docs(selfhost): systemd unit, own-database overlay, licences and release facts match the repo - #181
Merged
Merged
Conversation
…ase facts match the repo The self-hosting, installation, development, security and licensing docs had drifted from the code they describe: - systemd unit: /usr/bin on PATH (ffmpeg, gs and soffice were invisible), an optional root-owned EnvironmentFile for the variables the app reads only from the process environment (DATABASE_URL, FORWARDED_ALLOW_IPS, FILEMORPH_IMAGE_MAX_MEGAPIXELS, JWT_SECRET), a 127.0.0.1 bind, and one process: limiter and concurrency caps are per process, so extra workers or service instances multiply every limit. - Cloud overlay: a DATABASE_URL in .env loses to the overlay's own environment: value; to use your own database, edit the overlay and remove the postgres service and its depends_on. POSTGRES_PASSWORD falls back to "changeme"; JWT_SECRET has no fallback. - installation.md: the container user is a system user with an unpinned UID (look it up instead of chown 1000:1000); /ready checks DB and tempdir, not ffmpeg; APP_PORT is read only by run.py; python3 instead of python3.11. - development.md: the parity list names the test that pins each place a new format must appear. - security-overview.md: the shipped tax-retained deletion path instead of "Stripe accounts get 409", the webhook events, PGP wording aligned with SECURITY.md and release-signing.md, accepted advisories listed. - threat-model.md: rate limits key on request.client.host with FORWARDED_ALLOW_IPS, not X-Forwarded-For. - third-party-licenses.md: Ghostscript (AGPL-3.0, used unmodified as a separate program), LibreOffice (MPL-2.0) and fonts in the office image, pillow-avif-plugin with its codecs, Chart.js and the Tailwind bundle; httpx dropped; the v1.1.0 SBOM caveat. - patch-policy.md: the actual two-track release model (continuous latest/sha-* images, tags at the maintainer's discretion — one so far). - email-setup.md: no SMTP means 200 plus a log line, not 503. Full suite 1471 passed / 72 skipped; gitleaks and scope-guard clean; security-auditor and code-reviewer findings addressed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ommits Every PR adds its CHANGELOG entry at the same place, so each merge to main conflicts with every open PR. Taking this PR's entry out lets GitHub merge main in cleanly; the next commit puts it back on top. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ommits Every PR adds its CHANGELOG entry at the same place, so each merge to main conflicts with every open PR. Taking this PR's entry out lets GitHub merge main in cleanly; the next commit puts it back on top. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The last package of the documentation refresh from 2026-09-28: self-hosting, installation, development, email setup, security overview, threat model, incident response, pentest report notes, third-party licences, patch policy and release signing.
/usr/binis onPATH; before, ffmpeg, gs and soffice were invisible to a non-Docker install.EnvironmentFile=-/etc/filemorph/filemorph.envholds the variables the app reads only from the process environment.127.0.0.1.DATABASE_URLin.envloses to the overlay's ownenvironment:value, so the own-database instructions now say what actually works.POSTGRES_PASSWORDfalls back tochangeme;JWT_SECREThas no fallback./readychecks the DB and tempdir, not ffmpeg.APP_PORTis read only byrun.py.request.client.host+FORWARDED_ALLOW_IPS.httpxis dropped.Verification
main15e93fa.🤖 Generated with Claude Code