[{"data":1,"prerenderedAt":669},["ShallowReactive",2],{"\u002Fdocs\u002Fself-hosting\u002Ftroubleshooting":3},{"id":4,"title":5,"body":6,"description":661,"extension":662,"meta":663,"navigation":664,"path":665,"seo":666,"stem":667,"__hash__":668},"docs\u002Fdocs\u002Fself-hosting\u002Ftroubleshooting.md","Troubleshooting",{"type":7,"value":8,"toc":646},"minimark",[9,13,17,22,112,123,127,130,228,239,243,254,265,322,325,332,339,358,395,401,405,417,421,430,434,488,492,517,521,524,539,543,553,580,587,591,606,610,620,634,642],[10,11,5],"h1",{"id":12},"troubleshooting",[14,15,16],"p",{},"Most problems come down to a handful of settings. Start with the logs, then find your symptom below.",[18,19,21],"h2",{"id":20},"reading-the-logs","Reading the logs",[23,24,25,77],"code-group",{},[26,27,33],"pre",{"className":28,"code":29,"filename":30,"language":31,"meta":32,"style":32},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","sudo docker compose logs -f delivr-api\nsudo docker compose logs -f delivr-web\n","Docker","bash","",[34,35,36,61],"code",{"__ignoreMap":32},[37,38,41,45,49,52,55,58],"span",{"class":39,"line":40},"line",1,[37,42,44],{"class":43},"sBMFI","sudo",[37,46,48],{"class":47},"sfazB"," docker",[37,50,51],{"class":47}," compose",[37,53,54],{"class":47}," logs",[37,56,57],{"class":47}," -f",[37,59,60],{"class":47}," delivr-api\n",[37,62,64,66,68,70,72,74],{"class":39,"line":63},2,[37,65,44],{"class":43},[37,67,48],{"class":47},[37,69,51],{"class":47},[37,71,54],{"class":47},[37,73,57],{"class":47},[37,75,76],{"class":47}," delivr-web\n",[26,78,81],{"className":28,"code":79,"filename":80,"language":31,"meta":32,"style":32},"sudo journalctl -u delivr-api -f\nsudo journalctl -u delivr-web -f\n","systemd",[34,82,83,99],{"__ignoreMap":32},[37,84,85,87,90,93,96],{"class":39,"line":40},[37,86,44],{"class":43},[37,88,89],{"class":47}," journalctl",[37,91,92],{"class":47}," -u",[37,94,95],{"class":47}," delivr-api",[37,97,98],{"class":47}," -f\n",[37,100,101,103,105,107,110],{"class":39,"line":63},[37,102,44],{"class":43},[37,104,89],{"class":47},[37,106,92],{"class":47},[37,108,109],{"class":47}," delivr-web",[37,111,98],{"class":47},[14,113,114,115,118,119,122],{},"For more detail, set ",[34,116,117],{},"DLA_LOG_LEVEL=debug"," on the API and restart it. Log files are also written to ",[34,120,121],{},"data\u002Flogs\u002F",".",[18,124,126],{"id":125},"the-api-exits-right-after-starting","The API exits right after starting",[14,128,129],{},"The API validates its configuration on start and stops with a clear message if something is missing:",[131,132,133,146],"table",{},[134,135,136],"thead",{},[137,138,139,143],"tr",{},[140,141,142],"th",{},"Message",[140,144,145],{},"Fix",[147,148,149,163,173,183,197],"tbody",{},[137,150,151,157],{},[152,153,154],"td",{},[34,155,156],{},"The environment variable DLA_ENCRYPTION_KEY is required but not set.",[152,158,159,160,122],{},"Set a key: ",[34,161,162],{},"openssl rand -hex 32",[137,164,165,170],{},[152,166,167],{},[34,168,169],{},"DLA_ENCRYPTION_KEY is not set or is too short.",[152,171,172],{},"The key must be at least 32 characters long.",[137,174,175,180],{},[152,176,177],{},[34,178,179],{},"The environment variable DLA_APP_URL is required but not set.",[152,181,182],{},"Set it to the web client's public URL.",[137,184,185,190],{},[152,186,187],{},[34,188,189],{},"The environment variable DLA_DB_MIGRATION_DIR is required but not set.",[152,191,192,193,196],{},"Manual installs only: set it to ",[34,194,195],{},".\u002Fdrizzle\u002Fmigrations\u002Fsqlite",". The Docker image sets it for you.",[137,198,199,204],{},[152,200,201],{},[34,202,203],{},"… has to be one of the following: …",[152,205,206,207,210,211,214,215,214,218,214,221,224,225,122],{},"A variable has an invalid value, e.g. ",[34,208,209],{},"DLA_LOG_LEVEL"," must be ",[34,212,213],{},"debug",", ",[34,216,217],{},"info",[34,219,220],{},"warn",[34,222,223],{},"error",", or ",[34,226,227],{},"critical",[14,229,230,231,234,235,238],{},"If the container keeps restarting with permission errors, make sure the mounted ",[34,232,233],{},"data"," and ",[34,236,237],{},"config"," directories are writable.",[18,240,242],{"id":241},"sign-in-fails-or-cors-errors","Sign-in fails or CORS errors",[14,244,245,246,250,251,122],{},"Symptoms: the sign-in page loads, but signing in does nothing or shows a network error. The browser console mentions ",[247,248,249],"strong",{},"CORS"," or ",[34,252,253],{},"Access-Control-Allow-Origin",[14,255,256,257,260,261,264],{},"The API only accepts browser requests from the origin in ",[34,258,259],{},"DLA_APP_URL",". Check that it matches the address in your browser's address bar ",[247,262,263],{},"exactly",":",[131,266,267,277],{},[134,268,269],{},[137,270,271,274],{},[140,272,273],{},"✅ Correct",[140,275,276],{},"❌ Wrong",[147,278,279,292,302,312],{},[137,280,281,286],{},[152,282,283],{},[34,284,285],{},"https:\u002F\u002Fmail.example.com",[152,287,288,291],{},[34,289,290],{},"https:\u002F\u002Fmail.example.com\u002F"," (trailing slash)",[137,293,294,296],{},[152,295],{},[152,297,298,301],{},[34,299,300],{},"http:\u002F\u002Fmail.example.com"," (wrong scheme)",[137,303,304,306],{},[152,305],{},[152,307,308,311],{},[34,309,310],{},"https:\u002F\u002Fwww.mail.example.com"," (different host)",[137,313,314,316],{},[152,315],{},[152,317,318,321],{},[34,319,320],{},"https:\u002F\u002Fmail.example.com:443"," (explicit default port)",[14,323,324],{},"Restart the API after changing it.",[18,326,328,329],{"id":327},"the-web-client-calls-localhost14123","The web client calls ",[34,330,331],{},"localhost:14123",[14,333,334,335,338],{},"Symptoms: in the browser's network tab, API requests go to ",[34,336,337],{},"http:\u002F\u002Flocalhost:14123\u002Fv1"," instead of your API domain.",[14,340,341,342,345,346,349,350,353,354,357],{},"The container image is configured at ",[247,343,344],{},"runtime"," with ",[34,347,348],{},"NUXT_PUBLIC_API_URL",". The ",[34,351,352],{},"DELIVR_API_URL"," variable from the web client's ",[34,355,356],{},"example.env"," is only read when building from source. Set:",[26,359,363],{"className":360,"code":361,"language":362,"meta":32,"style":32},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","NUXT_PUBLIC_API_URL: \"https:\u002F\u002Fapi.mail.example.com\u002Fv1\"\nNUXT_PUBLIC_APP_URL: \"https:\u002F\u002Fmail.example.com\"\n","yaml",[34,364,365,382],{"__ignoreMap":32},[37,366,367,370,373,376,379],{"class":39,"line":40},[37,368,348],{"class":369},"swJcz",[37,371,264],{"class":372},"sMK4o",[37,374,375],{"class":372}," \"",[37,377,378],{"class":47},"https:\u002F\u002Fapi.mail.example.com\u002Fv1",[37,380,381],{"class":372},"\"\n",[37,383,384,387,389,391,393],{"class":39,"line":63},[37,385,386],{"class":369},"NUXT_PUBLIC_APP_URL",[37,388,264],{"class":372},[37,390,375],{"class":372},[37,392,285],{"class":47},[37,394,381],{"class":372},[14,396,397,398,122],{},"…and recreate the container with ",[34,399,400],{},"docker compose up -d",[18,402,404],{"id":403},"_413-request-entity-too-large-when-sending","\"413 Request Entity Too Large\" when sending",[14,406,407,408,411,412,122],{},"Your reverse proxy rejected a mail with attachments before it reached Delivr. Raise the proxy's body limit to at least ",[34,409,410],{},"DLA_MAX_ATTACHMENT_SIZE_MB"," + 16 MB (41 MB with the defaults). See ",[413,414,416],"a",{"href":415},"\u002Fdocs\u002Fself-hosting\u002Freverse-proxy#what-the-proxy-must-do","Reverse Proxy",[18,418,420],{"id":419},"the-mail-server-rejects-large-messages","The mail server rejects large messages",[14,422,423,424,426,427,122],{},"Delivr accepted the attachments, but the mail provider refused the message. Attachments grow by about 37% when encoded for sending, so 25 MB of files become roughly 34 MB. Set ",[34,425,410],{}," below your provider's limit divided by 1.37 — for a 25 MB provider limit, use ",[34,428,429],{},"18",[18,431,433],{"id":432},"a-mail-account-cant-connect","A mail account can't connect",[435,436,437,460,466,472,482],"ul",{},[438,439,440,443,444,447,448,451,452,455,456,122],"li",{},[247,441,442],{},"Double-check host, port, and encryption."," IMAP is usually ",[34,445,446],{},"993"," with SSL\u002FTLS; SMTP ",[34,449,450],{},"465"," with SSL\u002FTLS or ",[34,453,454],{},"587"," with STARTTLS. See ",[413,457,459],{"href":458},"\u002Fdocs\u002Fconfiguration\u002Fmail-providers","Mail Provider Settings",[438,461,462,465],{},[247,463,464],{},"Use an app password"," if the account has two-factor authentication (Gmail, iCloud, Yahoo, Fastmail, …).",[438,467,468,471],{},[247,469,470],{},"Check that IMAP is enabled"," for the mailbox — some providers turn it off by default.",[438,473,474,477,478,481],{},[247,475,476],{},"Check outbound connectivity"," from the server: ",[34,479,480],{},"nc -vz imap.example.com 993",". Some hosting providers block outgoing SMTP ports.",[438,483,484,487],{},[247,485,486],{},"OAuth-only providers"," such as Microsoft 365 \u002F Outlook.com no longer accept passwords for IMAP and aren't supported yet.",[18,489,491],{"id":490},"password-reset-emails-dont-arrive","Password-reset emails don't arrive",[435,493,494,505,508,511],{},[438,495,496,497,500,501,122],{},"System email requires the ",[34,498,499],{},"DLA_SMTP_*"," variables. Without them, Delivr can't send any mail of its own. See ",[413,502,504],{"href":503},"\u002Fdocs\u002Fconfiguration#system-email-smtp","System email",[438,506,507],{},"Each address can request a reset link once every 15 minutes.",[438,509,510],{},"Check the API log for SMTP errors, and the recipient's spam folder.",[438,512,513,514,122],{},"Make sure the user's email address in Delivr is correct — the admin starts out with the placeholder ",[34,515,516],{},"admin@delivr.local",[18,518,520],{"id":519},"too-many-login-attempts","\"Too many login attempts\"",[14,522,523],{},"After repeated failed sign-ins, Delivr refuses further attempts for that username for up to five minutes. Wait and try again. The counters are kept in memory, so restarting the API also clears them.",[14,525,526,527,530,531,534,535,122],{},"If ",[247,528,529],{},"everyone"," gets locked out as soon as one person mistypes their password a few times, Delivr is behind a reverse proxy but can't see the real client addresses. Set ",[34,532,533],{},"DLA_TRUST_PROXY=true"," — see ",[413,536,538],{"href":537},"\u002Fdocs\u002Fself-hosting\u002Fhardening#rate-limiting-at-the-proxy","Rate limiting at the proxy",[18,540,542],{"id":541},"attachment-previews-fail-downloads-work","Attachment previews fail, downloads work",[14,544,545,546,549,550,552],{},"Previews are streamed through the web client's server, which calls the API at its ",[247,547,548],{},"public"," URL. Make sure the server running Delivr Web can resolve and reach ",[34,551,348],{}," — test from inside the container:",[26,554,556],{"className":28,"code":555,"language":31,"meta":32,"style":32},"sudo docker compose exec delivr-web curl -sf https:\u002F\u002Fapi.mail.example.com\u002Fhealth\n",[34,557,558],{"__ignoreMap":32},[37,559,560,562,564,566,569,571,574,577],{"class":39,"line":40},[37,561,44],{"class":43},[37,563,48],{"class":47},[37,565,51],{"class":47},[37,567,568],{"class":47}," exec",[37,570,109],{"class":47},[37,572,573],{"class":47}," curl",[37,575,576],{"class":47}," -sf",[37,578,579],{"class":47}," https:\u002F\u002Fapi.mail.example.com\u002Fhealth\n",[14,581,582,583,586],{},"If that fails, your network doesn't allow hairpin connections. Add the public API hostname to the container's ",[34,584,585],{},"extra_hosts"," or fix the DNS on the host.",[18,588,590],{"id":589},"the-browser-doesnt-offer-to-install-the-app","The browser doesn't offer to install the app",[14,592,593,594,597,598,601,602,122],{},"PWAs require HTTPS (or ",[34,595,596],{},"localhost","). On iOS and iPadOS, installation is manual: tap ",[247,599,600],{},"Share → Add to Home Screen"," in Safari. See ",[413,603,605],{"href":604},"\u002Fdocs\u002Fguide\u002Fgetting-started#install-delivr-as-an-app","Install Delivr as an app",[18,607,609],{"id":608},"still-stuck","Still stuck?",[14,611,612,613,619],{},"Open an issue on ",[413,614,618],{"href":615,"rel":616},"https:\u002F\u002Fgithub.com\u002FDelivr-Project\u002FDelivr-Web\u002Fissues",[617],"nofollow","GitHub"," and include:",[435,621,622,625,628],{},[438,623,624],{},"The Delivr version and how you deployed it (Docker, manual)",[438,626,627],{},"Your reverse proxy and its configuration",[438,629,630,631],{},"The relevant log lines — ",[247,632,633],{},"remove secrets, tokens, and email addresses first",[14,635,636,637,641],{},"For security problems, use ",[413,638,640],{"href":639},"\u002Fsecurity#disclosure","responsible disclosure"," instead.",[643,644,645],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}",{"title":32,"searchDepth":63,"depth":63,"links":647},[648,649,650,651,653,654,655,656,657,658,659,660],{"id":20,"depth":63,"text":21},{"id":125,"depth":63,"text":126},{"id":241,"depth":63,"text":242},{"id":327,"depth":63,"text":652},"The web client calls localhost:14123",{"id":403,"depth":63,"text":404},{"id":419,"depth":63,"text":420},{"id":432,"depth":63,"text":433},{"id":490,"depth":63,"text":491},{"id":519,"depth":63,"text":520},{"id":541,"depth":63,"text":542},{"id":589,"depth":63,"text":590},{"id":608,"depth":63,"text":609},"Fixes for the most common Delivr deployment problems: startup errors, CORS and sign-in issues, attachment limits, mail account connections, and password-reset email.","md",{},{"title":5},"\u002Fdocs\u002Fself-hosting\u002Ftroubleshooting",{"title":5,"description":661},"docs\u002Fself-hosting\u002Ftroubleshooting","vBV4c8fUULVkxayk7rKL84FDSy6qTewqIyh319CEXNs",1791069427525]