2d69c61556
gates / gates (push) Successful in 27s
The operator's request of 2026-10-01 recorded in CONTEXT with the reviewer's defaults (new apps only; the 53 get a read-only gap page). The pilot: the draft caught R-752 and R-755, missed R-737 and (for a new app) R-738; the sharpened and new rows then found R-762 (wger serves no static files or photos), R-763 (strangers sign up, guest accounts), R-764 (no mail). Also R-758 (8 mem_limit under the sum), R-759 (wger's open record rows), R-760 (vikunja healthcheck), R-761 (logo comment). R-755 note. Register 392 -> 399. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
90 lines
9.4 KiB
Plaintext
90 lines
9.4 KiB
Plaintext
##### wger on 9202 — controller gitea.dooplex.hu/admin/felhom-controller:0.285.0
|
||
catalog clone: e9f50b5 calibre-web: the admin login name is generated at install (09 decision 61, R-752)
|
||
before: stack/volumes named wger: /opt/docker/stacks/wger
|
||
guest swap (free -m): Swap: 512 19 492
|
||
sampler started
|
||
poller started
|
||
deploy press at 15:06:36
|
||
15:06:36 [1] required fields filled beyond DOMAIN/SUBDOMAIN: ['ADMIN_PASSWORD']
|
||
15:06:37 [1] deploy -> 202 {'ok': True, 'message': 'Telepítés elindítva – az állapot a kártyán követhető'}
|
||
15:08:12 [1] deployed, controller state=running, pinned={'wger': 'wger/server:2.7'}
|
||
deploy -> True
|
||
controller log (after_install / hold): 2026/10/01 13:08:09 install_hold.go:135: [INFO] [stacks] wger: install hold OPENED by after_install — the app is reached as without a hold
|
||
4.3 press -> docker healthy: 107 s; RestartCount: 0; start_period in compose: start_period: 30s
|
||
controller state: running
|
||
3.5 stranger polls of admin/adminadmin from the press: 92 tries; codes {'404': 90, '401': 1, '400': 1}
|
||
first 3: ['13:06:35 404 404 page not found ', '13:06:36 404 404 page not found ', '13:06:37 404 404 page not found ']
|
||
last 3: ['13:08:07 404 404 page not found ', '13:08:08 401 {"error":"this app is waiting for its first setup"}', '13:08:10 400 {"status": 400, "errors": [{"message": "The username and/or password you specified are not']
|
||
any 200 with a token: False
|
||
1.5 the server process: python3 manage.py runserver 0.0.0.0:8000 | /usr/bin/python3 manage.py runserver 0.0.0.0:8000
|
||
1.7 image entrypoint:
|
||
1.7 entrypoint switches (if-tests in /home/wger/entrypoint.sh):
|
||
10:if [ "$YARN_PROCESS_STATIC" == "True" ];
|
||
21:if [ "$DJANGO_CLEAR_STATIC_FIRST" == "False" ]; then
|
||
27:if [[ "$DJANGO_DEBUG" == "False" && "${DJANGO_COLLECTSTATIC_ON_STARTUP:-True}" == "True" ]];
|
||
34:if [[ "$DJANGO_PERFORM_MIGRATIONS" == "True" ]];
|
||
41:if [[ "$SYNC_EXERCISES_ON_STARTUP" == "True" ]];
|
||
48:if [[ "$DOWNLOAD_EXERCISE_IMAGES_ON_STARTUP" == "True" ]];
|
||
55:if [[ "$DOWNLOAD_EXERCISE_VIDEOS_ON_STARTUP" == "True" ]];
|
||
62:if [[ "$LOAD_ONLINE_FIXTURES_ON_STARTUP" == "True" ]];
|
||
69:if [[ "$SYNC_INGREDIENTS_ON_STARTUP" == "True" ]];
|
||
81:if [[ "$WGER_USE_GUNICORN" == "True" ]];
|
||
0.4/1.7 the IMAGE's env defaults for those switches (+ debug/mail/sync):
|
||
the RUNNING container's env, the same switches (values: only these named, non-secret ones):
|
||
container: SITE_URL=https://fitness.enkisfelhom.hu
|
||
container: AXES_COOLOFF_TIME=5
|
||
container: DJANGO_PERFORM_MIGRATIONS=True
|
||
container: AXES_HANDLER=axes.handlers.database.AxesDatabaseHandler
|
||
container: AXES_LOCKOUT_PARAMETERS=username
|
||
container: X_FORWARDED_PROTO_HEADER_SET=True
|
||
container: TZ=Europe/Budapest
|
||
container: CSRF_TRUSTED_ORIGINS=https://fitness.enkisfelhom.hu
|
||
container env NAMES (all): APP_BUILD_COMMIT APP_BUILD_DATE AXES_COOLOFF_TIME AXES_HANDLER AXES_LOCKOUT_PARAMETERS CSRF_TRUSTED_ORIGINS DEBIAN_FRONTEND DJANGO_DB_DATABASE DJANGO_DB_ENGINE DJANGO_DB_HOST DJANGO_DB_PASSWORD DJANGO_DB_PORT DJANGO_DB_USER DJANGO_PERFORM_MIGRATIONS DJANGO_SETTINGS_MODULE LANG LANGUAGE LC_ALL PATH PYTHONDONTWRITEBYTECODE PYTHONPATH PYTHONUNBUFFERED SECRET_KEY SITE_URL TZ X_FORWARDED_PROTO_HEADER_SET
|
||
1.6 the env names wger's settings READ (settings/main.py, env.*('NAME'...)):
|
||
ACCESS_TOKEN_LIFETIME ALLOW_GUEST_USERS ALLOW_REGISTRATION ALLOW_UPLOAD_VIDEOS AUTH_PROXY_CREATE_UNKNOWN_USER AUTH_PROXY_HEADER AUTH_PROXY_TRUSTED_IPS AUTH_PROXY_USER_EMAIL_HEADER AUTH_PROXY_USER_NAME_HEADER AWS_ACCESS_KEY_ID AWS_S3_DOMAIN AWS_S3_REGION_NAME AWS_SECRET_ACCESS_KEY AWS_STORAGE_BUCKET_NAME AXES_COOLOFF_TIME AXES_ENABLED AXES_FAILURE_LIMIT AXES_HANDLER AXES_IPWARE_PROXY_COUNT AXES_LOCKOUT_PARAMETERS CACHE_API_EXERCISES_CELERY CELERY_BACKEND CELERY_BROKER DJANGO_ADMINS DJANGO_CACHE_BACKEND DJANGO_CACHE_CLIENT_CLASS DJANGO_CACHE_CLIENT_PASSWORD DJANGO_CACHE_CLIENT_SSL_CERTFILE DJANGO_CACHE_CLIENT_SSL_CERT_REQS DJANGO_CACHE_CLIENT_SSL_KEYFILE DJANGO_CACHE_LOCATION DJANGO_CACHE_TIMEOUT DJANGO_DB_DATABASE DJANGO_DB_ENGINE DJANGO_DB_HOST DJANGO_DB_PASSWORD DJANGO_DB_PORT DJANGO_DB_USER DJANGO_MEDIA_ROOT DJANGO_STATIC_ROOT DOWNLOAD_INGREDIENTS_FROM EMAIL_HOST EMAIL_HOST_PASSWORD EMAIL_HOST_USER EMAIL_PORT EMAIL_USE_SSL EMAIL_USE_TLS ENABLE_EMAIL EXERCISE_CACHE_TTL EXPORT_INGREDIENTS_BULK_CELERY EXPOSE_PROMETHEUS_METRICS FROM_EMAIL IDP_OIDC_PRIVATE_KEY JWT_PRIVATE_KEY JWT_PUBLIC_KEY LOGIN_REDIRECT_URL LOG_LEVEL_PYTHON MEDIA_URL MIN_ACCOUNT_AGE_TO_TRUST NUMBER_OF_PROXIES POWERSYNC_TOKEN_LIFETIME POWERSYNC_URL POWERSYNC_URL_PATH RECAPTCHA_PRIVATE_KEY RECAPTCHA_PUBLIC_KEY RECAPTCHA_REQUIRED_SCORE REFRESH_TOKEN_LIFETIME S3_MEDIA_FILES_LOCATION S3_STATIC_FILES_LOCATION SECRET_KEY SECURE_PROXY_SSL_HEADER SITE_URL STATIC_URL SYNC_EXERCISE_IMAGES_CELERY SYNC_EXERCISES_CELERY SYNC_EXERCISE_VIDEOS_CELERY SYNC_INGREDIENTS_CELERY SYNC_OFF_DAILY_DELTA_CELERY TIME_ZONE USE_CELERY USE_RECAPTCHA USE_S3_MEDIA_FILES USE_S3_STATIC_FILES USE_S3_URL_FOR_MEDIA USE_S3_URL_FOR_STATIC USE_X_FORWARDED_HOST WGER_MAX_SESSION_LENGTH_HOURS WGER_SHOW_APP_STORE_LINKS WGER_SOCIAL_PROVIDERS X_FORWARDED_PROTO_HEADER_SET
|
||
of which key/secret-like: ['ACCESS_TOKEN_LIFETIME', 'AWS_ACCESS_KEY_ID', 'AWS_SECRET_ACCESS_KEY', 'DJANGO_CACHE_CLIENT_PASSWORD', 'DJANGO_CACHE_CLIENT_SSL_KEYFILE', 'DJANGO_DB_PASSWORD', 'EMAIL_HOST_PASSWORD', 'IDP_OIDC_PRIVATE_KEY', 'JWT_PRIVATE_KEY', 'JWT_PUBLIC_KEY', 'POWERSYNC_TOKEN_LIFETIME', 'RECAPTCHA_PRIVATE_KEY', 'RECAPTCHA_PUBLIC_KEY', 'REFRESH_TOKEN_LIFETIME', 'SECRET_KEY']
|
||
set in the container: ['DJANGO_DB_PASSWORD', 'SECRET_KEY'] NOT set: ['ACCESS_TOKEN_LIFETIME', 'AWS_ACCESS_KEY_ID', 'AWS_SECRET_ACCESS_KEY', 'DJANGO_CACHE_CLIENT_PASSWORD', 'DJANGO_CACHE_CLIENT_SSL_KEYFILE', 'EMAIL_HOST_PASSWORD', 'IDP_OIDC_PRIVATE_KEY', 'JWT_PRIVATE_KEY', 'JWT_PUBLIC_KEY', 'POWERSYNC_TOKEN_LIFETIME', 'RECAPTCHA_PRIVATE_KEY', 'RECAPTCHA_PUBLIC_KEY', 'REFRESH_TOKEN_LIFETIME']
|
||
1.8/0.4 Django settings inside the app:
|
||
DEBUG False
|
||
EMAIL_BACKEND django.core.mail.backends.console.EmailBackend
|
||
WGER_SETTINGS sync/download: {'ALLOW_GUEST_USERS': True, 'ALLOW_REGISTRATION': True, 'ALLOW_UPLOAD_VIDEOS': True, 'EMAIL_FROM': 'wger Workout Manager <wger@example.com>', 'DOWNLOAD_INGREDIENTS_FROM': 'WGER', 'SYNC_EXERCISES_CELERY': False, 'SYNC_EXERCISE_IMAGES_CELERY': False, 'SYNC_EXERCISE_VIDEOS_CELERY': False, 'SYNC_INGREDIENTS_CELERY': False, 'SYNC_OFF_DAILY_DELTA_CELERY': False, 'SYNC_INGREDIENTS_DUMP_URL': 'https://wger.de/media/ingredients/ingredients.jsonl.gz', 'TWITTER': False, 'MASTODON': 'https://fosstodon.org/@wger', 'USE_CELERY': False}
|
||
JWT key loaded: False (env in this shell is not the server env)
|
||
0.4/0.5 the container's first-start log lines about the network (sync/download/http):
|
||
Apply all migrations: account, actstream, allauth_idp_oidc, auth, authtoken, axes, config, contenttypes, core, easy_thumbnails, exercises, gallery, gym, mailer, manager, measurements, mfa, nutrition, sessions, sites, socialaccount, token_blacklist, trophies, weight
|
||
Applying nutrition.0012_alter_ingredient_license_author... OK
|
||
Applying exercises.0001_initial... OK
|
||
Applying nutrition.0013_ingredient_image... OK
|
||
Applying nutrition.0015_alter_ingredient_creation_date_and_more... OK
|
||
Applying nutrition.0024_remove_ingredient_status... OK
|
||
Applying nutrition.0028_ingredient_dietary_properties... OK
|
||
Applying nutrition.0029_ingredient_nutriscore... OK
|
||
Applying manager.0011_remove_set_exercises... OK
|
||
Applying exercises.0002_auto_20150307_1841... OK
|
||
Applying exercises.0003_auto_20160921_2000... OK
|
||
Applying exercises.0004_auto_20170404_0114... OK
|
||
outbound TCP connections the wger process holds right now: 1 020012AC:CDBA
|
||
1 060012AC:CC06
|
||
3.9 browser form, https Origin + CSRF, RIGHT password: ok
|
||
3.9 browser form, WRONG password: POST /en/user/login -> 200 (refused)
|
||
3.9/0.7 phone-app route /allauth/app/v1/auth/login, RIGHT password: http=200 keys=['access_token', 'is_authenticated', 'refresh_token', 'session_token']
|
||
the API with that token: http=200
|
||
3.9/0.7 phone-app route /allauth/app/v1/auth/login, WRONG password: http=400 keys=['errors', 'status']
|
||
1.8 unknown page through traefik: http=404 debug-page=False traceback=False
|
||
wger: POST /api/v2/weightentry/ http=201
|
||
seed: {'weight': '84.42'}
|
||
2.8 POST /api/v2/gallery/ (multipart, through traefik): http=201 {"id":1,"date":"2026-10-01","image":"…","description":"felhom pilot","heig
|
||
2.8 GET the uploaded image back through traefik (/media/gallery/1/def0a0d8-3cc7-4384-96df-ddfcdfaefb8d.png): http=404 bytes=2830 same=False
|
||
2.8 the same image with NO session: http=404
|
||
wger: readback of the seeded weight entry http=200 found=True
|
||
verify (fixture readback, with its negative controls): True
|
||
2.7 the volumes' size after the seed: wger_wger_data=4.2M wger_wger_media=16K
|
||
4.4 negative control: docker pause wger at 15:09:17 — controller state before: running
|
||
states seen while paused (s, (state, health)): [(4, ('stopped', None))]
|
||
after unpause, state running again after 40 s
|
||
5.1 wger cgroup from birth: 90 samples over 183 s; limit 402653184
|
||
peak anon 266.8 MiB (69.5 % of the limit); peak swap 0 bytes; oom_kill max 0; last: 0 running healthy
|
||
2.6 stop -> 200
|
||
2.6 remove, KEEP drive data (wger has no drive data) -> 200 {'ok': True, 'data': {'removed': 'wger', 'volumes_removed': ['wger_wger_data', 'wger_wger_media'], 'hdd_paths_removed': [], 'hdd_paths_preserved': [], 'backup_paths_removed': ['/mnt/sys_drive/felhom-d
|
||
left after: stack dir / containers / volumes: /opt/docker/stacks/wger
|
||
the image (kept per decision 53 until the sweep):
|