I learned something interesting in doing some more testing...
Using the -W option does indeed prompt for a password, but it accepts any value entered at the password prompt. In order to actually authenticate with a password when using psql, you must modify the pg_hba.conf file to use scram-sha-256 as the method for type local.
When I do this, I am unable to authenticate (both while using my actual password, and also while using a password of "test".
And then I figured out the problem.
In my docker-compose.yml, I had put single quotes around my postgres password, thinking this would be safe per my understanding of this question. However, just to check, I tried logging in to psql using the password 'test'. Sure enough, it worked.
Yeah the name you want for the database host is postgres, or whatever the container is named in the docker-compose.yml.
I was curious about this, and it turns out both work. I tested by pinging both postgres and lemmy_postgres_1, and both responded with the same IP address. Good to know, but I did go ahead and change it back to postgres
Maybe try a very simple password temporarily like test, rebuild the postgres container/delete the volumes and see if it works.
I did this, and I'm still getting the same error, so obviously something is wrong.
This makes sense, and I do have a dollar sign in my password...
However, I have confirmed that postgres does in fact parse the password correctly, as I can log in with the defined username/password combo directly using psql
So I think that disproves this theory, doesn't it?
edit: I tried getting rid of the dollar sign just in case... unfortunately I'm still getting the same error
Thank you for enlightening me on the -W option in psql. I have successfully logged in using the expected password for lemmy. This points to something with the connection string. According to the error log, the connection string being used is:
As far as I can tell, the percent encoding is correct. Any ideas how to troubleshoot this further?
edit: it just occurred to me that my container name is lemmy_postgres_1, not postgres as was entered in my lemmy.hjson file. Let's see if changing that will work...
edit2: no, that had no effect. I'm getting the authentication error for user lemmy on both the lemmy container and the postgres container. :(
I got it going... the main problem was that the ports for the proxy container were defined in a confusing way. Rather, the port definition should be symmetrical (e.g. 1236:1236) and not conflated with the lemmy server port (8536). Then, the nginx_internal.conf should be set to listen on 1236 only.
Do you mind sharing what exactly you changed in order to get it to work? I got nginx_internal.conf installed, but did not make any changes to it. I'm not able to get the UI using http://:1236
I'm not a complete newb when it comes to nginx, but I'm having a hard time understanding what all the different parts are here. For instance, what is the lemmy-ui container for? Is that what needs to be exposed for me to access the UI? If so, I don't see any port mapping the in container definition, so is it hard-coded to use a specific port?
I just realized that entire instance is just a bot crossposting posts from reddit via a bot. I got excited looking at the post count, but didn't realize that the actual user engagement is next to nothing. So, I don't want to subscribe after all!
For whatever my opinion is worth (I'm ~1350 blitz on lichess), if you're finding your openings boring, then just try something new. For me, it helps to keep in mind that the goal is to have fun, NOT to maintain a certain Elo.
I don't know for sure... but my instinct is that NAT reflection is moot in that case, because your connection is going out past the edge router and doing the DNS query there, which will then direct you back to your public IP.
I'm sure there's somebody around that knows the answer for certain!
Thank you! I did figure that out as I got further along into this... so much new stuff to learn!!
I learned something interesting in doing some more testing...
Using the
-Woption does indeed prompt for a password, but it accepts any value entered at the password prompt. In order to actually authenticate with a password when usingpsql, you must modify thepg_hba.conffile to usescram-sha-256as the method for typelocal.When I do this, I am unable to authenticate (both while using my actual password, and also while using a password of "test".
And then I figured out the problem.
In my
docker-compose.yml, I had put single quotes around my postgres password, thinking this would be safe per my understanding of this question. However, just to check, I tried logging in topsqlusing the password'test'. Sure enough, it worked.I found another stack exchange with some different advice on strings in yaml: https://stackoverflow.com/questions/53082932/yaml-docker-compose-spaces-quotes
So, I tried my password again, without the single quotes... and it worked.
Perhaps this will help somebody beating their head against the wall in the future.
Turns out, unless you update
pg_hba.confto force password use, using the-Woption prompts for a password, but authenticates with any value entered.I tried this... updated the user to
lemmy1. The error message does indeed change to reflect the new user.Super frustrating!
I was curious about this, and it turns out both work. I tested by pinging both
postgresandlemmy_postgres_1, and both responded with the same IP address. Good to know, but I did go ahead and change it back topostgresI did this, and I'm still getting the same error, so obviously something is wrong.
This makes sense, and I do have a dollar sign in my password...
However, I have confirmed that postgres does in fact parse the password correctly, as I can log in with the defined username/password combo directly using
psqlSo I think that disproves this theory, doesn't it?
edit: I tried getting rid of the dollar sign just in case... unfortunately I'm still getting the same error
Thank you for enlightening me on the
-Woption in psql. I have successfully logged in using the expected password for lemmy. This points to something with the connection string. According to the error log, the connection string being used is:As far as I can tell, the percent encoding is correct. Any ideas how to troubleshoot this further?
edit: it just occurred to me that my container name is
lemmy_postgres_1, notpostgresas was entered in mylemmy.hjsonfile. Let's see if changing that will work...edit2: no, that had no effect. I'm getting the authentication error for user lemmy on both the lemmy container and the postgres container. :(
Frustratingly, when you use psql on the terminal, it does not prompt you for a password. So I'm still not sure if the password works or not :(
Ahh, ok... if you add the
-Woption when logging in to psql (psql -U lemmy -W), it will prompt for the password.The password works! So, apparently it's something with the connection string.
Username definitely matches!
And yes, I have several special characters, but the password is surrounded by single quotes in
docker-compose.yml, so that should not matter, right?I don't know how to do this yet, but this will be the first thing I try this morning.
I got it going... the main problem was that the ports for the proxy container were defined in a confusing way. Rather, the port definition should be symmetrical (e.g.
1236:1236) and not conflated with the lemmy server port (8536). Then, thenginx_internal.confshould be set to listen on1236only.Do you mind sharing what exactly you changed in order to get it to work? I got
nginx_internal.confinstalled, but did not make any changes to it. I'm not able to get the UI using http://:1236I'm not a complete newb when it comes to nginx, but I'm having a hard time understanding what all the different parts are here. For instance, what is the
lemmy-uicontainer for? Is that what needs to be exposed for me to access the UI? If so, I don't see any port mapping the in container definition, so is it hard-coded to use a specific port?Any help you can provide is greatly appreciated!
Thank you kindly for your efforts anyway!
I just realized that entire instance is just a bot crossposting posts from reddit via a bot. I got excited looking at the post count, but didn't realize that the actual user engagement is next to nothing. So, I don't want to subscribe after all!
Maybe I'm confused then. I entered
!homeassistant@lemmit.onlinein the search field, but no results were found.If you're a 1. d4 player, you need to know the Englund Gambit
For whatever my opinion is worth (I'm ~1350 blitz on lichess), if you're finding your openings boring, then just try something new. For me, it helps to keep in mind that the goal is to have fun, NOT to maintain a certain Elo.
Influxdb + grafana for me! Good stuff!
I don't know for sure... but my instinct is that NAT reflection is moot in that case, because your connection is going out past the edge router and doing the DNS query there, which will then direct you back to your public IP. I'm sure there's somebody around that knows the answer for certain!
If your router has NAT reflection, then the problem you describe is non existent. I use the same domain/protocol both inside and outside my network.