Skip to content

Mattermost, Open WebUI, RustDesk, Vikunja, NetBox, SearXNG and 6 more: small fixes - #375

Open
jackspiering wants to merge 4 commits into
mainfrom
small-stack-fixes
Open

jackspiering wants to merge 4 commits into
mainfrom
small-stack-fixes

Conversation

@jackspiering

@jackspiering jackspiering commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Small stack fixes from an external review (section 3.3).

  • Mattermost: SERVICEPORT=8065, and the commented LAN ports block maps to 8065 (Calls lines kept). Removes HTTP_PORT/HTTPS_PORT and the inaccurate comments.
  • Open WebUI: host.docker.internal did not resolve on Linux. Adds extra_hosts: host.docker.internal:host-gateway to the tailscale service, and the README explains that a native Ollama must listen beyond loopback.
  • RustDesk Server: removes the Serve configuration that proxied to a port where nothing listens.
  • Vikunja: requires VIKUNJA_SERVICE_SECRET, so it is no longer regenerated at every start. "Upgrading" note added: existing logins end one last time.
  • NetBox: REDIS_HOST now points to the persistent redis container, not the cache. "Upgrading" note added.
  • SearXNG: settings.yml was a 2761-line copy of upstream's file that referenced engines upstream has removed. It is now use_default_settings: true plus secret_key. "Upgrading" note added. The note also says how to update a clone when the container owns the settings folder. Without that step, git pull stops with unable to unlink old 'services/searxng/searxng/settings.yml': Permission denied and leaves the clone half updated. The stack now sets FORCE_OWNERSHIP=false, so the folder stays with the host user and that step is needed only once.
  • GitSave: DISABLE_AUTH defaults to false instead of being required.
  • Mailpit, Seafile: README corrections.
  • KitchenOwl, Sure: four files are no longer executable.
  • Sure, MeTube: TS_ACCEPT_DNS is explained for Sure and commented out for MeTube.
  • Origin comments on the config files copied from upstream (NetBox, Vikunja).

Related Issues

  • None.

Verification

  • docker compose config --quiet passes in all 12 changed directories with dummy values for required variables, and Vikunja without its secret fails with the expected error.
  • rumdl check --config .markdownlint.yml . (0.2.78) and git diff --check origin/main are clean. The six NetBox config files parse with Python's ast.
  • The SearXNG replacement was diffed against upstream searx/settings.yml at the commit nearest the stack's copy. The only real difference was secret_key.
  • Run on the Tailnet with a test auth key, one stack at a time:
    • SearXNG: started from main, then updated with each path in the "Upgrading" note (chown before the pull, recovery after a failed pull, and an edited settings.yml). Tailscale Serve answers 200 before and after. The log has 19 Cannot load engine lines with the old file and none with the new one.
    • SearXNG with FORCE_OWNERSHIP=false: the folder stays with the host user, an edit of settings.yml without sudo takes effect after docker compose restart application, and Tailscale Serve answers 200. A folder that an earlier version gave to user 977 keeps working. On a stub stack started from main, the "Upgrading" note was followed step by step: docker compose up -d recreates application, and a later change to settings.yml pulls without chown. With folder mode 700 the stack fails with and without the setting.
    • NetBox: the rq keys are in redis and none are in redis-cache. A queued job completes.
    • Vikunja: on main, a login token returns 401 after the application restarts. With the secret, it stays valid after a restart and after the container is recreated.
    • Open WebUI: with only the tailscale container started, host.docker.internal:11434 reaches a stand-in listener on the Docker host.
  • Not run at runtime: Open WebUI with a real Ollama, Mattermost Calls, RustDesk without Serve, and MeTube without MagicDNS.

Checklist

  • I have performed a self-review of my code and followed the templates structure.
  • I have added verification that the stack works as expected.
  • I have updated necessary documentation (e.g. frontpage README.md ).
  • I have selected the correct label(s) for this PR.

Additional Context

  • SearXNG's request method is now GET, which is SearXNG's default. The stack's old method: "POST" was upstream's default when the file was copied. The search form of the running stack uses GET. The "Upgrading" note says so, and how to keep POST (tested).
  • The reason given for Sure's TS_ACCEPT_DNS=true (an OIDC provider on the Tailnet) is the review's suggestion, not confirmed.

…older

SearXNG makes its own user the owner of ./searxng at each start. An existing user's git pull then fails with 'unable to unlink old services/searxng/searxng/settings.yml: Permission denied' and leaves the clone half updated. The Upgrading section now gives the chown step to run before the update, the steps to recover after a failed pull, and the restart that loads the new file.
…t the upgrade notes

SearXNG: FORCE_OWNERSHIP=false stops the image from making its own user the owner of ./searxng, so later changes to settings.yml no longer break git pull and need no sudo. The chown before the update is now a one-time step. The Upgrading note also says that the request method is GET now and how to keep POST.

Vikunja: logins already ended at every restart before the secret was set, so the note now says they end one last time.
SearXNG: the step that recreates the application container stood before the recovery steps, so a reader who recovered from a failed pull never reached it. Without it the old container takes the folder again at its next start. Sure: the README states the effect of TS_ACCEPT_DNS, not a reason that was never recorded.
@jackspiering
jackspiering requested a review from crypt0rr October 10, 2026 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant