github amayer1983/docksentry v2.18.0-beta.38

pre-release3 hours ago

Two things that were asked for, and four days of taking the test suite apart to find out which of the promises around them anything actually held.

/hosts check <endpoint>

Try a host before you add it (#7, @LeeNX). It asks, in order, whether the scheme is one Docksentry speaks, whether anything answers, which engine it is, and whether containers can be listed and one inspected — then names the question that failed instead of returning a bare no. It writes nothing and works before the endpoint is in DOCKER_HOSTS, which is the point: you find out now rather than when an update fails. On Discord it is /hosts check:<endpoint>.

Two limits, said out loud rather than implied. Every question it asks is a read, so a socket proxy that allows GET and refuses POST passes the whole check and fails the first update with a 403 — the "ready" line says so. And the endpoint is whatever you type, so anyone who may command the bot can point it at an address on your network: on Telegram the answer goes to the whole group, on Discord only to whoever asked unless DISCORD_PUBLIC_REPLIES=true.

E-mail that survives a greylisting

A relay answering 450 Greylisted — try again later is asking us to come back, and it was being filed as a refusal — the crash alert was thrown away while the server was asking for a retry. Every mail now carries a Message-ID (#66, @NotRetarded): it was said this path had no transaction id to recognise a second copy with, it has one, and nothing was setting it. A connection that dies once the server has said 354 is held for one more attempt under the same id and no further, so the worst case is two copies of one alert rather than thirty.

The same mistake was in all six HTTP channels, facing the other way: 429 Too Many Requests and 503 Service Unavailable were dropped outright. ntfy.sh rate-limits free accounts, and a burst of failed updates is exactly when a limit is hit and when the message matters.

⚠️ If you set SMTP_TLS to anything other than ssl, starttls or none

SMTP_TLS=TLS — the obvious thing to type — used to fall through to plain SMTP, so with SMTP_USER set the password went out in clear. It now refuses to send and says why in the container log. Mail will stop working until you change it to one of the three words. An empty value meant plain SMTP here while the interface showed STARTTLS; it means STARTTLS now, as it says.

A correction to go with it: a commit of mine on 07.10. claimed SMTP_TLS=SSL had the same problem. It did not — that value has always been lower-cased on the way in, and I wrote that without checking it.

Also fixed

  • Tapping the same update twice no longer puts a ⚠️ "container not in the update list" directly under a green ✅. A second tap on something already running is told so.
  • Messages about one container name the host it is on. portainer alone is ambiguous the moment two machines run one.
  • A maintenance window with an unreadable weekday (["Sat"] instead of [5]) dropped the restriction entirely and updated on days you had excluded. It stays shut now.

The part you cannot see

Most of this release is test work, and the reason is worth one paragraph. A mutation sweep over the whole suite — delete the line that enforces a promise, run all 181 procedures, see whether anything notices — found ten promises that nothing held: rollback after a failed update, quiet hours, maintenance mode, update windows, EXCLUDE_CONTAINERS, /pin, both GitOps labels, the Web UI's CSRF check and its auth gate, the weekly report's schedule, and healthcheck.py, which no procedure loaded at all.

All of them are driven now, and scripts/test_guard_mutations.py breaks each one on purpose and requires a named procedure to go red — so the next time one of them quietly stops working, something says so. 193 procedures, 4605 checks, 69 guarded promises.


Testers — the two things most worth a look: @NotRetarded on the SMTP side (#66), and @LeeNX on /hosts check against a Podman host, including context://. Full notes in #63.

Don't miss a new docksentry release

NewReleases is sending notifications on new releases.