#Backup Settings
1 messages Β· Page 1 of 1 (latest)
the server and worker containers status goes to unhealthy after several hours. The warning I can see is:
warning error=authentik starting event=failed to proxy to backend logger=authentik.router
It was working fine for months and recently started happening...nothing has changed except for recent authentik upgrades.
digging further it looks like the postgres container is most likely the culprit. It is throwing: FATAL: sorry, too many clients already.
are you on pg16
Has anyone ran into this issue?
and whats ur current authentik version / does authentik have it's own container or you're using a common db
probably not...this is what i have in my script
authentik on 2024.6.1
yes authentik is on it's own container
you had to upgrade your postgres when passing to authentik 2024.6.x
π€¦ββοΈ I didn't realize I needed to upgrade the database
thanks for pointing that out
no problem
ping me if it still happens after the upgrade ill try to help you out more
I upgraded the ps to 16 and that resolved that issue but authentik still was hanging after an hour so I decided to start over and reconfigure everything. Still not working
can you share your logs
I noticed this in the log.
/ak-root/venv/lib/python3.12/site-packages/opencontainers/distribution/reggie/defaults.py:17: SyntaxWarning: invalid escape sequence '('
"http[s]?://(?:[a-zA-Z]|[0-9]|[$-_@.&+]|[!*(),]|(?:%[0-9a-fA-F][0-9a-fA-F]))+"
any ideas?
thats normal-ish
which container logs?
quoting jens:
Yeah itβs due to a dependency that hasnβt been updated
well wdym by hanging
the server container goes to unhealthy status and I am not able to get to my authentik website or any other sites that I set up
docker compose up --build --force-recreate
and then send logs of everything
and can you also send your docker-compose.yml
let it run a minute to get the logs and not just startup things
and can you try copying it in a way that doesn't break formatting / encoding
it usually takes an hour before it becomes unresponsive
@past ravine The server container just went to unhealthy status but don't see anything in the logs
hmm i don't seem to see any errors either. could you share your docker information and virtual machine information
i saw stack.env in your compose file. are you deploying using portainer? if so, can you try deploying from the command line directly
@river sleet
Yea I set it up in portainer. I'll remove it and try from the command line.
Just weird that it was working fine for more than 6 months
@past ravine I just tried the command line and it still goes unresponsive after an hour or so.
I noticed this warning
{"domain_url": null, "event": "Loaded MMDB database", "file": "/geoip/GeoLite2-City.mmdb", "last_write": 1720729303.0, "level": "info", "logger": "authentik.events.context_processors.mmdb", "pid": 15, "schema_name": "public", "timestamp": "2024-07-16T02:14:39.100134"}
warning error=authentik starting event=failed to proxy to backend logger=authentik.router timestamp=2024-07-16T02:14:40Z
any idea what the issue could be
by the looks of it it's just authentik starting
but can you
ok thanks for trying
can you try deleting all data and downgrading to 2024.4.x and retrying?
yes ...I was thinking of reverting
it might be an issue with proxmox and the latest release
but make sure ur on latest docker stable
with 2024.4.x which pg version should I be using
might as well stay with 16
i upgraded after the pr was merged and didn't have any issues
Server: Docker Engine - Community
Engine:
Version: 27.0.3
API version: 1.46 (minimum version 1.24)
Go version: go1.21.11
Git commit: 662f78c
Built: Sat Jun 29 00:02:33 2024
OS/Arch: linux/amd64
Experimental: false
containerd:
Version: 1.7.18
GitCommit: ae71819c4f5e67bb4d5ae76a6b735f29cc25774e
runc:
Version: 1.7.18
GitCommit: v1.1.13-0-g58aa920
docker-init:
Version: 0.19.0
GitCommit: de40ad0
What was the latest 2024.4.x version?
ok thanks...I think that will solve my problem since for longest time had no issues
BTW, do you use proxmox too?
or what is your setup
but are you able to get authentik working with that version
yes I was using authentik since 2024.2.x
rn it's cloud vms
moved them from my house to there for security, performance, and reliability
3 x 24gb ram nothing fancy really
I see.
i'm planning on moving them to a baremetal ec2 one day
and installing pve again
@river sleet so is authentik working fine now?
@final carbon do you know of any issues that could cause this on 2024.6? or maybe i missed something
I don't know yet...I just fired up my pbs and going to roll back to an instanct with my portainer config
i'm curious why are you managing it with portainer instead of the command line
and then update that script...I prefer portainer because it's easier
last time i played with portainer i deleted my gitlab install
I don't have to ssh in...got a web gui
yea I'm lazy LOL
i can't even log in lol
all my stuff is behind vpn so i only have authentik for a few things but i'm planning on adding it to the remaining things and maybe depend less on vpn
I'm like you...I only have a few things out in internet...the rest I wireguard to access.
i never got wireguard to work
i only have 2 public things: my broken and incomplete and weird website and my image host
I have wireguard on an LXC...works great
like i allowed the ports thru ip tables and ufw but i still couldn't get internet connection
well dns resolution actually
did you try tailscale and headscale? that works great too
unless it's cause my adguard runs on a container in a docker network and i expose :53 but if i expose it on all interfaces it causes massive drops in internet conn
but it was overkill for what I needed
yea i use tailscale
gonna add 3 more ips to it when i protect my intranet better
reminder to self tdk-1038 which has been unresolved for over a week
you should setup headscale if you have not
tbh i don't really see the need to self host it
I just prefer not having things routed outside of my self host if not needed
you still communicate with tailscale
when you set the control plane server in the ios app for example
- changing the url looks like a pain in the a in windows
I don't use tailscale anymore but I remember that you have to go thru the tailscale server for routing
yea
i'm not too much of a networking nerd so i don't want to make it too hard on myself either
but out of curiosity what do you self host
have you tried out plane for task mgmt
i couldn't get it to work. bunch of cors errors
paperless, freshrss, linkding and arr*
i imported over 1.1k tasks to notion from jira
and many others that I can't remember off top of my head since I shut down the vm to restore π
lol
no haven't tried plane...you got a link?
btw atlassian is a royal pain to delete your account
i just sent a gdpr deletion request or something to atlassian support
yea looks like a pain
plane?
no the Atlassian
oh and have you tried harbor docker registry? last i checked the docker container tried mounting the entire file system
I'm just at 5% in the restore. π€¦ββοΈ
yea there's a bunch of things to cancel everywhere
just create a new vm
with a weird install script and no prebuilt images
and another 20 on another server vm
it's just slow because I have my pbs backups stored in another NAS
you should give it another go...it is great
yea in def installing it when i get that baremetal
I have it setup to wake on lan to my PBS and does a nightly backup and then the PBS shuts down when done
but rn it's easy cause i can make a backup script in 300 lines of ruby which handles everything
And then sync the encrypted copy to onedrive
I just got a 4 line script in a cron job π
that turns on my pbs server and does the backup and shuts down
integrated pve backups ?
gitlab takes 20 seconds to load but my internet speed is 1.5gb up / down lol
one line to connect the pbs server
one line to backup
one line to shutdown
wow that is slow
where you located
I get 1gig u/d
π
there's one thing i miss
oh yea...other usefull stuff i use is homebride, scrypted, teslamate
forget what it's called
but it saves a complete backup of both the ram state and the disk state
what do you host?
i have an outdated ish list on https://sdko.org/homelab
oh yea it's intentional
uhh refresh
but for live stalking https://crt.sh/?q=sdko.org
Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)
yea i see it now
then there's this thing i'm working on. outdated ss but https://img.sdko.org/u/pBZSoY.png
fun fact i made my personal site way before i even bought my new domain so it was just doing nothing for several weeks. i have a good dozen to dos to resolve
LOL
notice how there's no frontend technologies in /stack
look at certificate transparency logs
I had that working and now it's broken....another thing to fix π€¦ββοΈ
i was using it to monitor activities to see if I get weird people trying to hack my stuff
fail2ban
yea I have fail2ban setup on most my stuff
omg tailscale mobile auto connect is a pain to disable to disable vpn
it's the kind of thing you setup and forget
and I have geo locking
i block [...] or (ip.geoip.country in {"AF" "BD" "CN" "IR" "IQ" "KP" "RU" "YE" "XX"}) or [...]
xx being other territories and nations
I also try to be secure as well...got vlans setup in my home network to segragate different things
idk if it's worth vlan'ing in my use case for tailscale stuff
public things are running in same rev proxy container so
different containers and i get tailscale intranets separate ips from the machine's so technically ig?
yea
100.64.0.0/10 is for my devices
100.65.0.0/10 is for my vms
100.66.0.0/10 is for my intranet ips so at least i organize
LOL I'm now at 26% restore...it's 107GB.
yea you got it organized well
nice little notion docs
you are very organized
thanks
I need to put stuff down on paper one day...it's all in my head and sometimes I forget
wait until you see my todo
#13 is still open
"Push docker images from < > to new registry" which is not necessarily hard to do
yea not hard
it's changing it in my ci/cd which is annoying
which leads me to tdk-12 get gitlab host name working as intended cause rn it only works as http://gitlab:80 as external url which makes my life pain
Are you doing this for learning for work?
Yea...this is just my hobby
i might do something in cs
idk what yet but probably not software engineer
i won't say i hate writing code but i don't see myself doing that as a job
it's not a bad job though for the money
yea I do
I just do a lot of vb and sql
old school
vb is gonna be gone when tech debt is cleaned up in msft's codebase
replaced with python
u work at ibm or something ?
π€£
real question
or for the us gov maintaining the last nuclear control centers with 8 inch floppy disks
no...just an old company that's been around for over 100 years
at least they not using lisp
lol
my dad is sr project manager there so
i have the chance to see a lot of the inner workings
that's good you see it and know you don't want to do programming
I think I'm just going to call it a night and just let the damn restore go
same
It's going to be awhile
it's 1:45 am
I'll let you know if this works tomorrow
and i need to be up by 5 today
dang you better get some rest
bye
@past ravine FYI...I spent too much time trying to figure this out. I ended up rolling my VM all the way back until before the issue occurred and so far it is working fine. I was on 2024.4.2 and pg12
did you try saving a snapshot of that again and then updating pg and authentik at the same time
not yet...I'm planning to do that tomorrow. 2 reasons. 1 is because I have a nightly backup that I want to capture a good state and 2 because I want to let 24 hours lapses to make sure it truly is resolved.
and third...I'm busy too. π
yea makes sense
i'm a little more intrepid i backup my docker data every 3h instead of the entire vm state
unless oracle and soon aws have ways of backing up entire vms without that costing money
that's intense
Yea mine is incremental backups so not long to do and not much storage
But that would mean I would have to leave my PBS on all the time which I don't want to due to high electricity cost
i'm actually rewriting my backup manager to rust to redeploy it easily
since you have been in the industry a while what do you think of my current setup: all my vm mgmt things are binaries which are loaded to a docker base image as needed
kind of like software updates like ios
I think that's good and probably fits your needs. It's little overkill for my purposes
well i feel it's the easiest to maintain and use
instead of having to maintain several containers there's just one with binaries loaded on them. like linux rn
but i'm always looking into new things
that's good...I just want things to work. I don't have the bandwidth right now to tinker
I depend on these apps I have running
@past ravine I updated the pg to 16 and then authentik to 2024.6.1 and it's been over 24 hours with no problem. Sometimes it's just easier to rollback than to figure out the issue. Thanks for all the help though.
