github kossakovsky/selfhost-ai v1.16.4

3 hours ago

Fixed

  • Installer - make update and re-running the installer on an existing host aborted with 402 Payment Required: 03_generate_secrets.sh installed the caddy package from Caddy's Cloudsmith apt repository on every run just to hash basic-auth passwords, and that repository no longer serves packages or its index. Hashes now come from caddy hash-password in the caddy:2-alpine image the stack already runs (docker run --rm, password over stdin), so no Caddy package is installed on the host. The output is checked to be a bcrypt hash, and hashes are computed before .env is rewritten, so a Docker failure leaves .env untouched. The leftover Cloudsmith apt source and key are removed before apt update runs. The make update that installs 1.16.4 still runs the previous update.sh: its apt-get update prints the 402 errors once and skips the OS package upgrade for that run, while the update itself continues; the next make update upgrades packages as usual, and a failed package update is now reported as a warning instead of "updated successfully". A caddy package an aborted older run left installed on the host (its caddy.service can hold port 80) is reported with apt purge caddy, not removed. Existing hashes in .env are kept as they are.

Upgrade

Run make update. The run that installs 1.16.4 still executes the previous update.sh, so its system package step prints apt errors like 402 Payment Required and The repository 'https://dl.cloudsmith.io/public/caddy/stable/deb/debian any-version InRelease' is not signed and skips apt-get upgrade once. The update itself continues, and the new 03_generate_secrets.sh removes the Cloudsmith source, so the next make update upgrades system packages as usual.

If make update already failed with the 402 (as on 1.16.3), just run make update again: it fetches 1.16.4 and gets past the step that failed. The stack kept running on its previous configuration in the meantime, and existing basic-auth hashes in .env are kept.

If you see the warning about a host caddy package, an older installer run was interrupted before it removed the package again. Its caddy.service can hold port 80 and keep the stack's Caddy container from starting; remove it with sudo apt purge caddy.

Hashing now needs Docker and the caddy:2-alpine image only when a *_PASSWORD_HASH in .env is missing (fresh install, or a new basic-auth service).

Full Changelog: v1.16.3...v1.16.4

Don't miss a new selfhost-ai release

NewReleases is sending notifications on new releases.