tkohhh

u/tkohhh@waveform.social
4 posts · 24 comments

Recent posts

Recent comments

I learned something interesting in doing some more testing...

Using the -W option does indeed prompt for a password, but it accepts any value entered at the password prompt. In order to actually authenticate with a password when using psql, you must modify the pg_hba.conf file to use scram-sha-256 as the method for type local.

When I do this, I am unable to authenticate (both while using my actual password, and also while using a password of "test".

And then I figured out the problem.

In my docker-compose.yml, I had put single quotes around my postgres password, thinking this would be safe per my understanding of this question. However, just to check, I tried logging in to psql using the password 'test'. Sure enough, it worked.

I found another stack exchange with some different advice on strings in yaml: https://stackoverflow.com/questions/53082932/yaml-docker-compose-spaces-quotes

So, I tried my password again, without the single quotes... and it worked.

Perhaps this will help somebody beating their head against the wall in the future.

If you change the username for the db both for postgres and lemmy, do you get a different error about the new username?

I tried this... updated the user to lemmy1. The error message does indeed change to reflect the new user.

Super frustrating!

Yeah the name you want for the database host is postgres, or whatever the container is named in the docker-compose.yml.

I was curious about this, and it turns out both work. I tested by pinging both postgres and lemmy_postgres_1, and both responded with the same IP address. Good to know, but I did go ahead and change it back to postgres

Maybe try a very simple password temporarily like test, rebuild the postgres container/delete the volumes and see if it works.

I did this, and I'm still getting the same error, so obviously something is wrong.

This makes sense, and I do have a dollar sign in my password...

However, I have confirmed that postgres does in fact parse the password correctly, as I can log in with the defined username/password combo directly using psql

So I think that disproves this theory, doesn't it?

edit: I tried getting rid of the dollar sign just in case... unfortunately I'm still getting the same error

Thank you for enlightening me on the -W option in psql. I have successfully logged in using the expected password for lemmy. This points to something with the connection string. According to the error log, the connection string being used is:

postgres://lemmy:<my percent-encoded password>@postgres:5432/lemmy

As far as I can tell, the percent encoding is correct. Any ideas how to troubleshoot this further?

edit: it just occurred to me that my container name is lemmy_postgres_1, not postgres as was entered in my lemmy.hjson file. Let's see if changing that will work...

edit2: no, that had no effect. I'm getting the authentication error for user lemmy on both the lemmy container and the postgres container. :(

Frustratingly, when you use psql on the terminal, it does not prompt you for a password. So I'm still not sure if the password works or not :(

Ahh, ok... if you add the -W option when logging in to psql (psql -U lemmy -W), it will prompt for the password.

The password works! So, apparently it's something with the connection string.

Do you mind sharing what exactly you changed in order to get it to work? I got nginx_internal.conf installed, but did not make any changes to it. I'm not able to get the UI using http://:1236

I'm not a complete newb when it comes to nginx, but I'm having a hard time understanding what all the different parts are here. For instance, what is the lemmy-ui container for? Is that what needs to be exposed for me to access the UI? If so, I don't see any port mapping the in container definition, so is it hard-coded to use a specific port?

Any help you can provide is greatly appreciated!

I just realized that entire instance is just a bot crossposting posts from reddit via a bot. I got excited looking at the post count, but didn't realize that the actual user engagement is next to nothing. So, I don't want to subscribe after all!

I don't know for sure... but my instinct is that NAT reflection is moot in that case, because your connection is going out past the edge router and doing the DNS query there, which will then direct you back to your public IP. I'm sure there's somebody around that knows the answer for certain!