fix(security): publish the loopback-pinned UI images and pin the new tags
Fresh installs pull *-ui images from the registry, so the source fix alone left a newly flashed node serving the Bitcoin, LND, Electrs, FIPS and Guardian screens with no login. All five rebuilt and pushed to 146.59.87.168:3000/lfg2025 as 1.7.123-alpha AND :latest — both tags, because first-boot resolves the pinned tag from image-versions.sh while the daemon's companion installer hardcodes :latest, and a stale :latest would have quietly undone the fix on exactly the path that rebuilds companions. Verified by pulling each image back from the registry anonymously and reading /etc/nginx/conf.d/default.conf inside it — a private package would make fresh nodes fall back to a stale local image without saying so. Also fixes the FOURTH copy of bitcoin-ui's listen directive (scripts/reconcile-containers.sh wrote 'listen 8334' into the rendered nginx.conf on every reconcile, which would have re-opened the port after the image and template were both corrected). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
abf0f56afc
commit
9c736f20b6
@@ -84,7 +84,7 @@ STRFRY_IMAGE="$ARCHY_REGISTRY/strfry:1.0.4"
|
||||
NOSTR_VPN_IMAGE="$ARCHY_REGISTRY/nostr-vpn:v0.3.7"
|
||||
NOSTR_VPN_UI_IMAGE="$ARCHY_REGISTRY/nostr-vpn-ui:latest"
|
||||
FIPS_IMAGE="$ARCHY_REGISTRY/fips:v0.1.0"
|
||||
FIPS_UI_IMAGE="$ARCHY_REGISTRY/fips-ui:latest"
|
||||
FIPS_UI_IMAGE="$ARCHY_REGISTRY/fips-ui:1.7.123-alpha"
|
||||
|
||||
# AI / Routing
|
||||
ROUTSTR_IMAGE="$ARCHY_REGISTRY/routstr:v0.4.3"
|
||||
@@ -117,9 +117,9 @@ PENPOT_EXPORTER_IMAGE="$ARCHY_REGISTRY/penpot-exporter:2.4"
|
||||
PENPOT_FRONTEND_IMAGE="$ARCHY_REGISTRY/penpot-frontend:2.4"
|
||||
|
||||
# Custom UI containers (built from docker/ dirs, pushed to registry)
|
||||
BITCOIN_UI_IMAGE="$ARCHY_REGISTRY/bitcoin-ui:1.7.119-alpha"
|
||||
LND_UI_IMAGE="$ARCHY_REGISTRY/lnd-ui:1.7.119-alpha"
|
||||
ELECTRS_UI_IMAGE="$ARCHY_REGISTRY/electrs-ui:latest"
|
||||
BITCOIN_UI_IMAGE="$ARCHY_REGISTRY/bitcoin-ui:1.7.123-alpha"
|
||||
LND_UI_IMAGE="$ARCHY_REGISTRY/lnd-ui:1.7.123-alpha"
|
||||
ELECTRS_UI_IMAGE="$ARCHY_REGISTRY/electrs-ui:1.7.123-alpha"
|
||||
|
||||
# Base images
|
||||
NGINX_ALPINE_IMAGE="$ARCHY_REGISTRY/nginx:1.27.4-alpine"
|
||||
|
||||
@@ -809,7 +809,12 @@ ensure_bitcoin_ui_nginx_conf() {
|
||||
tmp="${CONF_PATH}.tmp.$$"
|
||||
sudo tee "$tmp" >/dev/null << EOF
|
||||
server {
|
||||
listen 8334;
|
||||
# Loopback ONLY — this is the fourth copy of this declaration (the others
|
||||
# are the Rust template in container/bitcoin_ui_nginx.conf.template, the
|
||||
# image, and the manifest). Host networking means this nginx binds the
|
||||
# HOST's address, so \`listen 8334;\` served the Bitcoin screen on every
|
||||
# interface with no login. The app gate owns the external addresses now.
|
||||
listen 127.0.0.1:8334;
|
||||
server_name _;
|
||||
root /usr/share/nginx/html;
|
||||
index index.html;
|
||||
|
||||
Reference in New Issue
Block a user