Fixed
- Installer -
make updateand re-running the installer on an existing host aborted with402 Payment Required:03_generate_secrets.shinstalled thecaddypackage from Caddy's Cloudsmith apt repository on every run just to hash basic-auth passwords, and that repository no longer serves packages or its index. Hashes now come fromcaddy hash-passwordin thecaddy:2-alpineimage the stack already runs (docker run --rm, password over stdin), so no Caddy package is installed on the host. The output is checked to be a bcrypt hash, and hashes are computed before.envis rewritten, so a Docker failure leaves.envuntouched. The leftover Cloudsmith apt source and key are removed beforeapt updateruns. Themake updatethat installs 1.16.4 still runs the previousupdate.sh: itsapt-get updateprints the 402 errors once and skips the OS package upgrade for that run, while the update itself continues; the nextmake updateupgrades packages as usual, and a failed package update is now reported as a warning instead of "updated successfully". Acaddypackage an aborted older run left installed on the host (itscaddy.servicecan hold port 80) is reported withapt purge caddy, not removed. Existing hashes in.envare kept as they are.
Upgrade
Run make update. The run that installs 1.16.4 still executes the previous update.sh, so its system package step prints apt errors like 402 Payment Required and The repository 'https://dl.cloudsmith.io/public/caddy/stable/deb/debian any-version InRelease' is not signed and skips apt-get upgrade once. The update itself continues, and the new 03_generate_secrets.sh removes the Cloudsmith source, so the next make update upgrades system packages as usual.
If make update already failed with the 402 (as on 1.16.3), just run make update again: it fetches 1.16.4 and gets past the step that failed. The stack kept running on its previous configuration in the meantime, and existing basic-auth hashes in .env are kept.
If you see the warning about a host caddy package, an older installer run was interrupted before it removed the package again. Its caddy.service can hold port 80 and keep the stack's Caddy container from starting; remove it with sudo apt purge caddy.
Hashing now needs Docker and the caddy:2-alpine image only when a *_PASSWORD_HASH in .env is missing (fresh install, or a new basic-auth service).
Full Changelog: v1.16.3...v1.16.4