Known issues¶
Last updated: 2026-10-06. If you hit something not on this list, post it in the Discord bug channel.
Platform-wide¶
- Changing an app's configuration redeploys it. There is no in-place config edit yet. Change the inputs, redeploy, and the app restarts with its data intact.
- Upgrades go one way. You can move an app to a newer catalog version. You cannot roll back to an older one from the console. Snapshot first.
- No automated backups. See the snapshot guide.
- No remote access through Mesopod. App names resolve to your LAN address. Use Tailscale from outside; see the remote access guide.
- The outpost does not update itself. When we ship an outpost fix, we will say so in Discord and you re-run the install command from the console. It is safe to re-run; the guide explains what it does the second time.
- Router DNS rebind protection. Some routers refuse to resolve public names to private addresses. The troubleshooting guide has the per-router fix.
- The console says "DNS written", not "app answers". Reachability is shown from the DNS side only. If a name resolves but the page does not load, the app is still starting or the route is not up yet; wait a minute and retry before reporting.
- Cancelling a queued start removes the instance. If you start a stopped app and cancel while it is queued, the instance is removed rather than returned to stopped. Volumes are kept.
- No "Updating" state while a deploy is in flight. The status can read as unchanged for a short time after you deploy. Watch the deploy log.
Linux (k3s)¶
- Registering a directory needs
sudo. On a machine where the install script set up k3s, k3s keeps its kubeconfig readable by root only. Run as your own user, the registration command the console gives you stops with no kubectl context reaches mesopod cluster. Putsudoin front ofbashin that command (curl -fsSL … | sudo bash -s -- …) and run it again. The same applies on Windows, where Mesopod runs this k3s install inside WSL2.
Mac¶
- Other devices can't reach your apps until you set the DNS target. The
console fills in each cluster's DNS target from the node, and on a Mac the
node is the k3d container or the OrbStack VM, not the Mac. That address
works on the Mac itself and nowhere else, so an app opens on the Mac but
not on your phone. In k3d mode, open Clusters, press Edit next to
the cluster's
dns →address, and enter your Mac's LAN address (on most Macs,ipconfig getifaddr en0prints it). The change applies in about 30 seconds. In OrbStack mode apps can only be reached from the Mac itself for now (install guide), so the detected address is the right one there.
Windows (new this week)¶
- Expect rough edges. The one-command installer is new and has been verified on one machine. A founder will be on the call for every Windows install in this cohort.
- Drives mounted from Windows are slow and ignore Linux ownership. Keep app data on the WSL distro's own disk. Media folders on Windows drives are fine for read-mostly use.
Specific apps¶
- Memos, n8n and Jellyfin can change the group and permissions of a directory you share with them. If you deploy one of them with Use a shared directory and leave Mount read-only unticked, Kubernetes gives every file and folder in that directory the app's group (10001 for Memos, 1000 for n8n and Jellyfin) the first time the app starts, and lets that group read and write them. Owners and file contents are not touched, but nothing changes the group back, and on a large directory that first start can take a long time. The console doesn't warn you about this yet. Tick Mount read-only for anything the app only needs to read, such as a media library, or give the app a directory of its own.
- Chatwoot loses uploaded files and queued jobs when it restarts, and a Redis restart can reopen super-admin account creation. Treat it as a demo, not a production helpdesk, for now.
- Plex answers on port 80 only (no port 32400, no Plex remote access through Plex's own relay) and transcodes in software. If you rely on Plex remotely or on hardware transcoding, keep your existing Plex.
- Immich runs machine learning on CPU. Initial library scans of large libraries take a long time.
- Open WebUI bundles its own Ollama on CPU. There is no option yet to point it at an Ollama you already run.
- qBittorrent and Transmission have no VPN sidecar. If you need a VPN for torrenting, keep your existing setup.
- Actual Budget has one server password and no account. The first visitor to a fresh instance sets it, so open the address yourself before you share it. Mesopod cannot reset that password if you forget it: upstream's reset is a command run inside the container, and the console has no shell. Keep it in a password manager. Your devices keep a full copy of each budget, so a lost password costs you the server copy only — open the app on a device that has the budget, export it from Settings, and redeploy with a new empty volume if you have to.