Files
app-catalog-felhom.eu/onboarding/karakeep.md
T
admin 882ac14309
gates / gates (push) Successful in 2s
Karakeep: the second new app through the checklist — template, record, fixture, first ladder step 0.33.1 -> 0.33.2
Bookmarks/articles/notes with a crawler (karakeep-chrome) and search (meilisearch v1.41.0). AI off unless the household
enters a key; setup gate + sign-up closed twice; Chrome healthcheck over bash /dev/tcp; smtp_mapping (plaintext), mail-off
boot measured; web memory 768M -> 1536M on measurements (bench watch, box crawl burst). onboarding/karakeep.md complete.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 18:01:07 +02:00

11 KiB

Onboarding record — karakeep

app: karakeep opened: 2026-10-01 template_at: the commit that publishes this record (karakeep 0.33.2 + karakeep-chrome 151.0.7922.47-r1 + meilisearch v1.41.0; web 1536M)

0.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/A/A1-github-facts.txt — AGPL-3.0; upstream's own images, pulled 0.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/A/A1-github-facts.txt — 0.33.2 on 2026-08-11; 5 releases in 2026; pushed 2026-09-29 0.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/FIT.md — 0.33.1, 0.33.2, chrome 151.0.7922.47-r1, meilisearch v1.41.0; amd64 + arm64 0.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — AI tagging OFF (no OPENAI_API_KEY; the log says „No inference client configured"); release check off (DISABLE_NEW_RELEASE_CHECK); meilisearch analytics off; the crawler fetches each saved page and an ad-block list (the product); the deploy field says what turning AI on sends where; the official phone app has crash reporting built in (FIT.md, R-774 — not on the page yet) 0.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep-768M/neg-and-crawl.txt — crawling needs the internet (example.com crawled with a screenshot); a private address is refused by Karakeep itself (felhom.eu resolves to the LAN here) 0.6 | n/a | Karakeep serves HTTP on port 3000 only; Chrome and Meilisearch stay on the internal network 0.7 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — the phone app's sign-in route (apiKeys.exchange) through traefik after the setup gate opened: right 200 + a key that reads the API, wrong 401 0.8 | done | app-catalog-felhom.eu/templates/karakeep/.felhom.yml — tagline + use_cases 0.9 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/karakeep/evidence/MV-karakeep/verdict.json — runs on the bench; NEXTAUTH_URL builds links only 1.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/G/gates-karakeep.txt — image-pins and image-resolvable exit 0 1.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/A/compose/karakeep.yml — SQLite inside the app, meilisearch v1.41.0 exactly as upstream's compose 1.3 | n/a | no MariaDB or PostgreSQL service in this template 1.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/karakeep/evidence/MV-karakeep/verdict.json ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/step.txt — 0.33.1 seeded, stepped INTO 0.33.2; the image's s6 init-db-migration service ran; read back on both venues 1.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — s6 supervises Next.js' production server and the workers (the image's own init) 1.6 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S1-karakeep-reads.txt — NEXTAUTH_SECRET and MEILI_MASTER_KEY generated; OPENAI_API_KEY empty by default; the rest of the key-like settings belong to features off here (OAuth, Prometheus) 1.7 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S1-karakeep-reads.txt — the entrypoint is s6 (/init) with fixed services; migrations run as its own init-db-migration service at every start; no switch to decide 1.8 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — an unknown page redirects (308), no debug output 1.9 | n/a | NEXTAUTH_SECRET signs sessions only (sign in again), MEILI_MASTER_KEY guards a rebuildable index; neither encrypts stored data 2.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/G/cvp-karakeep-tail.txt — volume-persistence gate CLEAN 2.2 | done | app-catalog-felhom.eu/templates/karakeep/docker-compose.yml — two named volumes (NVMe): the data (SQLite + assets) and the search index 2.3 | n/a | needs_hdd false: no drive path to classify; the tier-1 unit holds both volumes 2.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — the app wrote its database and crawled assets on first start 2.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/restore.txt — the update's per-app backup, remove keeping backups, the household's restore button, the bookmark read back with the household's own email + password 2.6 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/restore.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep-768M/remove.txt — both remove choices delete both volumes; no drive data exists 2.7 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — 732 KB + 512 KB after the seed and one crawl; each saved page adds its screenshot and content (MBs over a year) 2.8 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep-768M/neg-and-crawl.txt — the crawled page's screenshot is stored as an asset and served back through the app (assets: 2); the UI shows it (shots/karakeep/1.png) 3.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/install.txt — class 4: the first account became admin through the gate as the household 3.2 | n/a | no known default login: the first account is the household's own 3.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — setup_gate, opened by the household's press; before it a stranger's GET and sign-up answered 401; no probe (Karakeep has no public "set up" status) 3.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — after the press: users.create, batched, upper-case, // and /signup all 403; the app's own switch DISABLE_SIGNUPS=true. After remove + restore the switch still refuses, the route block is gone (R-773) 3.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/poll.txt — 93 stranger polls from the press: 404 until routed, then the gate's 401; never the app 3.6 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — 12 wrong sign-ins for the household's email: 401 each, no lock; the right one at once 3.7 | done | app-catalog-felhom.eu/templates/karakeep/.felhom.yml — add_people: the admin creates the family member's account (sign-up is closed); password change is in Karakeep's own settings 3.8 | n/a | no after_install command: the household makes its own first account 3.9 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/shots/karakeep/1.png — the API route (phone app, browser extension) and the browser sign-in over https through traefik (headless Chrome signed in) 4.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S1-karakeep-reads.txt — web: the image's own wget check (127.0.0.1); chrome: bash + raw HTTP/1.1 to DevTools (no wget/curl in that image); meilisearch: curl/wget /health 4.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/G/gates-karakeep.txt — probe-matches-compose exit 0 4.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/install.txt — all three healthy 83 s after the press (pulls included), 0 restarts 4.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — the app container stopped: degraded within 10 s, front door 404; back in 15 s. (A paused container reads running — Docker's count; the probe that found no container recorded healthy, R-772) 4.5 | done | app-catalog-felhom.eu/templates/karakeep/docker-compose.yml — container_name: karakeep; sidecars karakeep-chrome, karakeep-meilisearch 5.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/karakeep/mem-karakeep.csv — bench, swap 0, from birth: web ~503 MiB, chrome 35, meili 31; 0 kills 5.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep-final/burst.txt — at 1536M, 10 real pages saved at once: web 832 MiB = 54 %, chrome 28 %, meili 17 %, 0 kills, 0 restarts (at 1024M a crawl reached 80.3 %: box/karakeep/remove.txt) 5.3 | done | app-catalog-felhom.eu/templates/karakeep/.felhom.yml — mem_limit 2816M = 1536 + 768 + 512 5.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/karakeep-768M/evidence/MV-karakeep/verdict.json ; felhom.eu/documentation/audits/new-apps-2026-10-01/bench/karakeep/evidence/MV-karakeep/verdict.json — two watches at two limits: 79 % of 768M, 51 % of 1024M — it does not simply fill the limit 5.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S1-karakeep-reads.txt — pi_compatible false (Chrome + Meilisearch); ~2 GB of images 6.1 | done | app-catalog-felhom.eu/scripts/upgrade_fixtures_box.py — Karakeep: the first account, the phone app's key exchange, a bookmark over the REST API, three negative controls 6.2 | done | app-catalog-felhom.eu/templates/karakeep/.felhom.yml — the first ladder step 0.33.1 -> 0.33.2, written by upgrade-test.py --write-ladder 6.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/undo/box/radicale/step.txt — the box's own undo, proven on a real failed step this session (Radicale); Karakeep's step ran the same guarded Update (backing-up, verifying, done) 6.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/karakeep/evidence/MV-karakeep/verdict.json — no mark 6.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/FIT.md — plain x.y.z app tags; chrome tags follow Chrome's version; release/latest are not used 7.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/karakeep-mail-off-boot.txt — smtp_mapping (plaintext :2526); a fresh install with mail OFF (empty SMTP_*) boots and signs up. Mail ON is not provable on 9202 (no hub) — R-774 8.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/G/gates-karakeep.txt — copy-i18n exit 0 (frozen with --add-app) 8.2 | done | app-catalog-felhom.eu/templates/karakeep/.felhom.yml — tagline, use_cases, first_steps, add_people, the AI sentence on the deploy field; the first steps followed on 9202 (account, „Kész" press, API key) 8.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S3-karakeep-assets.txt — logo + three screenshots answer 200; boxes get them with the next hub release (R-766) 8.4 | done | app-catalog-felhom.eu/README.md — both tables; FIRST-ADMIN rows; category productivity; catalog_since 8.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S3-karakeep-assets.txt — the website's count holds 9.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/G/gates-karakeep.txt — every gate exit 0, the runtime volume gate included 9.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/install.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/karakeep/checks.txt — fresh installs from the drill catalog, as household and stranger 9.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/README.md — every row done or n/a; findings are rows R-772, R-773, R-774 9.4 | done | app-catalog-felhom.eu/onboarding/karakeep.md — published in one commit with this record (the onboarding gate)