Files
felhom.eu/documentation/audits/day-2026-10-08/r762/9202

R-762 on scratch 9202 (2026-10-08, 09:50–10:09 CEST)

wger was installed fresh from the drill catalog (commit bebbac8: wger un-hidden plus the gunicorn definition, DRILL only; reverted as 95876a3). The install went through the product's deploy endpoint (tools/box9202.py install). tools/repoint.py moved 9202's catalog setting to the drill catalog and back.

check result
workers 2 × „Booting worker" (wger.log); env WGER_USE_GUNICORN=True, WEB_CONCURRENCY=2
login page 200
CSS (the page's 3 links, through wger-files) 200 / 200 / 200 (2481 B, 277042 B, 1006 B, text/css)
photo POST /api/v2/gallery/ 201; read back 200, 179 B, image/png
control an unknown /static/ file 404
seed a weight entry 201, read back 200
600 s watch (10,944 requests: 8,208 × 200, 2,736 × 302) anon peak 258,273,280 B = 246.3 MiB = 64.1 % of 384M (memory.stat anon, every 2 s); oom 0, oom_kill 0; restarts 0, oomkilled false, healthy (wger and wger-files)
after the watch (plateau-check.txt) anon 246 MiB for 1,200 more login-page loads; oom_kill 0; restarts 0

memory.peak reached the limit (402,657,280 B) because it counts the page cache (after-watch-memory.txt: file 22 MiB, kernel 49 MiB). The anon figure is what counts.

The bench figure was 170 MiB (44 %). The bench load was 302 redirects only. Here the load also rendered the login page and served a photo upload. The cause of the difference was not measured.

Removal through the product (run.txt): stop 200, remove (with data) 200, volumes wger_wger_data, wger_wger_media and wger_wger_static removed. Afterwards: no wger container, no wger volume, deployed=False. /opt/docker/stacks/wger holds only the catalog's synced .felhom.yml and docker-compose.yml. It held the same two files before the test, because every catalog app has this directory.

Put back: repo_url = https://gitea.dooplex.hu/admin/app-catalog-felhom.eu.git. controller.yaml sha256 7739ad7b… is the same before and after. The save copy was deleted. Deployed apps are paperless-ngx and privatebin, as before.

The generated admin password was never written. The image's default password in wger.log is redacted.