chore: drop HOST overrides, move known issue to docs, tidy comments and gitignores

- Remove HOST=${SERVICE_HOSTNAME} from code-server, code-server-lsio and paseo; hostname: alone sets the name
- Move SERVICE_HOSTNAME to the top of their .env.example to match compose order
- Drop the openclaw ARM64 Chromium note from its README; docs/openclaw covers it
- List CUSTOM_USER in webtop's setup step
- Trim reasoning from diun and paseo comments
- Delete stale gitea and gitea-mirror .gitignore files
- Add TODO.md for remaining naming and README issues
This commit is contained in:
tiennm99 committed 2026-10-06 16:32:32 +07:00
1 parent 042d6bd6c0
commit 422eab8499
17 files changed
+41 -55

No files matched your search

+1 -1
View File
@@ -151,7 +151,7 @@ collapse and the existing grouping stands.
`.env.example` follows its compose file's order. The names differ — one `.env.example` follows its compose file's order. The names differ — one
`PASSWORD` can feed several container variables, and `SERVICE_HOSTNAME` feeds `PASSWORD` can feed several container variables, and `SERVICE_HOSTNAME` feeds
`HOST` — so each entry sits where the first compose entry that reads it sits. `hostname:` — so each entry sits where the first compose entry that reads it sits.
Reordering a compose file means reordering the `.env.example` with it. Reordering a compose file means reordering the `.env.example` with it.
## Deployment target ## Deployment target
+23
View File
@@ -0,0 +1,23 @@
# TODO
## Names that differ from the upstream Docker guide
Renaming a volume on a running deployment orphans its data, so each rename
needs a volume migration (the `migrate-service` skill), not just an edit.
- [ ] `owncloud` — upstream names its volumes `oc_files`, `mysql` and `redis`;
here they are `owncloud-data`, `owncloud-mysql-data` and
`owncloud-redis-data`.
- [ ] `litellm` — upstream's database service is `db` with volume
`postgres_data`; here it is `postgres` with `pg-data`.
- [ ] `openclaw` — upstream's service is `openclaw-gateway`; here it is
`openclaw`. Upstream uses bind mounts, so the volume names are free.
- [ ] `gitea` — Gitea's install guide names the app service `server`; here it
is `gitea`. Confirm against the current guide before renaming.
## README contradiction
- [ ] `code-server-lsio/README.md` says the `universal-docker` mod adds `abc` to
the Docker socket's group, so `docker` works without `sudo`.
`webtop/README.md` says `abc` is not in that group and must use `sudo`.
Both use the same mod; check which is true and fix the other.
+3 -3
View File
@@ -2,6 +2,9 @@
# #
# cp .env.example .env # cp .env.example .env
# Container hostname.
SERVICE_HOSTNAME=code-server-lsio
# Web UI login password. Required. # Web UI login password. Required.
# Also used for SUDO_PASSWORD inside the container. # Also used for SUDO_PASSWORD inside the container.
# Generate one with: openssl rand -base64 24 # Generate one with: openssl rand -base64 24
@@ -11,8 +14,5 @@ PASSWORD=
GIT_NAME= GIT_NAME=
GIT_EMAIL= GIT_EMAIL=
# Container hostname, also passed in as HOST -- the name zsh's prompt shows.
SERVICE_HOSTNAME=code-server-lsio
# Name of the installed web app. # Name of the installed web app.
# PWA_APPNAME=code-server # PWA_APPNAME=code-server
+1 -9
View File
@@ -32,7 +32,7 @@ separate rootless daemon.
| Variable | Purpose | | Variable | Purpose |
| --- | --- | | --- | --- |
| `SERVICE_HOSTNAME` | Container hostname, and the name the shell prompt shows. | | `SERVICE_HOSTNAME` | Container hostname. |
| `PASSWORD` | Web UI login, also the in-container sudo password. Required. | | `PASSWORD` | Web UI login, also the in-container sudo password. Required. |
| `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity |
| `PWA_APPNAME` | Optional. Name of the installed web app; defaults to `code-server`. | | `PWA_APPNAME` | Optional. Name of the installed web app; defaults to `code-server`. |
@@ -43,14 +43,6 @@ The compose file refuses to start when `PASSWORD` is unset or blank. The image
itself would start anyway and serve code-server with no authentication, on a itself would start anyway and serve code-server with no authentication, on a
container that holds the Docker socket. container that holds the Docker socket.
`SERVICE_HOSTNAME` is used twice: as the container's `hostname:` and as the
`HOST` variable inside it. Coolify injects `HOST=0.0.0.0` into every compose
app, and zsh seeds `$HOST` and the `%m`/`%M` prompt escapes from that variable
rather than calling `gethostname()` — so the prompt reads `0`, the first
dot-separated field of `0.0.0.0`. code-server itself never reads `HOST` — it
binds `[::]:8443` — so overriding it only affects the prompt. bash is
unaffected; its `\h` uses the real hostname.
`PUID`/`PGID` are pinned to `1000` in `compose.yml`; the `Dockerfile` depends `PUID`/`PGID` are pinned to `1000` in `compose.yml`; the `Dockerfile` depends
on that (see [Storage](#storage)). on that (see [Storage](#storage)).
-1
View File
@@ -17,7 +17,6 @@ services:
- GIT_AUTHOR_EMAIL=${GIT_EMAIL} - GIT_AUTHOR_EMAIL=${GIT_EMAIL}
- GIT_COMMITTER_NAME=${GIT_NAME} - GIT_COMMITTER_NAME=${GIT_NAME}
- GIT_COMMITTER_EMAIL=${GIT_EMAIL} - GIT_COMMITTER_EMAIL=${GIT_EMAIL}
- HOST=${SERVICE_HOSTNAME}
# - PWA_APPNAME=${PWA_APPNAME:-code-server} # - PWA_APPNAME=${PWA_APPNAME:-code-server}
volumes: volumes:
- 'code-server-config:/config' - 'code-server-config:/config'
+3 -3
View File
@@ -2,6 +2,9 @@
# #
# cp .env.example .env # cp .env.example .env
# Container hostname.
SERVICE_HOSTNAME=code-server
# Web UI login password. Required. # Web UI login password. Required.
# Generate one with: openssl rand -base64 24 # Generate one with: openssl rand -base64 24
PASSWORD= PASSWORD=
@@ -10,8 +13,5 @@ PASSWORD=
GIT_NAME= GIT_NAME=
GIT_EMAIL= GIT_EMAIL=
# Container hostname, also passed in as HOST -- the name zsh's prompt shows.
SERVICE_HOSTNAME=code-server
# Name shown in the title bar and welcome page. # Name shown in the title bar and welcome page.
# CODE_SERVER_APP_NAME=code-server # CODE_SERVER_APP_NAME=code-server
+1 -8
View File
@@ -149,7 +149,7 @@ sdk install java
| --- | --- | | --- | --- |
| `PASSWORD` | Web UI login. Required. | | `PASSWORD` | Web UI login. Required. |
| `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity |
| `SERVICE_HOSTNAME` | Container hostname, and the name the shell prompt shows (also passed as `HOST`) | | `SERVICE_HOSTNAME` | Container hostname |
| `CODE_SERVER_APP_NAME` | Optional. Name in the title bar and welcome page; defaults to `code-server`. | | `CODE_SERVER_APP_NAME` | Optional. Name in the title bar and welcome page; defaults to `code-server`. |
Generate a password with `openssl rand -base64 24`. Generate a password with `openssl rand -base64 24`.
@@ -161,13 +161,6 @@ can only read from inside the container.
The `coder` user has passwordless `sudo`, as the image sets it up. Anyone who The `coder` user has passwordless `sudo`, as the image sets it up. Anyone who
can log in to the editor is root in the container. can log in to the editor is root in the container.
`SERVICE_HOSTNAME` is used twice: as the container's `hostname:` and as the
`HOST` variable inside it. Coolify injects `HOST=0.0.0.0` into every compose
app, and zsh seeds `$HOST` and the `%m`/`%M` prompt escapes from that variable
rather than calling `gethostname()`, so a zsh prompt reads `0`. code-server
itself never reads `HOST`; it binds through `--bind-addr`. bash is unaffected;
its `\h` uses the real hostname.
## Docker access ## Docker access
The host's Docker socket is bind-mounted at `/var/run/docker.sock`. The image The host's Docker socket is bind-mounted at `/var/run/docker.sock`. The image
-1
View File
@@ -12,7 +12,6 @@ services:
- GIT_AUTHOR_EMAIL=${GIT_EMAIL} - GIT_AUTHOR_EMAIL=${GIT_EMAIL}
- GIT_COMMITTER_NAME=${GIT_NAME} - GIT_COMMITTER_NAME=${GIT_NAME}
- GIT_COMMITTER_EMAIL=${GIT_EMAIL} - GIT_COMMITTER_EMAIL=${GIT_EMAIL}
- HOST=${SERVICE_HOSTNAME}
# - CODE_SERVER_APP_NAME=${CODE_SERVER_APP_NAME:-code-server} # - CODE_SERVER_APP_NAME=${CODE_SERVER_APP_NAME:-code-server}
volumes: volumes:
- 'code-server-home:/home/coder' - 'code-server-home:/home/coder'
+1 -1
View File
@@ -21,7 +21,7 @@ services:
depends_on: depends_on:
- dockerproxy - dockerproxy
# Read-only slice of the Docker API. POST is revoked by default in this image. # Read-only slice of the Docker API.
dockerproxy: dockerproxy:
image: tecnativa/docker-socket-proxy:latest image: tecnativa/docker-socket-proxy:latest
restart: unless-stopped restart: unless-stopped
-3
View File
@@ -1,3 +0,0 @@
gitea-mirror/
.env
purge.py
-3
View File
@@ -1,3 +0,0 @@
gitea/
.env
purge.py
-5
View File
@@ -93,8 +93,3 @@ user.
`ghcr.io/openclaw/openclaw:latest-browser` is the latest stable release with `ghcr.io/openclaw/openclaw:latest-browser` is the latest stable release with
Playwright Chromium built in, published by the project's release automation. Playwright Chromium built in, published by the project's release automation.
Upstream publishes no major tag. Upstream publishes no major tag.
On ARM64, release 2026.9.8 cannot find its bundled Chromium ("No supported
browser found"); the fix is merged upstream but not yet released. Everything
except browser automation works meanwhile, and the browser starts working on
the first pull after a release that contains the fix, with no change here.
+3 -4
View File
@@ -2,6 +2,9 @@
# #
# cp .env.example .env # cp .env.example .env
# Container hostname, shown as the host label in the web UI.
SERVICE_HOSTNAME=paseo
# Password for the daemon API and web UI. Also the paseo user's login password, # Password for the daemon API and web UI. Also the paseo user's login password,
# so it is what `sudo` asks for inside a terminal. # so it is what `sudo` asks for inside a terminal.
# Generate one with: openssl rand -base64 24 # Generate one with: openssl rand -base64 24
@@ -23,7 +26,3 @@ AGENTS=claude codex
# these directly, so no `git config` step is needed. # these directly, so no `git config` step is needed.
GIT_NAME= GIT_NAME=
GIT_EMAIL= GIT_EMAIL=
# Container hostname, shown as the host label in the web UI. Also passed in as
# HOST -- the name zsh's prompt shows.
SERVICE_HOSTNAME=paseo
+3 -9
View File
@@ -35,7 +35,7 @@ your own machine.
| `PASEO_HOSTNAMES` | Domains allowed to reach the daemon, comma-separated. Your domain must be listed. | | `PASEO_HOSTNAMES` | Domains allowed to reach the daemon, comma-separated. Your domain must be listed. |
| `PASEO_TRUSTED_PROXIES` | Set to `uniquelocal`, or the UI loads but never connects. | | `PASEO_TRUSTED_PROXIES` | Set to `uniquelocal`, or the UI loads but never connects. |
| `AGENTS` | Agent CLIs to install on start if missing, space- or comma-separated. Empty installs none. See [Agents](#agents). | | `AGENTS` | Agent CLIs to install on start if missing, space- or comma-separated. Empty installs none. See [Agents](#agents). |
| `SERVICE_HOSTNAME` | Container hostname, shown as the host label in the UI and in the shell prompt. Without it the label is a random container ID. | | `SERVICE_HOSTNAME` | Container hostname, shown as the host label in the UI. Without it the label is a random container ID. |
| `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity for agents and terminals. | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity for agents and terminals. |
`PASEO_TRUSTED_PROXIES` matches the proxy's *source IP*, so hostnames are `PASEO_TRUSTED_PROXIES` matches the proxy's *source IP*, so hostnames are
@@ -46,14 +46,8 @@ the browser blocks that as mixed content. `uniquelocal` covers the private
ranges Docker uses. An exact CIDR works too, but Coolify assigns a fresh subnet ranges Docker uses. An exact CIDR works too, but Coolify assigns a fresh subnet
per project. per project.
`SERVICE_HOSTNAME` is used twice: as the container's `hostname:`, which is `SERVICE_HOSTNAME` sets the container's `hostname:`, which is where the daemon
where the daemon takes its host label from, and as the `HOST` variable inside takes its host label from.
it. Coolify injects `HOST=0.0.0.0` into every compose app, and zsh seeds `$HOST`
and the `%m`/`%M` prompt escapes from that variable rather than calling
`gethostname()` — so the prompt would read `0`, the first dot-separated field
of `0.0.0.0`. Paseo itself never reads `HOST` — it binds `PASEO_LISTEN` — so
overriding it only affects the prompt. bash is unaffected; its `\h` uses the
real hostname.
`SHELL=/bin/zsh` and `TZ=Asia/Ho_Chi_Minh` are written into `compose.yml` `SHELL=/bin/zsh` and `TZ=Asia/Ho_Chi_Minh` are written into `compose.yml`
directly rather than read from `.env`, which is why neither is in the table. directly rather than read from `.env`, which is why neither is in the table.
-1
View File
@@ -14,7 +14,6 @@ services:
- GIT_AUTHOR_EMAIL=${GIT_EMAIL} - GIT_AUTHOR_EMAIL=${GIT_EMAIL}
- GIT_COMMITTER_NAME=${GIT_NAME} - GIT_COMMITTER_NAME=${GIT_NAME}
- GIT_COMMITTER_EMAIL=${GIT_EMAIL} - GIT_COMMITTER_EMAIL=${GIT_EMAIL}
- HOST=${SERVICE_HOSTNAME}
volumes: volumes:
- 'paseo-home:/home/paseo' - 'paseo-home:/home/paseo'
- 'paseo-workspace:/workspace' - 'paseo-workspace:/workspace'
+1 -2
View File
@@ -36,8 +36,7 @@ for agent in ${agents//,/ }; do
continue continue
fi fi
# 126 and 127 are the shell's own codes for a binary that is missing or # Skip the agent when its command runs.
# cannot be executed; any other code means it ran.
rc=0 rc=0
/usr/sbin/gosu paseo bash -c '"$0" --version' "$agent" >/dev/null 2>&1 \ /usr/sbin/gosu paseo bash -c '"$0" --version' "$agent" >/dev/null 2>&1 \
|| rc=$? || rc=$?
+1 -1
View File
@@ -14,7 +14,7 @@ takes a few minutes longer before the desktop answers.
## Setup ## Setup
1. Set `PASSWORD`. 1. Set `CUSTOM_USER` and `PASSWORD`.
2. Map the domain to port `3000` and deploy. 2. Map the domain to port `3000` and deploy.
3. Open the domain and log in with `CUSTOM_USER` / `PASSWORD`. 3. Open the domain and log in with `CUSTOM_USER` / `PASSWORD`.