github kossakovsky/selfhost-ai v1.16.2

3 hours ago

Fixed

  • Langfuse / RAGFlow - make update aborted with 401 UNAUTHORIZED for quay.io/minio/minio whenever the langfuse or ragflow profile was active: that repository no longer allows anonymous pulls (MinIO stopped publishing images), and Docker Hub no longer serves minio/minio either. The minio and ragflow-minio services now run pgsty/silo, a maintained MinIO fork (also used by RAGFlow upstream) that keeps the data format, so existing buckets are picked up as they are (issue #135).
  • Caddy (security) - Port 7687 (Neo4j Bolt) was published on 0.0.0.0 on every install, also without the neo4j profile, and Docker-published ports bypass ufw. It is now published only while neo4j is active (docker-compose.neo4j.yml); the next make update or make restart closes it on installs without Neo4j (issue #134).

Upgrade

Run make update. Container names, volumes and credentials of minio / ragflow-minio are unchanged, so Langfuse and RAGFlow keep their stored objects.

If you worked around #135 with pull_policy: never for minio / ragflow-minio in docker-compose.override.yml, remove those lines first: the new pgsty/silo image is not on your host yet, and with never Compose refuses to pull it, so the services would fail to start.

Without the neo4j profile, docker ps --filter name=^/caddy$ should list only ports 80 and 443 after the update. A DOCKER-USER iptables rule you may have added for 7687 is no longer needed, but is harmless to keep. With neo4j active nothing changes.

Full Changelog: v1.16.1...v1.16.2

Don't miss a new selfhost-ai release

NewReleases is sending notifications on new releases.