I'm new to all of this stuff tbh so talk to me like I'm a baby please lol. Tried installing using the command from the site and keep getting this error. { SparkBox] EGRESS CHECK FAILED — containers on sbproxy cannot reach webhook.tomsparkbox.com. [SparkBox] License activation WILL fail until this is fixed. [SparkBox] Recovery (try in order): [SparkBox] 1. sudo rm -f /etc/docker/daemon.json && sudo systemctl restart docker [SparkBox] 2. sudo sparkbox repair-network [SparkBox] 3. Check UFW: grep DEFAULTFORWARDPOLICY /etc/default/ufw (should be ACCEPT) [SparkBox] 4. From inside dashboard: sudo docker exec sb-dashboard node -e "require('dns').lookup('webhook.tomsparkbox.com',(e,a)=console.log(e?e.code:a))" FAILURE] SparkBox installed, but Docker couldn't start the core services. [FAILURE] The most common causes are port conflicts (8443 already taken), missing /var/run/docker.sock permissions, or low disk space. [FAILURE] Last 20 lines of the sparkbox up log: 13 exporting to image 13 exporting layers done 13 exporting manifest sha256:1f5b43fa9a018ccd67e4221ef95948a836858e54611fc6fe795060e8efb880c3 done 13 exporting config sha256:624d77d5e15d493b838ddc6b68551ddafc89625dee222b7619b84be1a4e21e36 13 exporting config sha256:624d77d5e15d493b838ddc6b68551ddafc89625dee222b7619b84be1a4e21e36 done 13 exporting attestation manifest sha256:560f3addaf3e76de17d3ee6b9a6aba4a8d1da965b2b5b4ca444251ac8cfceaca 0.1s done 13 exporting manifest list sha256:ad62b8301b13e136f58bac7b7f69e657d610a2fa548aa90fe75d83ab4e2c3428 0.0s done 13 naming to docker.io/library/sparkbox-sparkbox-dashboard:latest done 13 unpacking to docker.io/library/sparkbox-sparkbox-dashboard:latest 13 unpacking to docker.io/library/sparkbox-sparkbox-dashboard:latest 1.2s done 13 DONE 1.5s 14 resolving provenance for metadata file 14 DONE 0.0s Image sparkbox-sparkbox-dashboard Built Container sb-dashboard Creating Container sb-dashboard Created Container sb-dashboard Starting Container sb-dashboard Started [FAILURE] Next steps: [FAILURE] 1. Run: /opt/sparkbox/sparkbox doctor (finds common causes automatically) [FAILURE] 2. Fix what it reports, then run: /opt/sparkbox/sparkbox up [FAILURE] 3. If you're still stuck, email support@tomsparkbox.com with the log output above } Any help would be greatly appreciated and let me know if/what other info you may need.
34 replies
tomspark wrote:
Couple things going on in your output: The "EGRESS CHECK FAILED" line is a non-fatal warning — even before v1.6.68, the install continues past it. SparkBox is free, so that egress check is only used for optional Pro-tier license activation; every bundled app (Jellyfin, Pi-hole, Vaultwarden, etc.) runs the same either way. We just shipped clearer wording for it in v1.6.68 because the old copy was misleading new users into thinking the install had failed. Your real failure is the line below — "Docker couldn't start the core services." We need to see which container died. Can you run: sudo /opt/sparkbox/sparkbox doctor and paste the output? That'll point at the actual cause. Most common one on a fresh install is UFW blocking container forwarding — grep DEFAULTFORWARDPOLICY /etc/default/ufw should say ACCEPT.
tomspark wrote:
That [WARN] PUID=1000 does not match current UID=0 is a misleading warning on our side — PUID=1000 in .env is the user the containers run as (node user inside the dashboard image is UID 1000), NOT a value that should match your host login. Doctor's comparing the wrong axis. Adding that to the patch list. What does the rest of doctor output say after that section? Specifically [Containers] and [Dashboard] — paste those if you can; that's where any actual problem will show. Also, try opening your dashboard URL directly: https://<your-server-IP (port 443 default, or whatever HTTPSPORT is in /opt/sparkbox/.env). If it loads, your install actually succeeded — the egress and PUID warnings were both cosmetic and the install completed past them.
tomspark wrote:
Weird that doctor stops there — it should keep going through [Container Egress], [Containers], and [Dashboard] sections. Either your terminal cut the output off when scrolling, or doctor genuinely exited early on something we don't catch. Quickest test of whether your install actually works (which is the real question, ignoring the warnings): open https://<your-server-IP in a browser. If you don't know your IP, run hostname -I on the SparkBox host and use the first one. If the dashboard loads (you'll get a cert warning — accept it), your install is fine and the egress + PUID warnings were both cosmetic. If the URL doesn't load at all, paste sudo docker ps output and I'll see which containers are alive vs dead.
tomspark wrote:
Nice — your install actually worked, all the warnings were noise. The bootstrap token is in your .env, you just scrolled past it in the install output. Grab it: sudo grep '^SBBOOTSTRAPTOKEN=' /opt/sparkbox/.env Paste the value (everything after the =) into the dashboard's first-run claim screen. That's the last step — set your admin password from there and you're in.
tomspark wrote:
Right on — glad you got there. Yell back here if anything else trips you up.
tomspark wrote:
Different roles, not interchangeable: - Tailscale / WireGuard mesh VPNs — connect YOUR devices to YOUR network securely. They don't hide your IP from torrent peers, they just give you remote access. SparkBox actually bundles a Tailscale module for that use case (remote dashboard access). - Browser VPNs / free VPNs (Brave, Opera, Hola, etc.) — usually don't allow port forwarding, throttle bandwidth heavily, or have spotty kill-switches. Some flat-out forbid P2P. Won't reliably work with the arr stack's download tunnel. - Paid privacy VPNs (Proton, Mullvad, Surfshark, Nord, etc.) — built for what SparkBox uses them for: a kill-switched tunnel for qBittorrent traffic with port forwarding, no logs, sustained throughput. Mullvad and Proton are the strongest privacy options; Surfshark/Nord are popular on price. For SparkBox specifically: pick a paid provider Gluetun supports (Proton, Mullvad, Surf, Nord all work). The bundled Tailscale module is for getting INTO your SparkBox from outside, not for routing torrents.
tomspark wrote:
Anytime — yell back if anything else trips you up.
tomspark wrote:
Two separate things going on: Search not finding eztv / pirate bay: Prowlarr's catalog is exact-match-ish. Try EZTV and ThePirateBay (capitals matter). If those still don't appear, the catalog filter at the top of the Add Indexer dialog might be hiding them — clear any 'Privacy: Public' / 'Type' filters and search again. "Unable to connect — DNS/SSL" on the ones you do try: that's almost always a Cloudflare-protected indexer needing FlareSolverr. Check Prowlarr → Settings → Indexers → Indexer Proxies — there should be a FlareSolverr entry pointing at http://flaresolverr:8191. If it's missing or shows red, that's the broken piece. SparkBox auto-wires it but the wire breaks if the gluetun container restarted. Quick test that pins it: try adding Nyaa (no Cloudflare). If THAT connects, you've narrowed it to FlareSolverr. If Nyaa also fails, paste sudo docker logs sb-prowlarr --tail 50 and I'll see what Prowlarr's actually complaining about.
tomspark wrote:
Found the actual root cause — gluetun is in a restart loop. WireGuard 'completes' but healthcheck times out (dial tcp4: lookup github.com: i/o timeout) every 6s, so it cycles through Surfshark servers. NO traffic is leaving your VPN tunnel. THAT'S why Prowlarr can't reach indexers.prowlarr.com, FlareSolverr can't initialize, indexer tests fail — everything downstream of gluetun is starved. Most common cause: stale/wrong Surfshark WireGuard private key. Fix: 1) Log into surfshark.com → Account → VPN → Manual Setup → WireGuard 2) Copy your private key (or regenerate one) 3) Edit /opt/sparkbox/.env, replace the value of WIREGUARDPRIVATEKEY= 4) sudo /opt/sparkbox/sparkbox up Then sudo docker logs -f sb-gluetun — when working you'll see healthcheck succeeded and the restart messages stop. If the new key still i/o-timeouts, your ISP is blocking UDP 51820. Switch Surfshark to OpenVPN in that case (set VPNTYPE=openvpn instead of wireguard in .env). Post back if it doesn't clear after the key swap.
tomspark wrote:
Progress — gluetun stable on OpenVPN is the breakthrough. The dashboard banner uses a separate health check that's failing for a different reason now, not the original restart loop. Quick verify the tunnel is actually routing traffic: sudo docker exec sb-gluetun wget -qO- https://api.ipify.org && echo If that returns Surfshark's IP (not your real public IP), the tunnel is fine and the dashboard banner is just stale — sudo docker restart sb-dashboard will refresh it. If it returns YOUR real IP or fails entirely, OpenVPN is up but routing didn't take. Paste sudo docker logs sb-gluetun --tail 20 and I'll see what OpenVPN is actually doing.
tomspark wrote:
Smoking gun: AUTHFAILED from Surfshark = OpenVPN is reaching the server but your credentials are wrong. Surfshark uses service credentials for OpenVPN, NOT your account email/password — they're different. Fetch them: surfshark.com → Account → VPN → Manual Setup → OpenVPN → 'Credentials' section. You'll see a service-username and service-password (random-looking strings, not your email). Edit /opt/sparkbox/.env: OPENVPNUSER=<paste service-username OPENVPNPASSWORD=<paste service-password Then sudo /opt/sparkbox/sparkbox up. Watch sudo docker logs -f sb-gluetun — you should see Initialization Sequence Completed and no more AUTHFAILED. After that, the dashboard banner should clear in ~30 seconds.
tomspark wrote:
Worth double-checking which credential type you used. Surfshark's OpenVPN service username is a random-looking string, NOT your account email. If what's in your config looks like an email (you@gmail.com style), that's the account login — different from the service one OpenVPN needs. The right ones are at surfshark.com → Account → VPN → Manual Setup → OpenVPN → Credentials section. There's also a 'Generate new credentials' button right there — if you suspect your saved values are stale, regenerate, then paste the fresh service-username + service-password into the install wizard or via the dashboard's Settings → VPN page, and restart the stack.
tomspark wrote:
If WireGuard's tunnel-completes-but-no-data AND OpenVPN AUTHFAILED both happen with the same Surfshark login, that points at something account-side rather than gluetun. Two sanity checks: 1) Log into surfshark.com and confirm your subscription is active — expired/lapsed accounts get rejected at auth even with regenerated credentials. 2) Install the Surfshark desktop or mobile app on another device, sign in with the same account, try to connect. If THAT fails too, it's account-side and Surfshark support is the path. If it works there but not in gluetun, something about the credential format is breaking the handoff. If you want to keep moving while sorting Surfshark: switch to a different provider gluetun supports (Mullvad and Proton are reliable). Change VPNSERVICEPROVIDER= in .env and the rest of the stack stays the same.
tomspark wrote:
Welcome back! Glad Surfshark sorted itself. Both of those issues are already fixed — you just need to update. Run this: sudo sparkbox update && sudo sparkbox restart media That pulls v1.6.85 (with the qBit "Unauthorized" fix from v1.6.80 and the download-path fix from v1.6.85) and restarts the media stack with the new settings. Wait ~2 minutes for everything to come back up. Then for the qBit login: sudo cat /opt/sparkbox/state/qbittorrent-admin-password.txt Username is admin, password is in that file. For seerr — once Jellyfin is healthy, seerr's setup will skip the wizard and just work. Open Jellyfin at port 8096 first to confirm it loads, then refresh seerr.
tomspark wrote:
Heads up — just shipped 1.6.89 with a fix for the original egress-check failure you reported here. Root cause was our curl -f flag: webhook.tomsparkbox.com is a Cloudflare Worker that only serves POST endpoints, so a bare GET returns 404, and -f was treating that 404 as a network failure. Dropped -f from both install.sh and sparkbox doctor. After sudo /opt/sparkbox/sparkbox update the check reads correctly. Nothing was functionally broken before — just misleading copy.
squid wrote:
[Docker] [OK] Docker daemon is accessible [OK] Docker version: Docker version 29.4.3, build 055a478 [OK] Docker Compose: 5.1.3 [Docker Socket] [OK] Docker socket exists at /var/run/docker.sock [OK] Docker socket is readable [User IDs] [INFO] Current user: root (UID=0, GID=0) [WARN] PUID=1000 does not match current UID=0 This can cause file permission issues with containers.
squid wrote:
That is all the the doctor output says
squid wrote:
The url did load but I dont have the bootstrap token
squid wrote:
Awesome! Tysm I really appreciate it, this is a great program you've made. Definitely makes the arr things less intimidating to a newbie
squid wrote:
I do have a question when it comes to the vpn if you don't mind answering, what makes the paid vpns different from the free ones (or are there free options?), like the vpns built into browsers or tailscale? Are you not able to use those for this application? (Sorry to be a bother, still trying to understand all of this lol)
squid wrote:
Ahh I see, Thank you!
squid wrote:
Back again D: I'm having trouble with setting up an indexer in prowlarr, the ones you showed in the video, eztv and the pirate bay, do not show up even when searching for them, and the indexers I've tried show this error (Unable to connect to indexer. This is typically caused by DNS/SSL issues. Check DNS settings, ensure IPv6 is working or disabled, consider using different DNS servers, or try a VPN/proxy if needed). I have surfshark running and it shows its working on the dashboard
squid wrote:
EZTV and ThePirateBay still do not show with proper capitalization and i do not have any filters on. I did have to add FlareSolverr, but it says disabled underneath it. You'll have to be more specific when you say try adding Nyaa lol, but the code outputs - at System.Net.Http.HttpConnectionPool.SendWithVersionDetectionAndRetryAsync(HttpRequestMessage request, Boolean async, Boolean doRequestAuth, CancellationToken cancellationToken) at System.Net.Http.AuthenticationHelper.SendWithAuthAsync(HttpRequestMessage request, Uri authUri, Boolean async, ICredentials credentials, Boolean preAuthenticate, Boolean isProxyAuth, Boolean doRequestAuth, HttpConnectionPool pool, CancellationToken cancellationToken) at System.Net.Http.DiagnosticsHandler.SendAsyncCore(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) at System.Net.Http.DecompressionHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) at System.Net.Http.HttpClient.<SendAsyncgCore|830(HttpRequestMessage request, HttpCompletionOption completionOption, CancellationTokenSource cts, Boolean disposeCts, CancellationTokenSource pendingRequestsCts, CancellationToken originalCancellationToken) at NzbDrone.Common.Http.Dispatchers.ManagedHttpDispatcher.GetResponseAsync(HttpRequest request, CookieContainer cookies) in ./NzbDrone.Common/Http/Dispatchers/ManagedHttpDispatcher.cs:line 120 at NzbDrone.Common.Http.HttpClient.ExecuteRequestAsync(HttpRequest request, CookieContainer cookieContainer) in ./NzbDrone.Common/Http/HttpClient.cs:line 171 at NzbDrone.Common.Http.HttpClient.ExecuteAsync(HttpRequest request) in ./NzbDrone.Common/Http/HttpClient.cs:line 70 at NzbDrone.Core.Indexers.IndexerHttpClient.ExecuteProxiedAsync(HttpRequest request, ProviderDefinition definition) in ./NzbDrone.Core/Indexers/IndexerHttpClient.cs:line 43 at NzbDrone.Core.Indexers.HttpIndexerBase1.<c.<<FetchIndexerResponseb570d.MoveNext() in ./NzbDrone.Core/Indexers/HttpIndexerBase.cs:line 665 --- End of stack trace from previous location --- at Polly.ResiliencePipeline.<c92.<<ExecuteAsyncb90d.MoveNext() --- End of stack trace from previous location --- at Polly.Outcome1.GetResultOrRethrow() at Polly.ResiliencePipeline.ExecuteAsyncTResult,TState at NzbDrone.Core.Indexers.HttpIndexerBase1.FetchIndexerResponse(IndexerRequest request) in ./NzbDrone.Core/Indexers/HttpIndexerBase.cs:line 664 at NzbDrone.Core.Indexers.HttpIndexerBase1.FetchPage(IndexerRequest request, IParseIndexerResponse parser) in ./NzbDrone.Core/Indexers/HttpIndexerBase.cs:line 587 at NzbDrone.Core.Indexers.HttpIndexerBase1.TestConnection() in ./NzbDrone.Core/Indexers/HttpIndexerBase.cs:line 764 [Warn] ProwlarrErrorPipeline: Invalid request Validation failed: -- : Unable to connect to indexer. This is typically caused by DNS/SSL issues. Check DNS settings, ensure IPv6 is working or disabled, consider using different DNS servers, or try a VPN/proxy if needed. See: 'https://wiki.servarr.com/prowlarr/troubleshootingdns-ssl-connection-issues' Resource temporarily unavailable (anidex.info:443) [Warn] IndexerDefinitionUpdateService: Error while getting indexer definitions, fallback to reading from disk. [v2.3.5.5327] System.Net.Http.HttpRequestException: Resource temporarily unavailable (indexers.prowlarr.com:443) --- System.Net.Sockets.SocketException (11): Resource temporarily unavailable at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.ThrowException(SocketError error, CancellationToken cancellationToken) at System.Net.Sockets.Socket.AwaitableSocketAsyncEventArgs.System.Threading.Tasks.Sources.IValueTaskSource.GetResult(Int16 token) at System.Net.Sockets.Socket.<ConnectAsyncgWaitForConnectWithCancellation|2850(AwaitableSocketAsyncEventArgs saea, ValueTask connectTask, CancellationToken cancellationToken) at NzbDrone.Common.Http.Dispatchers.ManagedHttpDispatcher.attemptConnection(AddressFamily addressFamily, SocketsHttpConnectionContext context, CancellationToken cancellationToken) in ./NzbDrone.Common/Http/Dispatchers/ManagedHttpDispatcher.cs:line 355 at NzbDrone.Common.Http.Dispatchers.ManagedHttpDispatcher.onConnect(SocketsHttpConnectionContext context, CancellationToken cancellationToken) in ./NzbDrone.Common/Http/Dispatchers/ManagedHttpDispatcher.cs:line 341 at System.Net.Http.HttpConnectionPool.ConnectToTcpHostAsync(String host, Int32 port, HttpRequestMessage initialRequest, Boolean async, CancellationToken cancellationToken) --- End of inner exception stack trace --- at System.Net.Http.HttpConnectionPool.ConnectToTcpHostAsync(String host, Int32 port, HttpRequestMessage initialRequest, Boolean async, CancellationToken cancellationToken) at System.Net.Http.HttpConnectionPool.ConnectAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) at System.Net.Http.HttpConnectionPool.AddHttp2ConnectionAsync(QueueItem queueItem) at System.Threading.Tasks.TaskCompletionSourceWithCancellation1.WaitWithCancellationAsync(CancellationToken cancellationToken) at System.Net.Http.HttpConnectionPool.SendWithVersionDetectionAndRetryAsync(HttpRequestMessage request, Boolean async, Boolean doRequestAuth, CancellationToken cancellationToken) at System.Net.Http.AuthenticationHelper.SendWithAuthAsync(HttpRequestMessage request, Uri authUri, Boolean async, ICredentials credentials, Boolean preAuthenticate, Boolean isProxyAuth, Boolean doRequestAuth, HttpConnectionPool pool, CancellationToken cancellationToken) at System.Net.Http.DiagnosticsHandler.SendAsyncCore(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) at System.Net.Http.DecompressionHandler.SendAsync(HttpRequestMessage request, Boolean async, CancellationToken cancellationToken) at System.Net.Http.HttpClient.<SendAsyncgCore|830(HttpRequestMessage request, HttpCompletionOption completionOption, CancellationTokenSource cts, Boolean disposeCts, CancellationTokenSource pendingRequestsCts, CancellationToken originalCancellationToken) at NzbDrone.Common.Http.Dispatchers.ManagedHttpDispatcher.GetResponseAsync(HttpRequest request, CookieContainer cookies) in ./NzbDrone.Common/Http/Dispatchers/ManagedHttpDispatcher.cs:line 120 at NzbDrone.Common.Http.HttpClient.ExecuteRequestAsync(HttpRequest request, CookieContainer cookieContainer) in ./NzbDrone.Common/Http/HttpClient.cs:line 171 at NzbDrone.Common.Http.HttpClient.ExecuteAsync(HttpRequest request) in ./NzbDrone.Common/Http/HttpClient.cs:line 70 at NzbDrone.Common.Http.HttpClient.GetAsyncT in ./NzbDrone.Common/Http/HttpClient.cs:line 393 at NzbDrone.Common.Http.HttpClient.GetT in ./NzbDrone.Common/Http/HttpClient.cs:line 401 at NzbDrone.Core.IndexerVersions.IndexerDefinitionUpdateService.All() in ./NzbDrone.Core/IndexerVersions/IndexerDefinitionUpdateService.cs:line 95
tomspark wrote:
Two things to fix: 1) Enable FlareSolverr. You added it but it shows disabled — click on it, toggle Enabled to ON, click Test (should go green), Save. Without that, every Cloudflare-protected indexer fails connection. 2) Resource temporarily unavailable (indexers.prowlarr.com:443) is the real culprit — Prowlarr can't reach its OWN indexer-definitions catalog from inside the gluetun network namespace. That's why EZTV/ThePirateBay don't appear in search either (catalog never refreshed). Network issue, not an indexer issue. Run these on the host so I can pin it: sudo docker exec sb-prowlarr curl -m 10 -sI https://indexers.prowlarr.com 2&1 | head -3 sudo docker logs sb-gluetun --tail 30 First tells me if Prowlarr can reach the catalog at all. Second tells me what gluetun's doing — Resource temporarily unavailable usually means gluetun's tunnel is bouncing or Surfshark hasn't fully come up. Paste both.
squid wrote:
I have no option to endable FlareSolverr it only shows the name, tags, and host. The code outputs 2026-05-10T00:18:04Z INFO [wireguard] Using available kernelspace implementation 2026-05-10T00:18:04Z INFO [wireguard] Connecting to 92.119.16.113:51820 2026-05-10T00:18:04Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-05-10T00:18:10Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-05-10T00:18:10Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-05-10T00:18:10Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-05-10T00:18:10Z INFO [vpn] stopping 2026-05-10T00:18:10Z INFO [vpn] starting 2026-05-10T00:18:10Z INFO [firewall] allowing VPN connection... 2026-05-10T00:18:10Z INFO [wireguard] Using available kernelspace implementation 2026-05-10T00:18:10Z INFO [wireguard] Connecting to 156.146.54.69:51820 2026-05-10T00:18:10Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-05-10T00:18:16Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-05-10T00:18:16Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-05-10T00:18:16Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-05-10T00:18:16Z INFO [vpn] stopping 2026-05-10T00:18:17Z INFO [vpn] starting 2026-05-10T00:18:17Z INFO [firewall] allowing VPN connection... 2026-05-10T00:18:17Z INFO [wireguard] Using available kernelspace implementation 2026-05-10T00:18:17Z INFO [wireguard] Connecting to 82.102.31.3:51820 2026-05-10T00:18:17Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-05-10T00:18:23Z WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-05-10T00:18:23Z INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-05-10T00:18:23Z INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-05-10T00:18:23Z INFO [vpn] stopping 2026-05-10T00:18:23Z INFO [vpn] starting 2026-05-10T00:18:23Z INFO [firewall] allowing VPN connection... 2026-05-10T00:18:23Z INFO [wireguard] Using available kernelspace implementation 2026-05-10T00:18:23Z INFO [wireguard] Connecting to 195.242.212.147:51820 2026-05-10T00:18:23Z INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working.
squid wrote:
Ok I got gluetun to stop doing the restart loop, switched to openvpn. Now the banner in sparkbox says VPN has a problem after I changed the settings to match with openvpn
squid wrote:
The first code fails to output anything, the result from the second is - 2026-05-10T00:46:08Z INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AFINET]185.141.119.50:1194 2026-05-10T00:46:08Z INFO [openvpn] UDPv4 link local: (not bound) 2026-05-10T00:46:08Z INFO [openvpn] UDPv4 link remote: [AFINET]185.141.119.50:1194 2026-05-10T00:46:08Z INFO [openvpn] [us-dtw-v127.prod.surfshark.com] Peer Connection Initiated with [AFINET]185.141.119.50:1194 2026-05-10T00:46:09Z ERROR [openvpn] AUTH: Received control message: AUTHFAILED Your credentials might be wrong 🤨 2026-05-10T00:46:09Z INFO [openvpn] SIGUSR1[soft,auth-failure] received, process restarting 2026-05-10T00:46:19Z INFO [openvpn] TCP/UDP: Preserving recently used remote address: [AFINET]185.141.119.50:1194 2026-05-10T00:46:19Z INFO [openvpn] UDPv4 link local: (not bound) 2026-05-10T00:46:19Z INFO [openvpn] UDPv4 link remote: [AFINET]185.141.119.50:1194 2026-05-10T00:46:20Z INFO [openvpn] [us-dtw-v127.prod.surfshark.com] Peer Connection Initiated with [AFINET]185.141.119.50:1194 2026-05-10T00:46:21Z ERROR [openvpn] AUTH: Received control message: AUTHFAILED Your credentials might be wrong 🤨 2026-05-10T00:46:21Z INFO [openvpn] SIGUSR1[soft,auth-failure] received, process restarting
squid wrote:
Unfortunately its not that as I already had the service credentials put in correctly. Should I try resetting the credentials and re inputting them?
squid wrote:
Ya it definitely wasn't my email lol, I tried regenerating the credentials and editing them but same problem. I'm at a loss lol
squid wrote:
Surfshark works on my phone. I'm done toying with it tonight, might come back to it tomorrow. I really appreciate all the help though, I definitely learned a bit, have a good one!👍
squid wrote:
I've made progress. I got surfshark running properly now and the tunnel is up, traffic going through, i see eztv and pirate bay yada yada. I'm now having a problem with qbittorrent when I open it through sparkbox it opens a new tab and just says unathorized at the top left of the screen, also, sparkbox says the media thing didn't finish setting up or something so when I open seerr it wants me to go through all the setup
squid wrote:
I'm still getting the unauthorized error after updating and even tried restarting a few times
squid wrote:
Any fix for the unathorized error? I'm still getting it even after updates
tomspark wrote:
The qBit "unauthorized" is a different bug from the egress check v1.6.89 fixed — sorry that wasn't clearer. Quick diag, what's showing unauthorized: - qBit's web UI itself in your browser? (the v1.6.80 fix handles this — was it still failing after sudo sparkbox update?) - Sonarr/Radarr's Settings → Download Clients page red? - Prowlarr's indexer test? If you can paste the exact error wording or a screenshot, I'll narrow it down. Likeliest one-shot fix path either way: sudo /opt/sparkbox/sparkbox restart media (cycles the whole arr stack so each app re-handshakes with qBit). After that, hit qBit's web UI at http://<NAS-IP:8089 and confirm whether the login screen accepts the password from state/qbittorrent-admin-password.txt.