release: publish verified signed 1.8.22 OTA and app catalog

This commit is contained in:
archipelago
2026-10-01 06:15:32 -04:00
parent 0be7aee49d
commit 2e72b38778
5 changed files with 523 additions and 52 deletions
+10 -10
View File
@@ -1,6 +1,6 @@
# Next OTA and raw ISO after 1.8.21 # Next OTA and raw ISO after 1.8.21
**Status: implementation and final OTA/raw ISO acceptance passed; draft upload verification and offline signing/publication remain.** **Status: final OTA/raw ISO acceptance, signatures and Gitea public artifact verification passed; fleet promotion and ngit publication are being completed.**
Current acceptance evidence: [1.8.22 release acceptance](release-1.8.22-acceptance.md). Current acceptance evidence: [1.8.22 release acceptance](release-1.8.22-acceptance.md).
The chronological notes below retain earlier failures and superseded candidates; The chronological notes below retain earlier failures and superseded candidates;
@@ -35,12 +35,12 @@ See the Framework incident and 1.8.21 execution records for evidence/limits.
| Task | Implemented/verified | Remaining before release | | Task | Implemented/verified | Remaining before release |
| --- | --- | --- | | --- | --- | --- |
| X250 Bitcoin picker | Inline choices; actual Chromium kiosk selection, readability and pruning layout passed | Include in final UI/build checks | | X250 Bitcoin picker | Inline choices; actual Chromium kiosk selection, readability and pruning layout passed | Final UI/build checks passed |
| App disappearance/readiness | Durable inventory and safe lifecycle repair; delayed HTTP and desktop/mobile hard-refresh checks passed | Final lifecycle/reboot gate on candidate | | App disappearance/readiness | Durable inventory and safe lifecycle repair; delayed HTTP and desktop/mobile hard-refresh checks passed | Final candidate lifecycle, hard-refresh and stability checks passed |
| X250 GitWorkshop/Nginx | Missing build contexts restored, dependency/build checks and live UI passed; Nginx slow pull diagnosed; truthful progress label | Verify both artifact payloads contain all build contexts | | X250 GitWorkshop/Nginx | Missing build contexts restored, dependency/build checks and live UI passed; Nginx slow pull diagnosed; truthful progress label | OTA and ISO build-context/content checks passed |
| PRs 161/162 | Reviewed, repaired, merged/closed normally; combined regression suite passed | Funded Tor-only candidate purchase, retained change, refund, Files bytes and cached repeat passed; include in signed artifacts | | PRs 161/162 | Reviewed, repaired, merged/closed normally; combined regression suite passed | Funded Tor-only candidate purchase, retained change, refund, Files bytes and cached repeat passed; included in signed artifacts |
| Gitea/Portainer | Root cause confirmed; source network/backup/retry/catalog changes; real X250 routing repair and restart verified; private Git, SSH, LFS, registry and browser fixture checks passed | Automatic migration, scratch restore, failed-start recovery and reverse installation order passed. Operator confirms production site works through Portainer; production host reboot also preserved network/Git/Compose access; final candidate delivery and release checks remain | | Gitea/Portainer | Root cause confirmed; source network/backup/retry/catalog changes; real X250 routing repair and restart verified; private Git, SSH, LFS, registry and browser fixture checks passed | Automatic migration, scratch restore, failed-start recovery and reverse installation order passed. Operator confirms production site works through Portainer; production host reboot also preserved network/Git/Compose access; final candidate delivery and integration checks passed |
| Angor headless store service | Implemented standard Mempool adapter and separate optional relay, official logo, headless store entries and declarative dependency guard. API security/outage/DNS tests and five relay lifecycle cycles passed | Final candidate prerequisite/install acceptance, management restart/reboot checks and signed catalog delivery; real indexing on dev waits for Bitcoin sync | | Angor headless store service | Implemented standard Mempool adapter and separate optional relay, official logo, headless store entries and declarative dependency guard. API security/outage/DNS tests and five relay lifecycle cycles passed | Final candidate prerequisite/API, lifecycle and catalog checks passed; real indexing on dev waits for Bitcoin sync |
Durable payment receipts after a lost seller response remain a separately Durable payment receipts after a lost seller response remain a separately
recorded design follow-up. Preserve the truthful unconfirmed-refund warning and recorded design follow-up. Preserve the truthful unconfirmed-refund warning and
@@ -56,16 +56,16 @@ completed. See PR review for the accepted scope and coverage limits.
- [x] Commit and push completed source changes to git and ngit. - [x] Commit and push completed source changes to git and ngit.
- [x] Run final backend/UI/regression/release gates on the final source; inspect - [x] Run final backend/UI/regression/release gates on the final source; inspect
skipped tests and report actual hardware/runtime coverage. skipped tests and report actual hardware/runtime coverage.
- [ ] Prepare compatible signed app catalog; old runtimes must not apply a - [x] Prepare compatible signed app catalog; old runtimes must not apply a
migration before they have backup/recovery support. migration before they have backup/recovery support.
- [ ] Version/changelog and OTA payload prepared, validated and signed by user. - [x] Version/changelog and OTA payload prepared, validated and signed by user.
- [x] Raw ISO built; payload hashes/content verified; full installation and - [x] Raw ISO built; payload hashes/content verified; full installation and
installed-system boot tested in QEMU/KVM without network. installed-system boot tested in QEMU/KVM without network.
- [ ] User signs ISO checksums; publish OTA and ISO plus verification files on - [ ] User signs ISO checksums; publish OTA and ISO plus verification files on
git and ngit; independently read back hashes and update discovery. git and ngit; independently read back hashes and update discovery.
- [ ] Provide LAN scp command for the new raw ISO. - [ ] Provide LAN scp command for the new raw ISO.
Latest backend source verification: 1,609 passed, zero failed, four existing Latest backend source verification: 1,617 passed, zero failed, four existing
ignored tests. This is one layer of evidence, not a substitute for live gates. ignored tests. This is one layer of evidence, not a substitute for live gates.
## Angor verification — 2026-09-30 ## Angor verification — 2026-09-30
+10 -4
View File
@@ -76,8 +76,14 @@ cold boot above is the successful acceptance run.
The dev native Bitcoin/LND identity/start-time baseline also remained unchanged The dev native Bitcoin/LND identity/start-time baseline also remained unchanged
after the ISO build and VM acceptance. after the ISO build and VM acceptance.
## Publication pending ## Publication verification
Artifacts are staged in a draft release. Upload/readback verification and the All three operator signatures verify against the pinned release root. The five
operator's offline signatures must complete before promoting the fleet manifest Gitea assets match independent server-side SHA-256 checks. Both OTA components
and signed app catalog or publishing the Git/ngit releases. also passed complete public HTTPS downloads with exact hashes and sizes; the
raw ISO passed public size/range checks and both checksum sidecars read back
exactly. Only after these checks were the signed OTA manifest and compatible
app catalog promoted. The release tag identifies the tested source above.
Git/ngit publication and final update-discovery readback are recorded in the
release tracker after their completion.
+33 -17
View File
@@ -1,30 +1,46 @@
{ {
"changelog": [ "changelog": [
"Fixed Bitcoin and other containers being forcibly stopped after ten seconds during managed updates and restarts.", "Fixed Nginx Proxy Manager launch readiness choosing a proxy listener instead of its admin port after container recreation.",
"Existing installations now receive the same graceful shutdown allowance as new containers, without restarting apps just to apply this setting.", "Network diagnostic failures no longer stop all apps or rebuild shared container networking.",
"Prevented unnecessary Lightning restarts when Bitcoin has stayed running; dependency restarts now require an observed Bitcoin container change.", "Prevented orphaned companion dashboards from repeatedly reinstalling themselves after their backend app was removed.",
"Includes the Cashu payment, optional Bitcoin pruning, Lightning readiness, and explorer improvements from 1.8.20." "Fixed companion dashboard builds still referencing a retired image registry.",
"Fixed Angor Indexer health checks choosing IPv6 localhost for an IPv4 listener and unnecessarily restarting the working service.",
"Prevented false app restarts by probing each published port at its actual bind address; Nginx Proxy Manager now checks its internal admin API.",
"Added a backed-up migration for the recognized legacy Nginx Proxy Manager tunnel/LND port conflict in both OTA and ISO startup paths.",
"Checked Bitcoin and Electrum companion dashboards instead of backend protocol ports, preserving dashboard access during initial sync.",
"Removed web-interface waiting messages from headless services such as Phoenixd and clarified which interface is unavailable for launchable apps.",
"Finished runtime app-file promotion before manifest loading, preventing startup catalog refresh from forgetting disk-only apps.",
"Named the app in compact readiness messages and kept app-card actions aligned at the bottom.",
"Removed duplicate Mempool cards caused by frontend container aliases in restored inventory.",
"Kept installed apps visible through restarts and hard refreshes, and delayed app launches until their web interface is ready.",
"Made Bitcoin version selection readable and usable in the ThinkPad kiosk, above the pruning settings.",
"Restored GitWorkshop build files in installation/update payloads and made slow image-pull progress clearer.",
"Fixed same-node Gitea access from Portainer, with persistent runtime migration, state backups and recovery after failed restarts.",
"Preserved Gitea configuration and SSH operation during fresh setup and upgrades.",
"Improved paid-file delivery, saved-file permissions and repeat-download compatibility; verified Tor-only payment with change, rejection refunds and free repeat downloads.",
"Added a headless Angor Indexer service using the existing Mempool/ElectrumX stack, and an optional separate Angor relay.",
"Prevented manifest command arguments containing apostrophes from being corrupted in generated services."
], ],
"components": [ "components": [
{ {
"current_version": "1.8.21-alpha", "current_version": "1.8.22-alpha",
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago", "download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.22-alpha/archipelago",
"name": "archipelago", "name": "archipelago",
"new_version": "1.8.21-alpha", "new_version": "1.8.22-alpha",
"sha256": "ff602e85f340aff7e43d9d94f7f84f11f713735c964c0d8ba150e23b065c30eb", "sha256": "e108b78bbbd21cb7d5d47c8d0b7b9b19b63fb0c44678773603202440ec7d6f5b",
"size_bytes": 64748176 "size_bytes": 65627704
}, },
{ {
"current_version": "1.8.21-alpha", "current_version": "1.8.22-alpha",
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago-frontend-1.8.21-alpha.tar.gz", "download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.22-alpha/archipelago-frontend-1.8.22-alpha.tar.gz",
"name": "archipelago-frontend-1.8.21-alpha.tar.gz", "name": "archipelago-frontend-1.8.22-alpha.tar.gz",
"new_version": "1.8.21-alpha", "new_version": "1.8.22-alpha",
"sha256": "6c0842ec83a440269a353808a4cf154174f5232c9989b4a5448bc6486e1d0620", "sha256": "2da485a2da75ff2fbe4aba52d6f217150e303be43a031723480c9c4ff9d43f41",
"size_bytes": 97152546 "size_bytes": 98131119
} }
], ],
"release_date": "2026-09-30", "release_date": "2026-09-30",
"signature": "2ba21dde08284a13f511f11f0b925f09a56c1b36e40424558601b9ab6beea17edfa316e0baa51474bf084fd4da25429ec35a77d9a831554b309845c8226d4f0d", "signature": "34e9e3902d5960c977b528c4edbb4366ad862f761076755632296840604c8a84ae1bbb503d8d26b2fe7622ca1eccfaa15cb8d23935bcec6dbecdaf6c53f7f50e",
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT", "signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
"version": "1.8.21-alpha" "version": "1.8.22-alpha"
} }
+437 -4
View File
@@ -141,6 +141,198 @@
}, },
"version": "1.23.0" "version": "1.23.0"
}, },
"angor-indexer": {
"manifest": {
"app": {
"bitcoin_integration": {
"pruning_support": false,
"rpc_access": "none",
"sync_required": true
},
"category": "money",
"container": {
"image": "source.archipelago-foundation.org/chaum/angor-indexer:1.0.1",
"network": "archy-net",
"pull_policy": "if-not-present"
},
"dependencies": [
{
"app_id": "mempool-api",
"version": ">=3.0.0"
},
"bitcoin:archival"
],
"description": "Headless Bitcoin indexer endpoint for Angor. Reuses this node’s Mempool and Electrum index; requires a synced, unpruned Bitcoin node. Add this service’s address as the custom indexer in Angor settings. A relay is optional and installed separately.",
"health_check": {
"endpoint": "http://127.0.0.1:8080",
"interval": "30s",
"path": "/health",
"retries": 3,
"timeout": "8s",
"type": "http"
},
"id": "angor-indexer",
"install_prerequisites": [
"mempool-api"
],
"interfaces": {
"main": {
"description": "Use this origin as Angor’s custom mainnet indexer URL. HTTPS is required for browser clients.",
"name": "Angor Indexer API",
"path": "/",
"port": 8998,
"protocol": "http",
"type": "api"
}
},
"metadata": {
"features": [
"Angor mainnet API",
"Reuses existing Mempool indexing",
"No separate blockchain database",
"Optional independent relay"
],
"icon": "/assets/img/app-icons/angor-green.png",
"repo": "https://github.com/block-core/angor",
"tier": "optional"
},
"name": "Angor Indexer",
"ports": [
{
"auth": "open",
"auth_rationale": "Public Bitcoin chain-data API and validated transaction broadcast for Angor clients; no wallet keys or node RPC credentials are exposed. Browser cookie login would break machine clients.",
"bind": "127.0.0.1",
"container": 8080,
"host": 8998,
"protocol": "tcp"
}
],
"resources": {
"cpu_limit": 1,
"disk_limit": "128Mi",
"memory_limit": "128Mi"
},
"security": {
"capabilities": [],
"network_policy": "isolated",
"no_new_privileges": true,
"readonly_root": true,
"user": 101
},
"upstream": {
"kind": "github",
"repo": "block-core/angor"
},
"version": "1.0.1"
}
},
"version": "1.0.1"
},
"angor-relay": {
"manifest": {
"app": {
"category": "nostr",
"container": {
"image": "source.archipelago-foundation.org/chaum/angor-relay:1.1.2",
"pull_policy": "if-not-present"
},
"dependencies": [
{
"storage": "5Gi"
}
],
"description": "Optional dedicated Nostr relay for Angor project metadata. Separate storage and access settings keep the node’s internal relay private. Add this service’s address to Angor’s relay settings; use WSS for browser clients.",
"files": [
{
"content": "##\n## Default strfry config\n##\n\n# Directory that contains the strfry LMDB database (restart required)\ndb = \"./strfry-db/\"\n\ndbParams {\n # Maximum number of threads/processes that can simultaneously have LMDB transactions open (restart required)\n maxreaders = 256\n\n # Size of mmap() to use when loading LMDB (default is 10TB, does *not* correspond to disk-space used) (restart required)\n mapsize = 10995116277760\n\n # Disables read-ahead when accessing the LMDB mapping. Reduces IO activity when DB size is larger than RAM. (restart required)\n noReadAhead = false\n}\n\nevents {\n # Maximum size of normalised JSON, in bytes\n maxEventSize = 65536\n\n # Events newer than this will be rejected\n rejectEventsNewerThanSeconds = 900\n\n # Events older than this will be rejected\n rejectEventsOlderThanSeconds = 94608000\n\n # Ephemeral events older than this will be rejected\n rejectEphemeralEventsOlderThanSeconds = 60\n\n # Ephemeral events will be deleted from the DB when older than this\n ephemeralEventsLifetimeSeconds = 300\n\n # Maximum number of tags allowed\n maxNumTags = 2000\n\n # Maximum size for tag values, in bytes\n maxTagValSize = 1024\n}\n\nrelay {\n # Interface to listen on. Use 0.0.0.0 to listen on all interfaces (restart required)\n bind = \"0.0.0.0\"\n\n # Port to open for the nostr websocket protocol (restart required)\n port = 7777\n\n # Set OS-limit on maximum number of open files/sockets (if 0, don't attempt to set) (restart required)\n nofiles = 0\n\n # HTTP header that contains the client's real IP, before reverse proxying (ie x-real-ip) (MUST be all lower-case)\n realIpHeader = \"\"\n\n info {\n # NIP-11: Name of this server. Short/descriptive (< 30 characters)\n name = \"Angor Relay\"\n\n # NIP-11: Detailed information about relay, free-form\n description = \"Dedicated public relay for Angor project metadata.\"\n\n # NIP-11: Administrative nostr pubkey, for contact purposes\n pubkey = \"\"\n\n # NIP-11: Alternative administrative contact (email, website, etc)\n contact = \"\"\n\n # NIP-11: URL pointing to an image to be used as an icon for the relay\n icon = \"\"\n\n # List of supported lists as JSON array, or empty string to use default. Example: \"[1,2]\"\n nips = \"\"\n }\n\n # Maximum accepted incoming websocket frame size (should be larger than max event) (restart required)\n maxWebsocketPayloadSize = 131072\n\n # Maximum number of filters allowed in a REQ\n maxReqFilterSize = 200\n\n # Websocket-level PING message frequency (should be less than any reverse proxy idle timeouts) (restart required)\n autoPingSeconds = 55\n\n # If TCP keep-alive should be enabled (detect dropped connections to upstream reverse proxy)\n enableTcpKeepalive = false\n\n # How much uninterrupted CPU time a REQ query should get during its DB scan\n queryTimesliceBudgetMicroseconds = 10000\n\n # Maximum records that can be returned per filter\n maxFilterLimit = 500\n\n # Maximum number of subscriptions (concurrent REQs) a connection can have open at any time\n maxSubsPerConnection = 20\n\n writePolicy {\n # If non-empty, path to an executable script that implements the writePolicy plugin logic\n plugin = \"\"\n }\n\n compression {\n # Use permessage-deflate compression if supported by client. Reduces bandwidth, but slight increase in CPU (restart required)\n enabled = true\n\n # Maintain a sliding window buffer for each connection. Improves compression, but uses more memory (restart required)\n slidingWindow = true\n }\n\n logging {\n # Dump all incoming messages\n dumpInAll = false\n\n # Dump all incoming EVENT messages\n dumpInEvents = false\n\n # Dump all incoming REQ/CLOSE messages\n dumpInReqs = false\n\n # Log performance metrics for initial REQ database scans\n dbScanPerf = false\n\n # Log reason for invalid event rejection? Can be disabled to silence excessive logging\n invalidEvents = true\n }\n\n numThreads {\n # Ingester threads: route incoming requests, validate events/sigs (restart required)\n ingester = 3\n\n # reqWorker threads: Handle initial DB scan for events (restart required)\n reqWorker = 3\n\n # reqMonitor threads: Handle filtering of new events (restart required)\n reqMonitor = 3\n\n # negentropy threads: Handle negentropy protocol messages (restart required)\n negentropy = 2\n }\n\n negentropy {\n # Support negentropy protocol messages\n enabled = true\n\n # Maximum records that sync will process before returning an error\n maxSyncEvents = 1000000\n }\n}\n",
"overwrite": false,
"path": "/var/lib/archipelago/angor-relay-config/angor-relay.conf"
}
],
"health_check": {
"endpoint": "http://127.0.0.1:7777",
"interval": "30s",
"path": "/health",
"retries": 3,
"timeout": "5s",
"type": "http"
},
"id": "angor-relay",
"interfaces": {
"main": {
"description": "Nostr WebSocket endpoint; use ws:// for LAN or wss:// through your HTTPS domain.",
"name": "Angor Relay",
"path": "/",
"port": 8091,
"protocol": "http",
"type": "api"
}
},
"metadata": {
"features": [
"Angor project metadata",
"Separate from the node relay",
"Persistent Nostr event storage"
],
"icon": "/assets/img/app-icons/angor-green.png",
"repo": "https://github.com/hoytech/strfry",
"tier": "optional"
},
"name": "Angor Relay",
"nostr_integration": {
"monetization_enabled": false,
"relay_type": "public"
},
"ports": [
{
"auth": "open",
"auth_rationale": "Dedicated public Nostr relay for Angor project metadata; strfry verifies event signatures. It has separate storage from the private node relay and no wallet or node credentials.",
"bind": "127.0.0.1",
"container": 7777,
"host": 8091,
"protocol": "tcp"
}
],
"resources": {
"cpu_limit": 1,
"disk_limit": "5Gi",
"memory_limit": "512Mi"
},
"security": {
"apparmor_profile": "nostr-relay",
"capabilities": [],
"network_policy": "isolated",
"no_new_privileges": true,
"readonly_root": true,
"seccomp_profile": "default"
},
"upstream": {
"kind": "github",
"repo": "hoytech/strfry"
},
"version": "1.1.2",
"volumes": [
{
"options": [
"rw"
],
"source": "/var/lib/archipelago/angor-relay",
"target": "/app/strfry-db",
"type": "bind"
},
{
"options": [
"ro"
],
"source": "/var/lib/archipelago/angor-relay-config/angor-relay.conf",
"target": "/etc/strfry.conf",
"type": "bind"
}
]
}
},
"version": "1.1.2"
},
"archipelago-source": { "archipelago-source": {
"manifest": { "manifest": {
"app": { "app": {
@@ -2195,6 +2387,142 @@
] ]
} }
}, },
"manifest_variants": [
{
"manifest": {
"app": {
"backup_before_runtime_change": true,
"category": "development",
"container": {
"image": "source.archipelago-foundation.org/lfg2025/gitea:1.27.3",
"pull_policy": "if-not-present"
},
"dependencies": [
{
"storage": "50Gi"
}
],
"description": "Self-hosted Git service with built-in container registry, CI/CD, and package hosting.",
"environment": [
"GITEA__database__DB_TYPE=sqlite3",
"GITEA__server__SSH_PORT=2222",
"GITEA__server__SSH_LISTEN_PORT=22",
"GITEA__server__LFS_START_SERVER=true",
"GITEA__packages__ENABLED=true",
"GITEA__packages__LIMIT_TOTAL_OWNER_SIZE=-1",
"GITEA__packages__LIMIT_SIZE_CONTAINER=-1",
"GITEA__repository_0x2Erelease__FILE_MAX_SIZE=10240",
"GITEA__repository_0x2Erelease__MAX_FILES=20",
"GITEA__repository__ENABLE_PUSH_CREATE_USER=true",
"GITEA__repository__ENABLE_PUSH_CREATE_ORG=true"
],
"files": [
{
"content": "[server]\nDOMAIN = {{HOST_IP}}\nSSH_DOMAIN = {{HOST_IP}}\nROOT_URL = http://{{HOST_IP}}:3001/\n",
"overwrite": false,
"path": "/var/lib/archipelago/gitea/data/gitea/conf/app.ini"
}
],
"health_check": {
"endpoint": "http://localhost:3000",
"interval": "120s",
"path": "/",
"retries": 5,
"timeout": "30s",
"type": "http"
},
"id": "gitea",
"interfaces": {
"main": {
"description": "Gitea web interface",
"name": "Web UI",
"path": "/",
"port": 3001,
"protocol": "http",
"type": "ui"
}
},
"metadata": {
"features": [
"Git repositories with web UI",
"Built-in container/package registry",
"Issue tracking and pull requests",
"CI/CD via Gitea Actions",
"Lightweight SQLite deployment"
],
"icon": "/assets/img/app-icons/gitea.svg",
"launch": {
"open_in_new_tab": true
},
"repo": "https://gitea.com",
"tier": "optional"
},
"name": "Gitea",
"ports": [
{
"auth": "open",
"auth_rationale": "Gitea enforces its own account login on every page and API route; git clients authenticate with basic-auth/tokens and cannot complete a browser login challenge.",
"bind": "127.0.0.1",
"container": 3000,
"host": 3001,
"protocol": "tcp"
},
{
"auth": "none",
"auth_rationale": "Git over SSH, authenticated by the user's own SSH keypair. Not HTTP, so the gate cannot serve a login page here.",
"container": 22,
"host": 2222,
"protocol": "tcp"
}
],
"resources": {
"disk_limit": "50Gi",
"memory_limit": "256Mi"
},
"security": {
"capabilities": [
"CHOWN",
"FOWNER",
"SETUID",
"SETGID",
"DAC_OVERRIDE",
"NET_BIND_SERVICE",
"SYS_CHROOT"
],
"network_policy": "bridge",
"no_new_privileges": false,
"readonly_root": false
},
"upstream": {
"kind": "github",
"repo": "go-gitea/gitea"
},
"version": "1.27.3",
"volumes": [
{
"options": [
"rw"
],
"source": "/var/lib/archipelago/gitea/data",
"target": "/data",
"type": "bind"
},
{
"options": [
"rw"
],
"source": "/var/lib/archipelago/gitea/config",
"target": "/etc/gitea",
"type": "bind"
}
]
}
},
"requires": [
"runtime-migration-backup-v1"
]
}
],
"version": "1.27.3" "version": "1.27.3"
}, },
"grafana": { "grafana": {
@@ -4091,11 +4419,11 @@
"description": "Reverse proxy with SSL. Beautiful web interface for managing proxies. On a node, this manages its admin UI and upstream configuration — the proxy's own :80/:443 listeners are not published (the node's web server owns those ports).", "description": "Reverse proxy with SSL. Beautiful web interface for managing proxies. On a node, this manages its admin UI and upstream configuration — the proxy's own :80/:443 listeners are not published (the node's web server owns those ports).",
"environment": [], "environment": [],
"health_check": { "health_check": {
"endpoint": "localhost:81", "endpoint": "http://127.0.0.1:81/api/",
"interval": "30s", "interval": "30s",
"retries": 3, "retries": 3,
"timeout": "5s", "timeout": "5s",
"type": "tcp" "type": "http"
}, },
"id": "nginx-proxy-manager", "id": "nginx-proxy-manager",
"interfaces": { "interfaces": {
@@ -4996,6 +5324,111 @@
] ]
} }
}, },
"manifest_variants": [
{
"manifest": {
"app": {
"backup_before_runtime_change": true,
"category": "development",
"container": {
"data_uid": "1000:1000",
"image": "source.archipelago-foundation.org/lfg2025/portainer:2.45.0",
"network": "slirp4netns",
"pull_policy": "if-not-present"
},
"dependencies": [
{
"storage": "1Gi"
}
],
"description": "Container management web UI for the local Podman socket.",
"environment": [],
"id": "portainer",
"interfaces": {
"main": {
"description": "Portainer web interface",
"name": "Web UI",
"path": "/",
"port": 9000,
"protocol": "http",
"type": "ui"
}
},
"metadata": {
"features": [
"Container management dashboard",
"Local Podman socket access",
"Compose stack storage"
],
"icon": "/assets/img/app-icons/portainer.webp",
"launch": {
"open_in_new_tab": true
},
"tier": "optional"
},
"name": "Portainer",
"ports": [
{
"auth": "gated",
"bind": "127.0.0.1",
"container": 9000,
"host": 9000,
"protocol": "tcp"
}
],
"resources": {
"disk_limit": "1Gi",
"memory_limit": "256Mi"
},
"security": {
"capabilities": [
"CHOWN",
"SETUID",
"SETGID",
"DAC_OVERRIDE"
],
"network_policy": "isolated",
"no_new_privileges": true,
"readonly_root": false
},
"upstream": {
"kind": "github",
"repo": "portainer/portainer"
},
"version": "2.45.0",
"volumes": [
{
"options": [
"rw"
],
"source": "/var/lib/archipelago/portainer",
"target": "/data",
"type": "bind"
},
{
"options": [
"rw"
],
"source": "/var/lib/archipelago/portainer/compose",
"target": "/data/compose",
"type": "bind"
},
{
"options": [
"rw"
],
"source": "/run/user/1000/podman/podman.sock",
"target": "/var/run/docker.sock",
"type": "bind"
}
]
}
},
"requires": [
"runtime-migration-backup-v1"
]
}
],
"version": "2.45.0" "version": "2.45.0"
}, },
"router": { "router": {
@@ -5525,7 +5958,7 @@
"tag": "NOSTR IDENTITY // YOUR NODE" "tag": "NOSTR IDENTITY // YOUR NODE"
}, },
"schema": 1, "schema": 1,
"signature": "bbcc938b855c1cb5d803e4510e1aac3259fbf3eabf6f36294c7773634047a3d5edb5b37a17d01d62d1407e5701c62853e15e20e15cc7f486b8975b22eeb94c07", "signature": "66b78a5bc60992222b01ae901c5f4a40802667332a5ae47bdad7f34e149669261012ff6fd543478a4f318e850b0339be497af71a50266d829395a872ad386704",
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT", "signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
"storefront": { "storefront": {
"popular": [ "popular": [
@@ -5551,5 +5984,5 @@
} }
] ]
}, },
"updated": "2026-09-29" "updated": "2026-09-30"
} }
+33 -17
View File
@@ -1,30 +1,46 @@
{ {
"changelog": [ "changelog": [
"Fixed Bitcoin and other containers being forcibly stopped after ten seconds during managed updates and restarts.", "Fixed Nginx Proxy Manager launch readiness choosing a proxy listener instead of its admin port after container recreation.",
"Existing installations now receive the same graceful shutdown allowance as new containers, without restarting apps just to apply this setting.", "Network diagnostic failures no longer stop all apps or rebuild shared container networking.",
"Prevented unnecessary Lightning restarts when Bitcoin has stayed running; dependency restarts now require an observed Bitcoin container change.", "Prevented orphaned companion dashboards from repeatedly reinstalling themselves after their backend app was removed.",
"Includes the Cashu payment, optional Bitcoin pruning, Lightning readiness, and explorer improvements from 1.8.20." "Fixed companion dashboard builds still referencing a retired image registry.",
"Fixed Angor Indexer health checks choosing IPv6 localhost for an IPv4 listener and unnecessarily restarting the working service.",
"Prevented false app restarts by probing each published port at its actual bind address; Nginx Proxy Manager now checks its internal admin API.",
"Added a backed-up migration for the recognized legacy Nginx Proxy Manager tunnel/LND port conflict in both OTA and ISO startup paths.",
"Checked Bitcoin and Electrum companion dashboards instead of backend protocol ports, preserving dashboard access during initial sync.",
"Removed web-interface waiting messages from headless services such as Phoenixd and clarified which interface is unavailable for launchable apps.",
"Finished runtime app-file promotion before manifest loading, preventing startup catalog refresh from forgetting disk-only apps.",
"Named the app in compact readiness messages and kept app-card actions aligned at the bottom.",
"Removed duplicate Mempool cards caused by frontend container aliases in restored inventory.",
"Kept installed apps visible through restarts and hard refreshes, and delayed app launches until their web interface is ready.",
"Made Bitcoin version selection readable and usable in the ThinkPad kiosk, above the pruning settings.",
"Restored GitWorkshop build files in installation/update payloads and made slow image-pull progress clearer.",
"Fixed same-node Gitea access from Portainer, with persistent runtime migration, state backups and recovery after failed restarts.",
"Preserved Gitea configuration and SSH operation during fresh setup and upgrades.",
"Improved paid-file delivery, saved-file permissions and repeat-download compatibility; verified Tor-only payment with change, rejection refunds and free repeat downloads.",
"Added a headless Angor Indexer service using the existing Mempool/ElectrumX stack, and an optional separate Angor relay.",
"Prevented manifest command arguments containing apostrophes from being corrupted in generated services."
], ],
"components": [ "components": [
{ {
"current_version": "1.8.21-alpha", "current_version": "1.8.22-alpha",
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago", "download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.22-alpha/archipelago",
"name": "archipelago", "name": "archipelago",
"new_version": "1.8.21-alpha", "new_version": "1.8.22-alpha",
"sha256": "ff602e85f340aff7e43d9d94f7f84f11f713735c964c0d8ba150e23b065c30eb", "sha256": "e108b78bbbd21cb7d5d47c8d0b7b9b19b63fb0c44678773603202440ec7d6f5b",
"size_bytes": 64748176 "size_bytes": 65627704
}, },
{ {
"current_version": "1.8.21-alpha", "current_version": "1.8.22-alpha",
"download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.21-alpha/archipelago-frontend-1.8.21-alpha.tar.gz", "download_url": "https://source.archipelago-foundation.org/lfg2025/archy/releases/download/v1.8.22-alpha/archipelago-frontend-1.8.22-alpha.tar.gz",
"name": "archipelago-frontend-1.8.21-alpha.tar.gz", "name": "archipelago-frontend-1.8.22-alpha.tar.gz",
"new_version": "1.8.21-alpha", "new_version": "1.8.22-alpha",
"sha256": "6c0842ec83a440269a353808a4cf154174f5232c9989b4a5448bc6486e1d0620", "sha256": "2da485a2da75ff2fbe4aba52d6f217150e303be43a031723480c9c4ff9d43f41",
"size_bytes": 97152546 "size_bytes": 98131119
} }
], ],
"release_date": "2026-09-30", "release_date": "2026-09-30",
"signature": "2ba21dde08284a13f511f11f0b925f09a56c1b36e40424558601b9ab6beea17edfa316e0baa51474bf084fd4da25429ec35a77d9a831554b309845c8226d4f0d", "signature": "34e9e3902d5960c977b528c4edbb4366ad862f761076755632296840604c8a84ae1bbb503d8d26b2fe7622ca1eccfaa15cb8d23935bcec6dbecdaf6c53f7f50e",
"signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT", "signed_by": "did:key:z6Mkfu5LT8d4DjETtrkATvHh9Dvcbnr7zBCUwfau8Sw7DLWT",
"version": "1.8.21-alpha" "version": "1.8.22-alpha"
} }