From 706d2c9c0d8fbf94c7c59406fcf30b24ffd44332 Mon Sep 17 00:00:00 2001 From: orohi Date: Tue, 28 Jul 2026 12:06:07 +0300 Subject: [PATCH] Postgres healthcheck verifies password; document volume password mismatch (v2.5.11). Co-authored-by: Cursor --- README.md | 12 ++++++++++++ app.py | 2 +- docker-compose.yml | 6 +++++- 3 files changed, 18 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index 9290c86..482d8b6 100644 --- a/README.md +++ b/README.md @@ -206,6 +206,14 @@ The compose file connects the panel to Dokploy's Traefik network (`dokploy-netwo 3. Set env vars in Dokploy: `SECRET_KEY` (long random string), strong `POSTGRES_PASSWORD`. 4. Redeploy after changing domains or env. +**Postgres `password authentication failed`:** the database volume keeps the password from the **first** deploy. If you later change `POSTGRES_PASSWORD` in Dokploy, Postgres ignores the new value but the panel uses it in `DATABASE_URL`. Fix: either restore the original password in Dokploy env, or reset the DB volume (wipes panel DB data): + +```bash +docker compose -p home-vpn-g6rfpd down +docker volume rm home-vpn-g6rfpd_amnezia_pgdata +docker compose -p home-vpn-g6rfpd up -d --build +``` + If the domain shows **404 page not found** (plain text, Go-style), Traefik has no route to a healthy backend. After redeploying **v2.5.8+**, on the server run: ```bash @@ -254,8 +262,12 @@ GitHub Actions workflows in `.github/workflows/`: ## 📋 Fix / changelog (this fork) +### v2.5.11 +* **Postgres healthcheck** — verifies DB password (surfaces `POSTGRES_PASSWORD` / volume mismatch before panel starts). + ### v2.5.10 * **Docker startup** — run `uvicorn` directly in `CMD` (no shell entrypoint); rebuild required after deploy. +* **Postgres healthcheck** — verifies password, not only `pg_isready` (catches `POSTGRES_PASSWORD` mismatch with existing volume). ### v2.5.9 * **Remove move connections between servers** — feature rolled back; fixes startup crash (`ToggleConnectionRequest` was missing after v2.5.4). diff --git a/app.py b/app.py index 8edf399..1ee6fca 100644 --- a/app.py +++ b/app.py @@ -103,7 +103,7 @@ else: application_path = os.path.dirname(__file__) DATA_FILE = os.path.join(application_path, 'data.json') # legacy JSON; used only for one-shot import / export -CURRENT_VERSION = "v2.5.10" +CURRENT_VERSION = "v2.5.11" RELEASES_REPO_URL = repo_url() RELEASES_API_LATEST = api_latest_url() BIN_DIR = os.environ.get('TUNNEL_BIN_DIR', os.path.join(application_path, 'bin')) diff --git a/docker-compose.yml b/docker-compose.yml index b30ea92..15fb7c8 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -11,7 +11,11 @@ services: networks: - internal healthcheck: - test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-amnezia} -d ${POSTGRES_DB:-amnezia_panel}"] + test: + [ + "CMD-SHELL", + "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB} && PGPASSWORD=$${POSTGRES_PASSWORD} psql -U $${POSTGRES_USER} -d $${POSTGRES_DB} -c 'SELECT 1' >/dev/null", + ] interval: 10s timeout: 5s retries: 10