Tried opening a support ticket, and nothing has been accomplished. Entering day two of empty box and filling up frustrations
11 replies
Chris wrote:
I’m sorry you’ve reached day two without a useful result. I don’t yet have enough detail to identify whether this is Windows with WSL, Docker Desktop, a NAS, or Linux. Please reply with (1) which of those platforms you are using, and (2) the SparkBox version shown in the dashboard or by sudo sparkbox version from the SparkBox host. Please do not uninstall or reset anything while we establish those two facts.
1ye wrote:
1. Windows with WSL/Docker version: 29.7.2 (engine)/Docker Compose: 5.4.0 2. SparkBox v1.6.718
Chris wrote:
Thanks — that establishes Windows with WSL and Docker Engine, running SparkBox v1.6.718. The older blank-dashboard/page-delivery fix is already included in that version, so I do not want to send you through another reset or blind update. When you open the dashboard, is it (A) a completely white page, or (B) a browser error saying it cannot connect? Please reply with the exact visible result. Anthony will answer your private ticket inside the ticket; I’ll keep this public thread focused on the WSL dashboard symptom.
1ye wrote:
Upgraded SparkBox via WSL: sudo sparkbox upgrade [OK] SparkBox is already on the latest release (v1.6.720). Now though, none of the urls are working. My old pinned box shows 'FAILED TO FETCH' when refreshing the page and trying to log in. If I go back to the previous pages, it shows the similar information as the previous sudo sparkbox up dashboard: Apps 14 enabled Containers 1 Running Uptime —uptime System Healthy All systems operational My Ship the Fleet Couldn’t reach the fleet just now. VPN tunnel Down surfshark wireguard Downloads Not routed If VPN drops Kill-switch check not checked yet Test now Tunnel Down Recent Activity live dashboard started 2h Backups — Last backup — Size — Next run — Encryption — Security Network exposure — Admin re-auth — Pi-hole filtering Not installed Container health All healthy All 1 containers running and healthy. Nothing works and sudo SparkBox up after a pc reboot shows: [WARN] Clearing a busy marker left over from before the last reboot (it names pid 1, which belongs to a different boot). / | | | | ) \ \| ' \ / | '| |/ / \ / \ \/ / ) | |) | (| | | | <| |) | () < |/| ./ \,|| ||\\/ \//\\ || SparkBox v1.6.720 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private [INFO] Starting SparkBox... [INFO] Active modules: cloud coolercontrol core dashboard files homarr homeassistant immich media monitoring navidrome syncthing tailscale vaultwarden [INFO] Prepared 1 module config dir(s) for PUID=1000 PGID=1000 [INFO] Fetching images for module: homeassistant [+] pull 16/23 ⠇ Image homeassistant/home-assistant:2026.9.2 [⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣀⡀⣿⠀⠀⠀⣿⠀⣿] Pulling 24.9s failed to copy: local error: tls: bad record MAC [WARN] pull attempt 2/3 (previous attempt failed) — retrying in 10s [+] pull 3/23 ⠦ Image homeassistant/home-assistant:2026.9.2 [⣿⠀⣿⡀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣿] Pulling 22.7s failed to copy: local error: tls: bad record MAC [WARN] pull attempt 3/3 (previous attempt failed) — retrying in 15s [+] pull 12/23 ⠴ Image homeassistant/home-assistant:2026.9.2 [⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣿⠀⠀⣿⠀⠀⠀⠀⠀⠀⠀⣿] Pulling 23.6s failed to copy: local error: tls: bad record MAC [ERROR] Failed to pull images for module 'homeassistant' after 3 attempts. [ERROR] Likely causes: no internet access from this host, Docker Hub rate limit, or insufficient disk space. [ERROR] Try: docker pull <image:tag manually, or check 'docker info' for disk pressure. [INFO] Fetching images for module: media [+] pull 5/20 ! Image jellyfin/jellyfin:10.11.11 Interrupted 40.1s ⠙ Image lscr.io/linuxserver/sonarr:4.0.20 Pulling 40.1s ⠙ Image qmcgaw/deunhealth:latest@sha256:db1e4fcd3aceeb0da34a83f7a8a5432df586e6d0388ddb6ad8dd7b479e4... Pulling 40.1s ⠙ Image qmcgaw/gluetun:v3.41.3 Pulling 40.1s ⠙ Image ghcr.io/thephaseless/byparr:3.0.4 [⠀⠀⠀⠀⠀⠀⠀⠀] Pulling 40.1s ⠙ Image lscr.io/linuxserver/sabnzbd:5.1.3 Pulling 40.1s ⠙ Image lscr.io/linuxserver/radarr:6.4.4 Pulling 40.1s ! Image seerr/seerr:v3.4.1 Interrupted 40.1s ! Image lscr.io/linuxserver/lidarr:3.1.0 Interrupted 40.1s ! Image lscr.io/linuxserver/qbittorrent:5.2.3 Interrupted 40.1s ⠙ Image lscr.io/linuxserver/prowlarr:2.6.5 Pulling 40.1s ! Image lscr.io/linuxserver/bazarr:1.6.1 Interrupted 40.1s failed to copy: local error: tls: bad record MAC [WARN] pull attempt 2/3 (previous attempt failed) — retrying in 10s [+] pull 5/20 ⠦ Image lscr.io/linuxserver/radarr:6.4.4 Pulling 32.6s ⠦ Image lscr.io/linuxserver/sonarr:4.0.20 Pulling 32.6s ! Image jellyfin/jellyfin:10.11.11 Interrupted 32.6s ! Image seerr/seerr:v3.4.1 Interrupted 32.6s ⠦ Image qmcgaw/gluetun:v3.41.3 Pulling 32.6s ⠦ Image lscr.io/linuxserver/sabnzbd:5.1.3 Pulling 32.6s ⠦ Image lscr.io/linuxserver/prowlarr:2.6.5 Pulling 32.6s ! Image lscr.io/linuxserver/bazarr:1.6.1 Interrupted 32.6s ! Image lscr.io/linuxserver/lidarr:3.1.0 Interrupted 32.6s ⠦ Image ghcr.io/thephaseless/byparr:3.0.4 [⠀⠀⠀⠀⠀⠀⠀⠀] Pulling 32.6s ⠦ Image qmcgaw/deunhealth:latest@sha256:db1e4fcd3aceeb0da34a83f7a8a5432df586e6d0388ddb6ad8dd7b479e4... Pulling 32.6s ! Image lscr.io/linuxserver/qbittorrent:5.2.3 Interrupted 32.6s failed to copy: local error: tls: bad record MAC [WARN] pull attempt 3/3 (previous attempt failed) — retrying in 15s [+] pull 3/20 ⠋ Image lscr.io/linuxserver/radarr:6.4.4 Pulling 36.0s ! Image lscr.io/linuxserver/lidarr:3.1.0 Interrupted 36.0s ⠋ Image qmcgaw/deunhealth:latest@sha256:db1e4fcd3aceeb0da34a83f7a8a5432df586e6d0388ddb6ad8dd7b479e4... Pulling 36.0s ⠋ Image lscr.io/linuxserver/sonarr:4.0.20 Pulling 36.0s ⠋ Image jellyfin/jellyfin:10.11.11 Pulling 36.0s ! Image lscr.io/linuxserver/qbittorrent:5.2.3 Interrupted 36.0s ⠋ Image ghcr.io/thephaseless/byparr:3.0.4 [⠀⠀⠀⠀⠀⠀⠀⠀] Pulling 36.0s ⠋ Image lscr.io/linuxserver/prowlarr:2.6.5 Pulling 36.0s ⠋ Image seerr/seerr:v3.4.1 Pulling 36.0s ⠋ Image lscr.io/linuxserver/sabnzbd:5.1.3 Pulling 36.0s ! Image lscr.io/linuxserver/bazarr:1.6.1 Interrupted 36.0s ⠋ Image qmcgaw/gluetun:v3.41.3 Pulling 36.0s failed to copy: local error: tls: bad record MAC [ERROR] Failed to pull images for module 'media' after 3 attempts. [ERROR] Likely causes: no internet access from this host, Docker Hub rate limit, or insufficient disk space. [ERROR] Try: docker pull <image:tag manually, or check 'docker info' for disk pressure. [INFO] Fetching images for module: monitoring [+] pull 5/17 ⠼ Image louislam/uptime-kuma:2.5.5 [⣿⣿⣿⠀⣿⠀⠀⣄⠀⠀⠀⠀⠀⠀⣿⣿] Pulling 24.4s failed to copy: local error: tls: bad record MAC [WARN] pull attempt 2/3 (previous attempt failed) — retrying in 10s [+] pull 8/17 ⠧ Image louislam/uptime-kuma:2.5.5 [⣿⣿⣿⣷⠀⣿⠀⠀⠀⣿⣦⣿⠀⠀⣿⣿] Pulling 25.8s failed to copy: local error: tls: bad record MAC [WARN] pull attempt 3/3 (previous attempt failed) — retrying in 15s [+] pull 3/17 ⠧ Image louislam/uptime-kuma:2.5.5 [⣿⠀⠀⠀⣀⠀⠀⣿⠀⠀⠀⠀⠀⠀⠀⣿] Pulling 20.8s failed to copy: local error: tls: bad record MAC [ERROR] Failed to pull images for module 'monitoring' after 3 attempts. [ERROR] Likely causes: no internet access from this host, Docker Hub rate limit, or insufficient disk space. [ERROR] Try: docker pull <image:tag manually, or check 'docker info' for disk pressure. [ERROR] Image prefetch failed for: homeassistant media monitoring. Aborting before compose up to give a clean error. Despite this SparkBox doctor immediately follows with: [Internet exposure] [INFO] The dashboard container is not running, so exposure cannot be assessed — start it with 'sudo sparkbox up' and re-run doctor. ============================================ All checks passed! ============================================
Chris wrote:
I’m sorry — the earlier reply focused on a blank page, but your new output shows the immediate failure is different: SparkBox cannot pull images, so it aborts before it starts the services. The tls: bad record MAC message is a failed encrypted transfer between Docker and the registry; it is not evidence that the VPN tunnel or Jellyfin is broken. On the WSL host, run this one read-only check and paste only its final result: sudo docker pull hello-world. If it fails with the same TLS error, the problem is below SparkBox; if it succeeds, stop there and reply with that result so we can separate the pull path from the dashboard symptoms. The later “All checks passed!” line is misleading when the dashboard container is not running, and I’ve recorded that correction so it is not repeated.
1ye wrote:
I've uninstalled WSL and set up SparkBox on the UGREEN NAS, only to encounter the very same problem with tls and Docker being unreachable for some reason. New Specs: UGREEN NAS DH2300 SparkBox v1.6.722 Client: Docker Engine - Community Version: 29.6.2 Context: default Debug Mode: false Plugins: buildx: Docker Buildx (Docker Inc.) Version: v0.33.0 compose: Docker Compose (Docker Inc.) Version: v5.1.3 As I am experiencing identical issues as the WSL, I've run the same diagnostics. Just ran the sudo docker pull to get the following: sudo docker pull hello-world Using default tag: latest latest: Pulling from library/hello-world 58dee6a49ef1: Pull complete Digest: sha256:5e23090353324d887c48ad5e5c56d294eab81588df9605b07d1afe895f9cc8f8 Status: Downloaded newer image for hello-world:latest docker.io/library/hello-world:latest Why is nothing working???
Chris wrote:
Thanks — this changes the diagnosis again: on the UGREEN NAS, Docker can pull hello-world, so Docker is not generally unreachable. The repeated failure is limited to one or more SparkBox application image transfers, and the earlier WSL result cannot be carried over to this NAS. On the NAS host, run this one read-only check: sudo docker pull homeassistant/home-assistant:2026.9.2. If it succeeds, stop there and tell me; if it fails, paste only the final error line. Do not reset WSL, reinstall Docker, or delete images/configuration. I’ve corrected the diagnosis to separate a general Docker connection failure from the application-image pull path so the unsupported explanation is not repeated to the next person.
1ye wrote:
Error from latest pull: local error: tls: bad record MAC
Chris wrote:
Thank you — that one line settles it, and I'm sorry it took a WSL wipe and a NAS reinstall to get here. Neither was ever going to help, and I should have said so sooner. local error: tls: bad record MAC means the data arriving at your box was altered somewhere between Docker Hub and the machine — the download is being corrupted in transit, not refused. A tiny image like hello-world fits in a handful of packets and gets through; a big app image crosses thousands, and one damaged packet kills the whole pull. Because a Windows PC and a fresh NAS fail identically, the damage is on the path they share: a cable or switch port, a Wi‑Fi extender or powerline adapter, the router/modem, or the ISP line. Nothing on the NAS is broken and nothing on it needs resetting — SparkBox only asks Docker to download, and Docker does that over the NAS's own network connection. One check: plug the NAS into the router with a different Ethernet cable, straight into a different router port (no switch, extender or powerline adapter in between), then run exactly the same pull again: sudo docker pull homeassistant/home-assistant:2026.9.2. If it completes, the cable or device you removed was corrupting the traffic and sudo sparkbox up will finish normally. If it still fails on that direct cable, the corruption is in the router/modem or upstream — power-cycle both, apply any pending router firmware update and retry; if it fails even then, the line itself needs reporting to your ISP (a phone-hotspot test on the NAS would prove it). I've recorded this so the pull error is explained in plain terms the next time anyone hits it, instead of sending them through a reinstall.
1ye wrote:
It's not the cable, router, modem, ISP, or VPN. Per Tom AI: And there are no new dockerd blocked or Btrfs I/O errors. So we can now rule out: Full storage Reported disk I/O errors The Ethernet link A general GHCR outage The wrong CPU architecture A still-wedged Docker daemon . . . . It’s a repeatable failure downloading one specific large GHCR blob. The earlier Docker/Btrfs blocking was real, but it isn’t currently recurring. . . . Docker client/server: 29.6.2 Driver: overlay2 Architecture: aarch64 Kernel: 6.1.115+ Successful FlareSolverr pull Failed Byparr ARM64 pull Clean btrfs device stats The earlier dockerd blocked / btrfssync Since your reply I've rebooted the NAS and rerun the Home Assistant pull without changing cables, outlets, VPN, or anything else. sudo docker pull homeassistant/home-assistant:2026.9.2 2026.9.2: Pulling from homeassistant/home-assistant e6d068a57c17: Already exists 11ad6d389236: Pull complete f8b45745c3b9: Pull complete 37f11674dbd9: Pull complete 4a4f564eb63b: Pull complete 2c1ce468d9f3: Pull complete 30c4bcf42cc5: Pull complete 9f7b3693a959: Pull complete 98168d40aab2: Pull complete e8cf381243b8: Pull complete af57f847c59e: Pull complete 2ae39eb33555: Pull complete 204479e77b3b: Pull complete d80e2b17100d: Pull complete 932693b55b47: Pull complete 1958f1c16175: Pull complete 21afbd9fe95d: Pull complete 37e1bf8a94d6: Pull complete e56dd41cf6db: Pull complete 8accb9d8fc6e: Pull complete 9bd931435e87: Pull complete Digest: sha256:a1bc133af84ee6505fe2c266d9805b7c75b780dfdc188edfee3b11e8f3cd8efe Status: Downloaded newer image for homeassistant/home-assistant:2026.9.2 docker.io/homeassistant/home-assistant:2026.9.2 It succeeded, but per Tom AI's advice, doing another sudo sparkbox up would just lead to more of the same or potentially stress something. No idea what to do now.
Chris wrote:
I’m sorry this has followed you from WSL to the UGREEN NAS. The successful hello-world pull shows Docker is reachable, while the repeated tls: bad record MAC on the Home Assistant image shows the failure is specific to transferring that application image, not a general SparkBox dashboard or Docker connection failure. Please stop retrying sparkbox up for now; it will keep attempting the same pulls and cannot start the stack until they complete. Do not uninstall Docker, reset WSL, or delete images/configuration. The exact Home Assistant pull error is enough for us to keep this as an image-transfer problem rather than send you through another reset.