Compare commits

..
19 Commits
Author SHA1 Message Date
notplantsandnotplants 26ef5e6625 refactor(backup): inline backupbot hooks, drop mysql_backup.sh
cc-ci/testme cc-ci: success
Move the mysqldump/gunzip commands directly into the
backupbot.backup.pre-hook / backupbot.restore.post-hook label values
on the db service and delete the external mysql_backup.sh + its
config mount + MYSQL_BACKUP_VERSION. Matches the inline pattern used
by akaunting / engelsystem / forgejo and removes one file from the
recipe surface area.
2026-06-02 17:04:02 +00:00
autonomic-bot fefff0d643 chore: upgrade to 1.3.0+6.42.0-alpine
cc-ci/testme cc-ci: success
2026-06-02 02:04:59 +00:00
notplants ae43ffe340 fix(healthcheck): raise app start_period 1m->15m (slow fresh-DB migration)
Ghost's fresh-DB first boot runs a full schema migration (dozens of CREATE
TABLEs, each a separate MySQL round-trip; ~6-9min on a small/slow node). The
1m start_period + 10x30s retries (~6min grace) is too tight there: swarm marks
the still-migrating task unhealthy and kills it mid-migration, leaving a stale
migrations_lock row so every later task deadlocks (MigrationsAreLockedError).

start_period only widens the startup grace window: a healthy check still marks
the task healthy immediately, so fast hosts are unaffected. It cannot be exposed
as an env var (abra validates the literal compose 'duration' format BEFORE env
substitution, rejecting ${VAR} / "${VAR:-1m}" with FATA 'Does not match format
duration'), so a literal bump is the only way to widen it.
2026-05-30 17:18:13 +01:00
autonomic-bot 6d6227f7ba fix(backup): use volume-relative backup path (backupbot restores it) + drop rm post-hook
backupbot restores backed-up files by volume; an absolute backup.path is not mapped back into the
volume on restore, so the restore.post-hook reimported a missing dump. Use
backupbot.backup.volumes.mysql.path=backup.sql.gz (mirrors the postgres recipes).
2026-05-30 05:42:00 +00:00
autonomic-bot a1e95fcbcd fix(backup): single-file mysqldump backup + reimport-on-restore hook
The previous recipe backed the DB up as a mysqldump --tab into /var/lib/mysql-files with NO restore
hook (and the mysql data volume itself was not backupbot-labelled), so a restored backup silently
kept the live, un-restored DB state — data loss on restore. Add mysql_backup.sh (backup: gzipped
mysqldump --databases ghost into the data volume; restore: reimport it) wired via backupbot
backup.pre-hook + restore.post-hook, mirroring the postgres recipes (mattermost-lts, immich). Bump
1.2.0 -> 1.3.0.
2026-05-30 04:58:53 +00:00
val ff03db348f chore: publish 1.2.0+6.21.2-alpine release 2026-03-12 03:56:46 +01:00
val (he/him) a6f646a2c8 Merge pull request 'fixed image version as default, extra compose file for custom image version' (#7) from fixed_image_version into main
Reviewed-on: https://git.coopcloud.tech/coop-cloud/ghost/pulls/7
2026-03-12 02:51:17 +00:00
val 858284e1fe fixed image version as default, extra compose file for custom image version 2026-03-12 03:48:07 +01:00
val (he/him) e6f9ecba68 Merge pull request 'chore: Configure Renovate' (#6) from renovate/configure into main
Reviewed-on: https://git.coopcloud.tech/coop-cloud/ghost/pulls/6
2026-03-12 02:07:51 +00:00
Renovate Bot c3d3eeef56 Add renovate.json 2026-03-10 17:41:37 +00:00
val 1f1add13ee release notes 2025-10-17 17:40:48 +02:00
val 89a9b369bb chore: publish 1.1.1+6-alpine release 2025-10-17 17:40:02 +02:00
val ccc8ee11e9 chore: publish 1.1.0+6-alpine release 2025-10-16 15:25:16 +02:00
val 900386ffa7 Merge pull request '[mass update] fix supporting multiple domains while enforcing ssl' (#4) from forceSsl into main
Reviewed-on: https://git.coopcloud.tech/coop-cloud/ghost/pulls/4
2025-10-15 16:46:31 +00:00
Ammar Hussein 1126e8cdf5 [mass update] fix supporting multiple domains while enforcing ssl 2025-09-08 08:11:16 -07:00
3wordchant 298401b27f chore: publish 1.0.1+5-alpine release 2025-09-01 15:25:59 -04:00
3wordchant 0b3cc6cd1e Add missing secret versions 2025-09-01 15:25:24 -04:00
val 0b22b0bab5 chore: publish 1.0.0+5-alpine release 2025-06-14 16:07:32 +02:00
val 937d84be3f Merge pull request 'version 1.0.0 - upgrade mysql db, added secret, added healthchecks' (#3) from revitalize into main
Reviewed-on: https://git.coopcloud.tech/coop-cloud/ghost/pulls/3
2025-06-14 14:05:20 +00:00
9 changed files with 47 additions and 17 deletions
+22 -7
View File
@@ -9,14 +9,29 @@ DOMAIN=ghost.example.com
#EXTRA_DOMAINS=', `www.ghost.example.com`' #EXTRA_DOMAINS=', `www.ghost.example.com`'
LETS_ENCRYPT_ENV=production LETS_ENCRYPT_ENV=production
## Mail settings SECRET_DB_PASSWORD_VERSION=v1
#MAIL_TRANSPORT=smtp
#MAIL_FROM=admin@example.com SECRET_SMTP_PASSWORD_VERSION=v1
#MAIL_OPTIONS_HOST=mail.example.com
#MAIL_OPTIONS_PORT=587 ## Mail settings (mandatory)
MAIL_TRANSPORT=smtp
MAIL_FROM=admin@example.com
MAIL_OPTIONS_HOST=mail.example.com
MAIL_OPTIONS_PORT=587
MAIL_OPTIONS_AUTH_USER=smtpuser@example.com
#MAIL_OPTIONS_SECURE=false #MAIL_OPTIONS_SECURE=false
#MAIL_OPTIONS_AUTH_USER=smtpuser@example.com
## Advanced options
# see here: https://docs.ghost.org/config#number-of-connections
#DATABASE_POOL_MIN=2
#DATABASE_POOL_MAX=15
COMPOSE_FILE="compose.yml"
## Matrix-Synapse-Redirection ## Matrix-Synapse-Redirection
# COMPOSE_FILE="$COMPOSE_FILE:compose.matrix.yml" # COMPOSE_FILE="$COMPOSE_FILE:compose.matrix.yml"
# MATRIX_DOMAIN=matrix-synapse.example.com # MATRIX_DOMAIN=matrix-synapse.example.com
## Custom Image Version
# COMPOSE_FILE="$COMPOSE_FILE:compose.customversion.yml"
# IMAGE_VERSION=6.3.1
+1 -1
View File
@@ -1 +1 @@
export GHOST_ENTRYPOINT_VERSION=v1 export GHOST_ENTRYPOINT_VERSION=v1
+3
View File
@@ -0,0 +1,3 @@
services:
app:
image: ghost:${IMAGE_VERSION}-alpine
+11 -9
View File
@@ -1,6 +1,6 @@
services: services:
app: app:
image: ghost:5-alpine image: ghost:6.42.0-alpine
environment: environment:
# see https://ghost.org/docs/config/#configuration-options # see https://ghost.org/docs/config/#configuration-options
database__client: mysql database__client: mysql
@@ -8,6 +8,8 @@ services:
database__connection__user: root database__connection__user: root
database__connection__database: ghost database__connection__database: ghost
database__connection__password_FILE: /run/secrets/db_password database__connection__password_FILE: /run/secrets/db_password
database__pool__min: ${DATABASE_POOL_MIN:-0}
database__pool__max: ${DATABASE_POOL_MAX:-10}
url: https://$DOMAIN url: https://$DOMAIN
mail__transport: ${MAIL_TRANSPORT} mail__transport: ${MAIL_TRANSPORT}
mail__from: ${MAIL_FROM} mail__from: ${MAIL_FROM}
@@ -45,17 +47,17 @@ services:
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}" - "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
# Redirect from EXTRA_DOMAINS to DOMAIN # Redirect from EXTRA_DOMAINS to DOMAIN
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect" - "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true" - "traefik.http.middlewares.${STACK_NAME}-redirect.redirectscheme.scheme=https"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}" - "traefik.http.middlewares.${STACK_NAME}-redirect.redirectscheme.permanent=true"
- "backupbot.backup=true" - "backupbot.backup=true"
- "backupbot.backup.path=/var/lib/ghost/content" - "backupbot.backup.path=/var/lib/ghost/content"
- "coop-cloud.${STACK_NAME}.version=0.1.0+5-alpine" - "coop-cloud.${STACK_NAME}.version=1.3.0+6.42.0-alpine"
healthcheck: healthcheck:
test: ["CMD", "wget", "--header=X-Forwarded-Proto: https", "--spider", "-q", "http://localhost:2368/ghost/api/admin/site"] test: ["CMD", "wget", "--header=X-Forwarded-Proto: https", "--spider", "-q", "http://localhost:2368/ghost/api/admin/site"]
interval: 30s interval: 30s
timeout: 10s timeout: 10s
retries: 10 retries: 10
start_period: 1m start_period: 15m
db: db:
image: mysql:8.0 image: mysql:8.0
@@ -70,9 +72,9 @@ services:
deploy: deploy:
labels: labels:
- "backupbot.backup=true" - "backupbot.backup=true"
- "backupbot.backup.pre-hook=mysqldump -u root -p\"$$(cat /run/secrets/db_password)\" ghost --tab /var/lib/mysql-files/" - 'backupbot.backup.pre-hook=mysqldump -u root -p"$$(cat /run/secrets/db_password)" --single-transaction --routines --triggers --databases ghost | gzip > /var/lib/mysql/backup.sql.gz'
- "backupbot.backup.post-hook=rm -rf /var/lib/mysql-files/*" - "backupbot.backup.volumes.mysql.path=backup.sql.gz"
- "backupbot.backup.path=/var/lib/mysql-files/" - 'backupbot.restore.post-hook=gunzip -c /var/lib/mysql/backup.sql.gz | mysql -u root -p"$$(cat /run/secrets/db_password)"'
healthcheck: healthcheck:
test: ["CMD", "mysqladmin", "ping", "-h", "localhost", "-u", "root", "-p\"$$(cat /run/secrets/db_password)\""] test: ["CMD", "mysqladmin", "ping", "-h", "localhost", "-u", "root", "-p\"$$(cat /run/secrets/db_password)\""]
@@ -101,4 +103,4 @@ secrets:
configs: configs:
ghost_entrypoint: ghost_entrypoint:
name: ${STACK_NAME}_ghost_entrypoint_${GHOST_ENTRYPOINT_VERSION} name: ${STACK_NAME}_ghost_entrypoint_${GHOST_ENTRYPOINT_VERSION}
file: entrypoint.sh file: entrypoint.sh
+1
View File
@@ -0,0 +1 @@
breaking change due to mysql-upgrade and secrets, checkout release-notes in release/1.0.0+5-alpine
+1
View File
@@ -0,0 +1 @@
when deploying, healthchecks may fail once, it seems to be caused by a database update/migration needing more time. Just wait some time and deploy again
+1
View File
@@ -0,0 +1 @@
set mysql-pooling default to 0, added option to set it via env
+1
View File
@@ -0,0 +1 @@
move IMAGE_VERSION in extra compose file to make sure, main is always a knowingly working version
+6
View File
@@ -0,0 +1,6 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:recommended"
]
}