Files
app-catalog-felhom.eu/templates/radicale/docker-compose.yml
T
admin 195129cbb1
gates / gates (push) Successful in 2s
Radicale: the first new app through the checklist — template, record, fixture, first ladder step 3.8.0 -> 3.8.1
Calendar and contacts (CalDAV/CardDAV), ghcr.io/kozea/radicale:3.8.1. Login file written from the generated password on
the first start only (R-765: rewriting it at every start lost the household's login on a restore). onboarding/radicale.md
complete; bench + 9202 proven; FIRST-ADMIN, README, Hungarian freeze.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 16:58:56 +02:00

65 lines
3.1 KiB
YAML

# Radicale - Naptár és névjegyek (CalDAV / CardDAV szerver)
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based — every calendar and address book is a folder of .ics/.vcf files)
# RAM: ~40M (mem_limit: 128M) | Pi-compatible: Yes (amd64, arm64, arm/v7)
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# RADICALE_USER - A bejelentkezési név (az űrlapon megadható, alapból "csalad")
# RADICALE_PASSWORD - A jelszó (telepítéskor generálva, az alkalmazás oldalán látható)
#
# The upstream image (ghcr.io/kozea/radicale, the Radicale project's own) ships NO config, and Radicale 3's
# default `auth type` is `denyall` — nobody can log in. So the start command writes the login file from the
# box's generated password (bcrypt, 0600, on the data volume) ON THE FIRST START ONLY, then starts Radicale with
# htpasswd auth. There is never a moment without a login (no install window, checklist 3.5). The password is
# read from the environment, never pasted into program code (checklist 3.8).
# FIRST START ONLY, measured 2026-10-01 on 9202: the box never puts a `type: password` value into a backup (an
# internet-reachable login; controller `PortableSecretEnvVars`) and makes a NEW one on a restore after a remove,
# expecting the app's own login to come back WITH ITS DATA. The first version rewrote the file at every start —
# a remove + restore then replaced the household's login with a value no page shows, and every phone lost its
# calendar. Written once, the login file lives on the data volume and comes back with the calendars.
services:
radicale:
image: ghcr.io/kozea/radicale:3.8.1
container_name: radicale
restart: unless-stopped
environment:
- TZ=Europe/Budapest
- RADICALE_USER=${RADICALE_USER}
- RADICALE_PASSWORD=${RADICALE_PASSWORD}
entrypoint:
- /bin/sh
- -c
- |
[ -s /var/lib/radicale/users ] || /app/bin/python -c 'import os, bcrypt; f = "/var/lib/radicale/users"; u = os.environ["RADICALE_USER"]; p = os.environ["RADICALE_PASSWORD"].encode(); open(f, "w").write(u + ":" + bcrypt.hashpw(p, bcrypt.gensalt()).decode() + "\n"); os.chmod(f, 0o600)' || exit 1
exec /app/bin/python /app/bin/radicale --hosts 0.0.0.0:5232 --auth-type htpasswd --auth-htpasswd-filename /var/lib/radicale/users --auth-htpasswd-encryption bcrypt --storage-filesystem-folder /var/lib/radicale/collections
volumes:
- radicale_data:/var/lib/radicale
networks:
- traefik-public
deploy:
resources:
limits:
memory: 128M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:5232/.web/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
labels:
- "traefik.enable=true"
- "traefik.http.routers.radicale.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.radicale.entrypoints=websecure"
- "traefik.http.routers.radicale.tls=true"
- "traefik.http.routers.radicale.tls.certresolver=letsencrypt"
- "traefik.http.services.radicale.loadbalancer.server.port=5232"
volumes:
radicale_data:
networks:
traefik-public:
external: true