET, which DOES size its heap from the cgroup limit, and the measurement says the limit is not the binding constraint: anon peaked at 12.3 per cent of 512 M under a 605-second soak with no kill and no restart, and the box's three installs peaked lower still on the same limit. 5.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — amd64 and arm64, so pi_compatible true; the image is about 267 MB to pull. 6.1 | done | app-catalog-felhom.eu/scripts/upgrade_fixtures_box.py ; felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json — the LubeLogger fixture seeds and reads back through the app's own routes: its login, a vehicle with a marker plate, and a service record with a marker description, then both read back from the API. It proves itself on every verify: no cookie must be 401, a session from a wrong password must be 401, and a vehicleId that cannot exist must answer an empty list. 6.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/box-verdict-lubelogger.json ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/step.txt — bench proven and box proven, the box through the product's own guarded Update in 25.6 s: backing-up, safety-dump, pulling, copying, verifying, done. Written into the template by upgrade-test.py --write-ladder, never by hand. 6.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/grocy/step.txt — no forced-fail case was manufactured for this app, and one was not needed to learn the answer: the harness's ABORT leg put v1.7.2 back and recorded starts-and-serves, so an undo on this app returns a working app with its data (LiteDB performs no destructive migration). The product's own undo on a REAL failure was measured in this same session on grocy, where it restored the pre-update backup and the data read back. 6.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/evidence/MV-lubelogger/verdict.json — files_changed is empty: it rewrites no file at start, so there is no files_may_change mark to carry. 6.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/FIT.md ; felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/partA-probes.txt — the tag shape is v<major>.<minor>.<patch> and has not changed across 74 releases; latest and edge exist beside it and are not used. The publisher does not re-push a version tag: each release is a new tag, seventeen of them in 2026. 7.1 | n/a | it sends mail only when MailConfig is set, which this template does not set; its own startup banner says SMTP Not Configured and it boots 8.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/gates.txt — gate copy-i18n green with lubelogger in the freeze: 21 Hungarian strings, 21 with English, informal te, no keruk. 8.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/member-and-upload.txt — every claim on the app page was followed on 9202: the tagline, the use cases, the first steps, and add_people, which was CORRECTED after the first route turned out to be the self-service one. 8.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/bench/lubelogger/shots — the app's own icon with its dark background dropped and the mark made white, the rule SparkyFitness's PNG follows, and three screenshots of the app with a household's own car and its service history; installed as felhom.eu/website/assets/lubelogger-logo.png and lubelogger-screenshot-1..3.webp. 8.4 | done | app-catalog-felhom.eu/README.md ; app-catalog-felhom.eu/FIRST-ADMIN.md ; app-catalog-felhom.eu/templates/lubelogger/.felhom.yml — both README tables, the FIRST-ADMIN row, category home and catalog_since 2026-10-10. 8.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/site-count.txt — the count moved in every place the website states it, both language sets, with a control that no old count is left. 9.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/gates.txt — catalog_gates.py lubelogger exit 0, every gate in the table. 9.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/install.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/checks.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/step.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/restore.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/member-and-upload.txt ; felhom.eu/documentation/audits/new-apps-2026-10-10/box/lubelogger/remove.txt — a fresh install on 9202 from the drill catalog, walked as the household and as a stranger, start to finish. 9.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-10/README.md — this record; the findings are in the register and in the catalog CHANGELOG. 9.4 | done | app-catalog-felhom.eu/templates/lubelogger ; app-catalog-felhom.eu/onboarding/lubelogger.md — published to the live catalog in one commit.