Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
16 KiB
Onboarding record — grimmory
app: grimmory opened: 2026-10-02 template_at: uncommitted working tree 2026-10-02 (grimmory v3.5.0 + mariadb:11.4, family_gate)
0.1 | done | felhom.eu/documentation/audits/licences-2026-10-02/read-2.md — AGPL-3.0 at v3.5.0 (MariaDB GPL-2.0); upstream's own images, pulled, never redistributed
0.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/A/A1-github-facts.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/registry.txt — 24 releases in 2026, v3.5.0 on 2026-09-21, pushed 2026-10-01, nightlies daily to 2026-10-02
0.3 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/registry.txt — version tags vX.Y.Z on ghcr.io; v3.5.0 amd64 + arm64; mariadb:11.4 amd64 + arm64
0.4 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/checks.txt — no telemetry; a version check asks api.github.com for releases; metadata lookups send titles/ISBNs to the providers the household picks (the first_steps say so); no connection held at rest
0.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/FIT.md ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt — the library works offline; metadata lookups and Kobo sync need the internet (Kobo's first initialization asks Kobo's store, then falls back — 200 measured)
0.6 | n/a | Grimmory serves HTTP on port 6060 only; the database stays internal
0.7 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt — every e-reader route through traefik, LAN and the simulated tunnel, no family cookie: OPDS with the OPDS user 200 / wrong 401 / none 401; Kobo with the device token 200 / made-up 401; KOReader with its own user + md5 key 200 / wrong 401; Komga API none 401
0.8 | done | app-catalog-felhom.eu/templates/grimmory/.felhom.yml — tagline + use_cases (hu, en)
0.9 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S2-grimmory-bench-probe.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt — no public-URL setting is read; it starts, sets up and serves on the bench under no public name
1.1 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/catalog-gates-grimmory.txt — image-pins and image-resolvable
1.2 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt — upstream's compose runs MariaDB 11.4 (linuxserver 11.4.8); the template runs the official mariadb:11.4, same major
1.3 | done | app-catalog-felhom.eu/templates/grimmory/docker-compose.yml — MARIADB_AUTO_UPGRADE=1 on grimmory-db
1.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/grimmory/evidence/MV-grimmory/verdict.json ; felhom.eu/documentation/audits/new-apps-2026-10-01/bench/grimmory/evidence/MV-grimmory/migration-lines.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/step.txt — Flyway migrates at every start (146 migrations validated); v3.4.1 seeded, stepped INTO v3.5.0 on both venues, read back
1.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/checks.txt — java -jar /app/app.jar (Spring Boot, Tomcat); mariadbd
1.6 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt — every env placeholder listed: DATABASE_PASSWORD generated (upstream's fallback would be the DB root password); the token key is generated by the app (1.9); OIDC forced off, remote-auth headers off by default, API docs off by default
1.7 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt — the entrypoint makes the user (USER_ID/GROUP_ID 1000), chowns /app/data /books /bookdrop, drops to it with su-exec; JVM flags fixed in JAVA_TOOL_OPTIONS; migrations by Flyway inside the app; no switch left to decide
1.8 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/checks.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt — an unknown page answers the app's page (200), no stack trace; log level INFO; API docs off
1.9 | n/a | the token-signing key is generated by Grimmory inside its own database and travels with the database backup; no template secret encrypts data
2.1 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/catalog-gates-grimmory.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/volume-persistence-after-R801.txt — volume-persistence CLEAN, also after the R-801 port fix (the gate now sends its requests)
2.2 | done | app-catalog-felhom.eu/templates/grimmory/docker-compose.yml — the database in a named volume (NVMe); covers/app files in ${HDD_PATH}/appdata/grimmory/data; the books in ${USERDATA_PATH}/media/grimmory (the household browses them); the import inbox in ${IMPORT_PATH}/grimmory
2.3 | done | app-catalog-felhom.eu/templates/grimmory/.felhom.yml — books mandatory (the DB points at them), appdata mandatory, the import inbox excluded; tier 1 holds the database volume
2.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S2-grimmory-bench-probe.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-seed.txt — the folders are 1000:1000 from the first start; the uploaded book is written on the household's drive
2.5 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/life.txt — the night chain's backup, remove keeping backups, the household's restore button, the book read back with the household's own login; the family-gate file and the stranger's refusal come back after the restore
2.6 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/life.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/final.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B4/grimmory-demo.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B4/teardown.txt — "remove, keep data" (9202): the app, its volume and gate file go, the drive data stays and the restore uses it; "remove with data" on 9202 is refused (R-442, no host agent — fail-closed); on demo-hp (live catalog) it removed the app, its volume, its appdata and its backups, and KEPT the book EPUB in the household's userdata folder — the box treats userdata as the household's files and the dialog does not say so (R-800)
2.7 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-seed.txt — 169 MB database (mostly the empty schema) + 76 KB on the drive after one book; the books dominate a real household's size
2.8 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-seed.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/shots/grimmory/1.png — the EPUB uploaded through traefik behind the family gate, listed back by the app's own API and shown in its web page
3.1 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/A/setup.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/install.txt — class 4: the household makes the first admin with POST /api/v1/setup through the setup gate (200)
3.2 | n/a | no default login exists; the first visitor creates the admin (class 4, gated)
3.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/install.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/checks.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/setup.txt — the probe reads false before the first admin and true after; the setup gate opened by its probe (~10 s), the family gate stays
3.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/checks.txt — no sign-up route; a stranger's second setup 403; the books API with no token 401
3.5 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/install.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt — before the gate: a stranger's polls of the setup status from the press got 404/401 until the household's admin existed; behind the family gate a stranger gets the gate's answer on all 18 paths × 2 routes
3.6 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/throttle.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt — Grimmory locks a NAME and an ADDRESS for 15 min after 5 wrong tries (hard-coded); behind the family gate a stranger cannot reach the sign-in at all (6 tries: the gate's 401, then the household signs in 200) — only a family member could still lock a name (R-775)
3.7 | done | app-catalog-felhom.eu/templates/grimmory/.felhom.yml ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/setup.txt — add_people: first the Család card (measured: add, password once), then the account in Grimmory's Users page
3.8 | n/a | no after_install or after_setup command in the template
3.9 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-seed.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt — the web client's sign-in (/api/v1/auth/login) through traefik over https behind the family gate: right 200, wrong 401; every e-reader route as 0.7
3.10 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt ; felhom.eu/documentation/audits/visitors-2026-10-01/A/sweep/sweep-4.md ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt — Tomcat's native forwarded headers read the address from the RIGHT, skipping internal proxies; used for the per-address sign-in lock; the gate's own lock is per visitor and per name (a stranger's guesses never locked a member)
4.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/S/S1-grimmory-reads.txt ; app-catalog-felhom.eu/templates/grimmory/docker-compose.yml — wget is in the image (curl is not); mariadb's own healthcheck.sh; both dial 127.0.0.1
4.2 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/catalog-gates-grimmory.txt — probe-matches-compose
4.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/install.txt ; felhom.eu/documentation/audits/new-apps-2026-10-01/S/S2-grimmory-bench-probe.txt — box: all healthy 99 s after the press (start_period 120 s), 0 restarts; bench: 76 s
4.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/checks.txt — grimmory stopped: the state read degraded within 10 s, the front door 404; running again 45 s after start
4.5 | done | app-catalog-felhom.eu/templates/grimmory/docker-compose.yml — container_name grimmory = the stack; sidecar grimmory-db
5.1 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/grimmory/mem-grimmory.csv — bench swap 0 (the swap column reads 0), from birth: grimmory 521.6 MiB anon = 50.9 % of 1024M, grimmory-db 108.7 MiB = 28.3 % of 384M; 0 kills
5.2 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/grimmory/evidence/MV-grimmory/verdict.json ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-mem.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-mem-burst.csv — bench: 606 s soak, 11 880 requests all 200, grimmory 40.8 %, db 27.9 % (anon); box: the household's heaviest ordinary act, 40 EPUBs uploaded at once and read in by the library (41 listed in 8 s) — peak anon 464.6 MiB = 45.4 % of 1024M; 0 kills, 0 restarts
5.3 | done | app-catalog-felhom.eu/templates/grimmory/.felhom.yml — mem_limit 1408M = 1024M + 384M, the header says the same
5.4 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-mem.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt — the heap sizes itself from the limit (the image's MaxRAMPercentage=60, ExitOnOutOfMemoryError): the JVM's own MaxHeapSize read at three limits with v3.5.0 — 768m → 461 MiB, 1024m → 614 MiB, 1536m → 922 MiB; watched in use at 1024M on two venues (bench 50.9 %, box 49.3 %, burst 45.4 %)
5.5 | done | app-catalog-felhom.eu/templates/grimmory/.felhom.yml ; felhom.eu/documentation/audits/new-apps-2026-10-01/S/S1-grimmory-reads.txt — pi_compatible true (both images arm64); the pull is 481 MB + 327 MB
6.1 | done | app-catalog-felhom.eu/scripts/upgrade_fixtures_box.py — Grimmory: first admin, a library, a real EPUB through the app's own API; readback with no-token, wrong-password and second-setup controls
6.2 | done | app-catalog-felhom.eu/templates/grimmory/.felhom.yml ; felhom.eu/documentation/audits/new-apps-2026-10-01/box/grimmory/box-verdict-grimmory.json ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-step.txt — the ladder step v3.4.1 -> v3.5.0, proven on both venues, written by --write-ladder; walked again on 9202 behind the family gate today (58.5 s, the book read back, the gate and the OPDS exception unchanged)
6.3 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/undo/box/radicale/step.txt — the box's own undo, proven on a real failed step (Radicale, 2026-10-01); Grimmory's step ran the same guarded Update
6.4 | done | felhom.eu/documentation/audits/new-apps-2026-10-01/bench/grimmory/evidence/MV-grimmory/verdict.json — files_changed empty, no mark
6.5 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/registry.txt — vX.Y.Z since v2.2.4, plus floating vX.Y, latest and dated nightlies (never pinned)
7.1 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/grimmory-reads/upstream-v3.5.0.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/setup.txt — mail (send a book) is set in the app's own settings and stored in its database; no mail env; a fresh install boots without it
8.1 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/catalog-gates-grimmory.txt — copy-i18n
8.2 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/A/setup.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/B/box/grim-seed.txt — the first steps hold on 9202: the admin, the Család card, a library on /books (= userdata/media/grimmory on the drive), the upload, OPDS on with an OPDS user
8.3 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/assets.txt — logo (from the image) and screenshots answer 200 on felhom.eu
8.4 | done | app-catalog-felhom.eu/README.md ; app-catalog-felhom.eu/FIRST-ADMIN.md ; app-catalog-felhom.eu/templates/grimmory/.felhom.yml — README app table + FIRST-ADMIN row (class 4); category media; catalog_since 2026-10-02
8.5 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/assets.txt — the website's app count read against the templates
9.1 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/B/catalog-gates-grimmory.txt — catalog_gates.py grimmory exit 0
9.2 | done | felhom.eu/documentation/audits/family-gate-2026-10-02/A/setup.txt ; felhom.eu/documentation/audits/family-gate-2026-10-02/A/items.txt — a fresh install on 9202 from the drill catalog behind the family gate, as the household, as family members and as a stranger
9.3 | done | felhom.eu/documentation/backlog/OPEN-ITEMS.md — every finding is a register row (R-775 narrowed: only a family member can still lock a name)
9.4 | done | app-catalog-felhom.eu/onboarding/grimmory.md — published in one commit with this record (the onboarding gate)