Skip to content

docs(selfhost): systemd unit, own-database overlay, licences and release facts match the repo - #181

Merged
MrChengLen merged 7 commits into
mainfrom
pr-selfhost-docs-truth
Sep 29, 2026
Merged

MrChengLen merged 7 commits into
mainfrom
pr-selfhost-docs-truth

Conversation

@MrChengLen

Copy link
Copy Markdown
Owner

What

The last package of the documentation refresh from 2026-09-28: self-hosting, installation, development, email setup, security overview, threat model, incident response, pentest report notes, third-party licences, patch policy and release signing.

  • systemd unit:
    • /usr/bin is on PATH; before, ffmpeg, gs and soffice were invisible to a non-Docker install.
    • An optional root-owned EnvironmentFile=-/etc/filemorph/filemorph.env holds the variables the app reads only from the process environment.
    • Binds to 127.0.0.1.
    • Runs one process: limiter and concurrency caps are per process.
  • Cloud overlay: a DATABASE_URL in .env loses to the overlay's own environment: value, so the own-database instructions now say what actually works. POSTGRES_PASSWORD falls back to changeme; JWT_SECRET has no fallback.
  • installation.md:
    • The container user's UID is looked up, not assumed to be 1000.
    • /ready checks the DB and tempdir, not ffmpeg.
    • APP_PORT is read only by run.py.
    • A new Windows section covers WeasyPrint (GTK/Pango) and Ghostscript.
  • development.md: the parity list names the test that pins each place a new format must appear.
  • security-overview / threat-model:
    • Deletion now describes the shipped tax-retained path instead of "Stripe accounts get 409".
    • The webhook events are listed correctly.
    • PGP wording matches SECURITY.md.
    • Accepted advisories are listed.
    • Rate limits key on request.client.host + FORWARDED_ALLOW_IPS.
  • third-party-licenses:
    • Added: Ghostscript (AGPL-3.0, used unmodified as a separate program), LibreOffice (MPL-2.0) and the fonts in the office image, pillow-avif-plugin + codecs, Chart.js and the Tailwind bundle.
    • httpx is dropped.
    • The v1.1.0 SBOM caveat is noted.
  • patch-policy: describes the actual two-track release model. This wording is for Lennart to review.
  • email-setup: without SMTP you get 200 plus a log line, not 503.

Verification

  • Full suite: 1471 passed / 72 skipped. Doc tests re-run on main 15e93fa.
  • gitleaks and scope-guard are clean.
  • security-auditor and code-reviewer findings are all addressed; both reviews ran twice.

🤖 Generated with Claude Code

MrChengLen and others added 7 commits September 29, 2026 09:20
…ase facts match the repo

The self-hosting, installation, development, security and licensing docs
had drifted from the code they describe:

- systemd unit: /usr/bin on PATH (ffmpeg, gs and soffice were invisible),
  an optional root-owned EnvironmentFile for the variables the app reads
  only from the process environment (DATABASE_URL, FORWARDED_ALLOW_IPS,
  FILEMORPH_IMAGE_MAX_MEGAPIXELS, JWT_SECRET), a 127.0.0.1 bind, and one
  process: limiter and concurrency caps are per process, so extra workers or
  service instances multiply every limit.
- Cloud overlay: a DATABASE_URL in .env loses to the overlay's own
  environment: value; to use your own database, edit the overlay and remove
  the postgres service and its depends_on. POSTGRES_PASSWORD falls back to
  "changeme"; JWT_SECRET has no fallback.
- installation.md: the container user is a system user with an unpinned UID
  (look it up instead of chown 1000:1000); /ready checks DB and tempdir, not
  ffmpeg; APP_PORT is read only by run.py; python3 instead of python3.11.
- development.md: the parity list names the test that pins each place a
  new format must appear.
- security-overview.md: the shipped tax-retained deletion path instead of
  "Stripe accounts get 409", the webhook events, PGP wording aligned with
  SECURITY.md and release-signing.md, accepted advisories listed.
- threat-model.md: rate limits key on request.client.host with
  FORWARDED_ALLOW_IPS, not X-Forwarded-For.
- third-party-licenses.md: Ghostscript (AGPL-3.0, used unmodified as a
  separate program), LibreOffice (MPL-2.0) and fonts in the office image,
  pillow-avif-plugin with its codecs, Chart.js and the Tailwind bundle; httpx
  dropped; the v1.1.0 SBOM caveat.
- patch-policy.md: the actual two-track release model (continuous
  latest/sha-* images, tags at the maintainer's discretion — one so far).
- email-setup.md: no SMTP means 200 plus a log line, not 503.

Full suite 1471 passed / 72 skipped; gitleaks and scope-guard clean;
security-auditor and code-reviewer findings addressed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ommits

Every PR adds its CHANGELOG entry at the same place, so each merge to main
conflicts with every open PR. Taking this PR's entry out lets GitHub merge
main in cleanly; the next commit puts it back on top.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ommits

Every PR adds its CHANGELOG entry at the same place, so each merge to main
conflicts with every open PR. Taking this PR's entry out lets GitHub merge
main in cleanly; the next commit puts it back on top.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MrChengLen
MrChengLen merged commit 522ce13 into main Sep 29, 2026
7 checks passed
@MrChengLen
MrChengLen deleted the pr-selfhost-docs-truth branch September 29, 2026 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant