eec1228dc8
bookstack-db, kimai-db, nextcloud-db, romm-db each gain `MARIADB_AUTO_UPGRADE=1` in the db service's environment list. Operator ruling 2026-09-13 on the measurement in felhom.eu/documentation/audits/SPIKE-r459-mariadb-upgrade-2026-09-06.md: an unconverted datadir is stable but never heals; the conversion costs ~7 s and the engine backs its system tables up first. MARIADB_DISABLE_UPGRADE_BACKUP is deliberately left UNSET — that backup is the precaution. NO `image:` line changed, so `catalog_since` does NOT move — the CLAUDE.md rule ties it to an image change and this is not one. Do not "fix" that. The setting is inert until an engine major actually moves, and none may until Slice 4 (R-448) ships — see the engine-major rule in CLAUDE.md and scripts/check-engine-major.py (next commit). The eleven PostgreSQL templates are untouched: R-463 is a different engine and a different measurement. REUSE.md: one convention row for the MariaDB sidecar env, same commit. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
86 lines
2.5 KiB
YAML
86 lines
2.5 KiB
YAML
# Kimai - Időkövetés és projektmenedzsment
|
|
# Domain: ${SUBDOMAIN}.${DOMAIN}
|
|
# Database: mariadb
|
|
# RAM: ~100M (mem_limit: 384M) | Pi-compatible: Yes
|
|
#
|
|
# Environment variables:
|
|
# DOMAIN - Your domain (e.g., demo-felhom.eu)
|
|
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
|
|
# ADMIN_EMAIL - Admin email
|
|
# ADMIN_PASSWORD - Admin jelszó (auto-generated)
|
|
|
|
services:
|
|
kimai:
|
|
image: kimai/kimai2:apache-2.57.0
|
|
container_name: kimai
|
|
restart: unless-stopped
|
|
depends_on:
|
|
kimai-db:
|
|
condition: service_healthy
|
|
environment:
|
|
- TZ=Europe/Budapest
|
|
- DATABASE_URL=mysql://kimai:${DB_PASSWORD}@kimai-db:3306/kimai?charset=utf8mb4&serverVersion=11.6.2-MariaDB
|
|
- ADMINMAIL=${ADMIN_EMAIL:-admin@example.com}
|
|
- ADMINPASS=${ADMIN_PASSWORD}
|
|
volumes:
|
|
- kimai_var:/opt/kimai/var
|
|
networks:
|
|
- traefik-public
|
|
- kimai-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 384M
|
|
healthcheck:
|
|
test: ["CMD", "curl", "-f", "http://127.0.0.1:8001"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 30s
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.kimai.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
|
|
- "traefik.http.routers.kimai.entrypoints=websecure"
|
|
- "traefik.http.routers.kimai.tls=true"
|
|
- "traefik.http.routers.kimai.tls.certresolver=letsencrypt"
|
|
- "traefik.http.services.kimai.loadbalancer.server.port=8001"
|
|
|
|
kimai-db:
|
|
image: mariadb:11.6
|
|
container_name: kimai-db
|
|
restart: unless-stopped
|
|
environment:
|
|
- MYSQL_ROOT_PASSWORD=${DB_PASSWORD}
|
|
- MYSQL_DATABASE=kimai
|
|
- MYSQL_USER=kimai
|
|
- MYSQL_PASSWORD=${DB_PASSWORD}
|
|
- TZ=Europe/Budapest
|
|
# MARIADB_AUTO_UPGRADE: on a MAJOR engine move the engine converts its own datadir (~7 s on a
|
|
# small DB, backs its system tables up first). Operator ruling 2026-09-13 on
|
|
# felhom.eu/documentation/audits/SPIKE-r459-mariadb-upgrade-2026-09-06.md. Inert until a
|
|
# major moves — and none may, until Slice 4 (R-448) ships: see CLAUDE.md, engine-major rule.
|
|
- MARIADB_AUTO_UPGRADE=1
|
|
volumes:
|
|
- kimai_db_data:/var/lib/mysql
|
|
networks:
|
|
- kimai-internal
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
memory: 256M
|
|
healthcheck:
|
|
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
start_period: 20s
|
|
|
|
volumes:
|
|
kimai_db_data:
|
|
kimai_var:
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
kimai-internal:
|