feat(apps): package podsteadr as a full Archipelago app (3-container manifest set)

Adds apps/podsteadr (main Fastify+Vue app, container.build from the podsteadr
repo), apps/podsteadr-mediamtx (RTMP/WHIP ingest, HLS, recording), and
apps/podsteadr-blossom (BUD-02 media blobs), wired together on a dedicated
podsteadr-net bridge network per the multi-container pattern documented in
docs/app-developer-guide.md (indeedhub's api/relay/minio/redis/postgres
siblings). All podsteadr ports are auth: none with a rationale, since it's a
public podcast/livestream server whose RSS feeds, HLS playback, and blob
reads must stay reachable by third-party clients with no Archipelago session
— the app already gates its own sensitive routes with NIP-98 and per-stream
secret keys.

Also updates apps/PORTS.md, apps/README.md, and bumps the reviewed
unauthenticated-port count in core/container/src/manifest.rs's
unauthenticated_ports_are_all_accounted_for test (25 -> 31) to acknowledge
the six new auth:none ports. Regenerated catalog-derived files
(core/archipelago/src/fips/app_ports.rs,
neode-ui/src/views/appSession/generatedAppSessionConfig.ts) via
scripts/generate-app-catalog.py.

All three manifests pass scripts/validate-app-manifest.sh and
`cargo test -p archipelago-container manifest`.
This commit is contained in:
2026-08-07 14:45:22 +00:00
parent 0e5f58a916
commit e2641bc10c
12 changed files with 713 additions and 12 deletions
@@ -28,6 +28,7 @@ export const GENERATED_APP_PORTS: Record<string, number> = {
"nostr-rs-relay": 18081,
"photoprism": 2342,
"pine": 10380,
"podsteadr": 8095,
"portainer": 9000,
"router": 8084,
"searxng": 8888,
@@ -87,6 +88,9 @@ export const GENERATED_APP_TITLES: Record<string, string> = {
"pine-openwakeword": "Pine Wake Word (openWakeWord)",
"pine-piper": "Pine Piper (TTS)",
"pine-whisper": "Pine Whisper (STT)",
"podsteadr": "podsteadr",
"podsteadr-blossom": "podsteadr Blossom",
"podsteadr-mediamtx": "podsteadr MediaMTX",
"portainer": "Portainer",
"router": "Mesh Router",
"searxng": "SearXNG",