Files
felhom.eu/documentation/audits/r459-spike-2026-09-06/ev/arm2/scratch-compose.yml
T
admin d6837d98ee
gates / gates (push) Successful in 20s
SPIKE R-459: the skipped MariaDB conversion is stable, and the trade it implied does not exist
Outcome A, qualified. Not B and not C.

It does not degrade: 5 of 5 restarts of 12.3 on an 11.6 datadir, readback passed
every time, mariadb_upgrade_info unchanged, the entrypoint line never escalated
past [Note]. It also never heals - the engine answers 'Major version upgrade
detected from 11.6.2-MariaDB to 12.3.3-MariaDB. Check required!' on every start
and will forever.

The trade R-459 was expected to produce is not real. Converting properly SUCCEEDS
across the multi-major jump, takes 7 seconds, backs up the system database
unasked - and putting 11.6 back afterwards STILL starts and serves the data. So
the operator is being handed a cheap correction, not a choice between a correct
engine and a reversible one.

The exit-code polarity was measured rather than read: 0 means the upgrade IS
needed, 1 means it is not. Assuming either the flag name or the polarity would
have inverted the headline. And run without credentials the same command returns
a confident-looking FATAL ERROR that is an auth failure.

R-464: after converting and going back, the entrypoint prints 'MariaDB upgrade
not required' on a state the same engine calls an unsupported downgrade. The
obvious cheap instrument for R-459 would have been to grep for that line, and it
would have reported fine for the broken case.

R-463: the PostgreSQL analogue, deliberately NOT measured here. 11 templates, 8
on postgres:16-alpine, register grep for pg_upgrade returns zero. The two engines
fail in OPPOSITE directions - MariaDB skips quietly, Postgres refuses to start -
so that one cannot hide; it presents as eight apps down at once.

No template changed. Teardown all three layers, hub checked rather than asserted,
local-lvm 30.53 percent before and after.
2026-09-06 17:42:19 +02:00

87 lines
2.3 KiB
YAML

# BookStack - Egyszerű, könyv-szerű wiki és dokumentáció platform
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: mariadb
# RAM: ~150M (mem_limit: 512M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
# DB_PASSWORD - Adatbázis jelszó (auto-generated)
# APP_KEY - Laravel application key (auto-generated)
services:
bookstack:
image: lscr.io/linuxserver/bookstack:25.02.2
container_name: bookstack
restart: unless-stopped
depends_on:
bookstack-db:
condition: service_healthy
environment:
- TZ=Europe/Budapest
- PUID=1000
- PGID=1000
- DB_HOST=bookstack-db
- DB_PORT=3306
- DB_USERNAME=bookstack
- DB_PASSWORD=${DB_PASSWORD}
- DB_DATABASE=bookstack
- APP_KEY=${APP_KEY}
- APP_URL=https://${SUBDOMAIN}.${DOMAIN}
volumes:
- bookstack_config:/config
networks:
- traefik-public
- bookstack-internal
deploy:
resources:
limits:
memory: 512M
healthcheck:
test: ["CMD", "curl", "-f", "http://127.0.0.1:80"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.bookstack.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.bookstack.entrypoints=websecure"
- "traefik.http.routers.bookstack.tls=true"
- "traefik.http.routers.bookstack.tls.certresolver=letsencrypt"
- "traefik.http.services.bookstack.loadbalancer.server.port=80"
bookstack-db:
image: mariadb:11.6
container_name: bookstack-db
restart: unless-stopped
environment:
- MYSQL_ROOT_PASSWORD=${DB_PASSWORD}
- MARIADB_AUTO_UPGRADE=1
- MYSQL_DATABASE=bookstack
- MYSQL_USER=bookstack
- MYSQL_PASSWORD=${DB_PASSWORD}
- TZ=Europe/Budapest
volumes:
- bookstack_db_data:/var/lib/mysql
networks:
- bookstack-internal
deploy:
resources:
limits:
memory: 256M
healthcheck:
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
interval: 10s
timeout: 5s
retries: 5
start_period: 20s
volumes:
bookstack_config:
bookstack_db_data:
networks:
traefik-public:
external: true
bookstack-internal: