feat: ISO networking stack — relay + nvpn v0.3.7 + WireGuard
Add nostr-rs-relay as native system service (port 7777) for VPN signaling. Every node runs its own private relay from first boot. Update nvpn binary from v0.3.4 to v0.3.7 (fixes mesh event processing). Add WireGuard helper and address service for peer VPN. First-boot script configures relay, nvpn identity, relay URLs (direct + Tor onion), and syncs daemon config. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
e977600471
commit
7741dc8652
@@ -0,0 +1,14 @@
|
||||
[Unit]
|
||||
Description=Assign WireGuard server address to wg0
|
||||
After=nostr-vpn.service
|
||||
Wants=nostr-vpn.service
|
||||
ConditionPathExists=/sys/class/net/wg0
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
RemainAfterExit=yes
|
||||
ExecStart=/bin/bash -c 'ip address show dev wg0 | grep -q "10.44.0.1" || ip address add 10.44.0.1/16 dev wg0'
|
||||
ExecStart=/bin/bash -c 'iptables -t nat -C POSTROUTING -s 10.44.0.0/16 ! -o wg0 -j MASQUERADE 2>/dev/null || iptables -t nat -A POSTROUTING -s 10.44.0.0/16 ! -o wg0 -j MASQUERADE'
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,19 @@
|
||||
[info]
|
||||
relay_url = "ws://0.0.0.0:7777/"
|
||||
name = "Archipelago Private Relay"
|
||||
description = "Private Nostr relay for Archipelago mesh VPN peer discovery"
|
||||
|
||||
[database]
|
||||
data_directory = "/var/lib/archipelago/nostr-relay"
|
||||
in_memory = true
|
||||
|
||||
[network]
|
||||
address = "0.0.0.0"
|
||||
port = 7777
|
||||
ping_interval = 120
|
||||
|
||||
[limits]
|
||||
messages_per_sec = 50
|
||||
max_event_bytes = 65536
|
||||
max_ws_message_bytes = 65536
|
||||
max_ws_frame_bytes = 65536
|
||||
@@ -0,0 +1,24 @@
|
||||
[Unit]
|
||||
Description=Archipelago Private Nostr Relay
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
Before=nostr-vpn.service
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=archipelago
|
||||
ExecStartPre=/bin/bash -c 'mkdir -p /var/lib/archipelago/nostr-relay'
|
||||
ExecStart=/usr/local/bin/nostr-rs-relay --config /var/lib/archipelago/nostr-relay/config.toml
|
||||
Restart=always
|
||||
RestartSec=3
|
||||
TimeoutStopSec=10
|
||||
|
||||
# Resource limits — relay is lightweight (in-memory mode)
|
||||
MemoryMax=512M
|
||||
LimitNOFILE=4096
|
||||
|
||||
StandardOutput=journal
|
||||
StandardError=journal
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user