From 422eab849911d4c5ff326c4917ffb1610442f8d2 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Tue, 6 Oct 2026 16:32:32 +0700 Subject: [PATCH] chore: drop HOST overrides, move known issue to docs, tidy comments and gitignores - Remove HOST=${SERVICE_HOSTNAME} from code-server, code-server-lsio and paseo; hostname: alone sets the name - Move SERVICE_HOSTNAME to the top of their .env.example to match compose order - Drop the openclaw ARM64 Chromium note from its README; docs/openclaw covers it - List CUSTOM_USER in webtop's setup step - Trim reasoning from diun and paseo comments - Delete stale gitea and gitea-mirror .gitignore files - Add TODO.md for remaining naming and README issues --- CLAUDE.md | 2 +- TODO.md | 23 +++++++++++++++++++++++ code-server-lsio/.env.example | 6 +++--- code-server-lsio/README.md | 10 +--------- code-server-lsio/compose.yml | 1 - code-server/.env.example | 6 +++--- code-server/README.md | 9 +-------- code-server/compose.yml | 1 - diun/compose.yml | 2 +- gitea-mirror/.gitignore | 3 --- gitea/.gitignore | 3 --- openclaw/README.md | 5 ----- paseo/.env.example | 7 +++---- paseo/README.md | 12 +++--------- paseo/compose.yml | 1 - paseo/entrypoint.sh | 3 +-- webtop/README.md | 2 +- 17 files changed, 41 insertions(+), 55 deletions(-) create mode 100644 TODO.md delete mode 100644 gitea-mirror/.gitignore delete mode 100644 gitea/.gitignore diff --git a/CLAUDE.md b/CLAUDE.md index d54dd6e..2153ef2 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -151,7 +151,7 @@ collapse and the existing grouping stands. `.env.example` follows its compose file's order. The names differ — one `PASSWORD` can feed several container variables, and `SERVICE_HOSTNAME` feeds -`HOST` — so each entry sits where the first compose entry that reads it sits. +`hostname:` — so each entry sits where the first compose entry that reads it sits. Reordering a compose file means reordering the `.env.example` with it. ## Deployment target diff --git a/TODO.md b/TODO.md new file mode 100644 index 0000000..abb9578 --- /dev/null +++ b/TODO.md @@ -0,0 +1,23 @@ +# TODO + +## Names that differ from the upstream Docker guide + +Renaming a volume on a running deployment orphans its data, so each rename +needs a volume migration (the `migrate-service` skill), not just an edit. + +- [ ] `owncloud` — upstream names its volumes `oc_files`, `mysql` and `redis`; + here they are `owncloud-data`, `owncloud-mysql-data` and + `owncloud-redis-data`. +- [ ] `litellm` — upstream's database service is `db` with volume + `postgres_data`; here it is `postgres` with `pg-data`. +- [ ] `openclaw` — upstream's service is `openclaw-gateway`; here it is + `openclaw`. Upstream uses bind mounts, so the volume names are free. +- [ ] `gitea` — Gitea's install guide names the app service `server`; here it + is `gitea`. Confirm against the current guide before renaming. + +## README contradiction + +- [ ] `code-server-lsio/README.md` says the `universal-docker` mod adds `abc` to + the Docker socket's group, so `docker` works without `sudo`. + `webtop/README.md` says `abc` is not in that group and must use `sudo`. + Both use the same mod; check which is true and fix the other. diff --git a/code-server-lsio/.env.example b/code-server-lsio/.env.example index e056e2d..338184d 100644 --- a/code-server-lsio/.env.example +++ b/code-server-lsio/.env.example @@ -2,6 +2,9 @@ # # cp .env.example .env +# Container hostname. +SERVICE_HOSTNAME=code-server-lsio + # Web UI login password. Required. # Also used for SUDO_PASSWORD inside the container. # Generate one with: openssl rand -base64 24 @@ -11,8 +14,5 @@ PASSWORD= GIT_NAME= GIT_EMAIL= -# Container hostname, also passed in as HOST -- the name zsh's prompt shows. -SERVICE_HOSTNAME=code-server-lsio - # Name of the installed web app. # PWA_APPNAME=code-server diff --git a/code-server-lsio/README.md b/code-server-lsio/README.md index 564bad9..8ed0930 100644 --- a/code-server-lsio/README.md +++ b/code-server-lsio/README.md @@ -32,7 +32,7 @@ separate rootless daemon. | Variable | Purpose | | --- | --- | -| `SERVICE_HOSTNAME` | Container hostname, and the name the shell prompt shows. | +| `SERVICE_HOSTNAME` | Container hostname. | | `PASSWORD` | Web UI login, also the in-container sudo password. Required. | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity | | `PWA_APPNAME` | Optional. Name of the installed web app; defaults to `code-server`. | @@ -43,14 +43,6 @@ The compose file refuses to start when `PASSWORD` is unset or blank. The image itself would start anyway and serve code-server with no authentication, on a container that holds the Docker socket. -`SERVICE_HOSTNAME` is used twice: as the container's `hostname:` and as the -`HOST` variable inside it. Coolify injects `HOST=0.0.0.0` into every compose -app, and zsh seeds `$HOST` and the `%m`/`%M` prompt escapes from that variable -rather than calling `gethostname()` — so the prompt reads `0`, the first -dot-separated field of `0.0.0.0`. code-server itself never reads `HOST` — it -binds `[::]:8443` — so overriding it only affects the prompt. bash is -unaffected; its `\h` uses the real hostname. - `PUID`/`PGID` are pinned to `1000` in `compose.yml`; the `Dockerfile` depends on that (see [Storage](#storage)). diff --git a/code-server-lsio/compose.yml b/code-server-lsio/compose.yml index d6a9279..401d15d 100644 --- a/code-server-lsio/compose.yml +++ b/code-server-lsio/compose.yml @@ -17,7 +17,6 @@ services: - GIT_AUTHOR_EMAIL=${GIT_EMAIL} - GIT_COMMITTER_NAME=${GIT_NAME} - GIT_COMMITTER_EMAIL=${GIT_EMAIL} - - HOST=${SERVICE_HOSTNAME} # - PWA_APPNAME=${PWA_APPNAME:-code-server} volumes: - 'code-server-config:/config' diff --git a/code-server/.env.example b/code-server/.env.example index fe46998..2740a59 100644 --- a/code-server/.env.example +++ b/code-server/.env.example @@ -2,6 +2,9 @@ # # cp .env.example .env +# Container hostname. +SERVICE_HOSTNAME=code-server + # Web UI login password. Required. # Generate one with: openssl rand -base64 24 PASSWORD= @@ -10,8 +13,5 @@ PASSWORD= GIT_NAME= GIT_EMAIL= -# Container hostname, also passed in as HOST -- the name zsh's prompt shows. -SERVICE_HOSTNAME=code-server - # Name shown in the title bar and welcome page. # CODE_SERVER_APP_NAME=code-server diff --git a/code-server/README.md b/code-server/README.md index 651a262..f7c1ebd 100644 --- a/code-server/README.md +++ b/code-server/README.md @@ -149,7 +149,7 @@ sdk install java | --- | --- | | `PASSWORD` | Web UI login. Required. | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity | -| `SERVICE_HOSTNAME` | Container hostname, and the name the shell prompt shows (also passed as `HOST`) | +| `SERVICE_HOSTNAME` | Container hostname | | `CODE_SERVER_APP_NAME` | Optional. Name in the title bar and welcome page; defaults to `code-server`. | Generate a password with `openssl rand -base64 24`. @@ -161,13 +161,6 @@ can only read from inside the container. The `coder` user has passwordless `sudo`, as the image sets it up. Anyone who can log in to the editor is root in the container. -`SERVICE_HOSTNAME` is used twice: as the container's `hostname:` and as the -`HOST` variable inside it. Coolify injects `HOST=0.0.0.0` into every compose -app, and zsh seeds `$HOST` and the `%m`/`%M` prompt escapes from that variable -rather than calling `gethostname()`, so a zsh prompt reads `0`. code-server -itself never reads `HOST`; it binds through `--bind-addr`. bash is unaffected; -its `\h` uses the real hostname. - ## Docker access The host's Docker socket is bind-mounted at `/var/run/docker.sock`. The image diff --git a/code-server/compose.yml b/code-server/compose.yml index 83ee647..962d6a7 100644 --- a/code-server/compose.yml +++ b/code-server/compose.yml @@ -12,7 +12,6 @@ services: - GIT_AUTHOR_EMAIL=${GIT_EMAIL} - GIT_COMMITTER_NAME=${GIT_NAME} - GIT_COMMITTER_EMAIL=${GIT_EMAIL} - - HOST=${SERVICE_HOSTNAME} # - CODE_SERVER_APP_NAME=${CODE_SERVER_APP_NAME:-code-server} volumes: - 'code-server-home:/home/coder' diff --git a/diun/compose.yml b/diun/compose.yml index b1837a5..18652ab 100644 --- a/diun/compose.yml +++ b/diun/compose.yml @@ -21,7 +21,7 @@ services: depends_on: - dockerproxy - # Read-only slice of the Docker API. POST is revoked by default in this image. + # Read-only slice of the Docker API. dockerproxy: image: tecnativa/docker-socket-proxy:latest restart: unless-stopped diff --git a/gitea-mirror/.gitignore b/gitea-mirror/.gitignore deleted file mode 100644 index 835601f..0000000 --- a/gitea-mirror/.gitignore +++ /dev/null @@ -1,3 +0,0 @@ -gitea-mirror/ -.env -purge.py diff --git a/gitea/.gitignore b/gitea/.gitignore deleted file mode 100644 index e9af3b3..0000000 --- a/gitea/.gitignore +++ /dev/null @@ -1,3 +0,0 @@ -gitea/ -.env -purge.py diff --git a/openclaw/README.md b/openclaw/README.md index 74d7698..d2733f9 100644 --- a/openclaw/README.md +++ b/openclaw/README.md @@ -93,8 +93,3 @@ user. `ghcr.io/openclaw/openclaw:latest-browser` is the latest stable release with Playwright Chromium built in, published by the project's release automation. Upstream publishes no major tag. - -On ARM64, release 2026.9.8 cannot find its bundled Chromium ("No supported -browser found"); the fix is merged upstream but not yet released. Everything -except browser automation works meanwhile, and the browser starts working on -the first pull after a release that contains the fix, with no change here. diff --git a/paseo/.env.example b/paseo/.env.example index ae18210..08209d5 100644 --- a/paseo/.env.example +++ b/paseo/.env.example @@ -2,6 +2,9 @@ # # cp .env.example .env +# Container hostname, shown as the host label in the web UI. +SERVICE_HOSTNAME=paseo + # Password for the daemon API and web UI. Also the paseo user's login password, # so it is what `sudo` asks for inside a terminal. # Generate one with: openssl rand -base64 24 @@ -23,7 +26,3 @@ AGENTS=claude codex # these directly, so no `git config` step is needed. GIT_NAME= GIT_EMAIL= - -# Container hostname, shown as the host label in the web UI. Also passed in as -# HOST -- the name zsh's prompt shows. -SERVICE_HOSTNAME=paseo diff --git a/paseo/README.md b/paseo/README.md index 87f38da..079099b 100644 --- a/paseo/README.md +++ b/paseo/README.md @@ -35,7 +35,7 @@ your own machine. | `PASEO_HOSTNAMES` | Domains allowed to reach the daemon, comma-separated. Your domain must be listed. | | `PASEO_TRUSTED_PROXIES` | Set to `uniquelocal`, or the UI loads but never connects. | | `AGENTS` | Agent CLIs to install on start if missing, space- or comma-separated. Empty installs none. See [Agents](#agents). | -| `SERVICE_HOSTNAME` | Container hostname, shown as the host label in the UI and in the shell prompt. Without it the label is a random container ID. | +| `SERVICE_HOSTNAME` | Container hostname, shown as the host label in the UI. Without it the label is a random container ID. | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity for agents and terminals. | `PASEO_TRUSTED_PROXIES` matches the proxy's *source IP*, so hostnames are @@ -46,14 +46,8 @@ the browser blocks that as mixed content. `uniquelocal` covers the private ranges Docker uses. An exact CIDR works too, but Coolify assigns a fresh subnet per project. -`SERVICE_HOSTNAME` is used twice: as the container's `hostname:`, which is -where the daemon takes its host label from, and as the `HOST` variable inside -it. Coolify injects `HOST=0.0.0.0` into every compose app, and zsh seeds `$HOST` -and the `%m`/`%M` prompt escapes from that variable rather than calling -`gethostname()` — so the prompt would read `0`, the first dot-separated field -of `0.0.0.0`. Paseo itself never reads `HOST` — it binds `PASEO_LISTEN` — so -overriding it only affects the prompt. bash is unaffected; its `\h` uses the -real hostname. +`SERVICE_HOSTNAME` sets the container's `hostname:`, which is where the daemon +takes its host label from. `SHELL=/bin/zsh` and `TZ=Asia/Ho_Chi_Minh` are written into `compose.yml` directly rather than read from `.env`, which is why neither is in the table. diff --git a/paseo/compose.yml b/paseo/compose.yml index 84543e7..e432a8c 100644 --- a/paseo/compose.yml +++ b/paseo/compose.yml @@ -14,7 +14,6 @@ services: - GIT_AUTHOR_EMAIL=${GIT_EMAIL} - GIT_COMMITTER_NAME=${GIT_NAME} - GIT_COMMITTER_EMAIL=${GIT_EMAIL} - - HOST=${SERVICE_HOSTNAME} volumes: - 'paseo-home:/home/paseo' - 'paseo-workspace:/workspace' diff --git a/paseo/entrypoint.sh b/paseo/entrypoint.sh index 06c8a5c..196e10f 100755 --- a/paseo/entrypoint.sh +++ b/paseo/entrypoint.sh @@ -36,8 +36,7 @@ for agent in ${agents//,/ }; do continue fi - # 126 and 127 are the shell's own codes for a binary that is missing or - # cannot be executed; any other code means it ran. + # Skip the agent when its command runs. rc=0 /usr/sbin/gosu paseo bash -c '"$0" --version' "$agent" >/dev/null 2>&1 \ || rc=$? diff --git a/webtop/README.md b/webtop/README.md index 6a1d1ce..07dbc18 100644 --- a/webtop/README.md +++ b/webtop/README.md @@ -14,7 +14,7 @@ takes a few minutes longer before the desktop answers. ## Setup -1. Set `PASSWORD`. +1. Set `CUSTOM_USER` and `PASSWORD`. 2. Map the domain to port `3000` and deploy. 3. Open the domain and log in with `CUSTOM_USER` / `PASSWORD`.