Fixed
- Langfuse / RAGFlow -
make updateaborted with401 UNAUTHORIZEDforquay.io/minio/miniowhenever thelangfuseorragflowprofile was active: that repository no longer allows anonymous pulls (MinIO stopped publishing images), and Docker Hub no longer servesminio/minioeither. Theminioandragflow-minioservices now runpgsty/silo, a maintained MinIO fork (also used by RAGFlow upstream) that keeps the data format, so existing buckets are picked up as they are (issue #135). - Caddy (security) - Port
7687(Neo4j Bolt) was published on0.0.0.0on every install, also without theneo4jprofile, and Docker-published ports bypass ufw. It is now published only whileneo4jis active (docker-compose.neo4j.yml); the nextmake updateormake restartcloses it on installs without Neo4j (issue #134).
Upgrade
Run make update. Container names, volumes and credentials of minio / ragflow-minio are unchanged, so Langfuse and RAGFlow keep their stored objects.
If you worked around #135 with pull_policy: never for minio / ragflow-minio in docker-compose.override.yml, remove those lines first: the new pgsty/silo image is not on your host yet, and with never Compose refuses to pull it, so the services would fail to start.
Without the neo4j profile, docker ps --filter name=^/caddy$ should list only ports 80 and 443 after the update. A DOCKER-USER iptables rule you may have added for 7687 is no longer needed, but is harmless to keep. With neo4j active nothing changes.
Full Changelog: v1.16.1...v1.16.2