app: id: fips-ui name: FIPS Mesh version: 1.0.0 description: | Archipelago-native dashboard for the FIPS mesh transport. Runs nginx inside a container with host networking, serves a static dashboard on :8336, and reverse-proxies /rpc/v1 to the archipelago backend on 127.0.0.1:5678. All FIPS controls (status, seed anchors, reconnect, restart, and stable-channel daemon updates) go through the existing fips.* RPC methods, authenticated by the browser's own archipelago session — there is no separate secret to manage. container: build: context: /opt/archipelago/docker/fips-ui dockerfile: Dockerfile tag: localhost/fips-ui:local resources: memory_limit: 128Mi security: readonly_root: false network_policy: host # Host networking: nginx listens on 8336 directly on the host IP and # proxies to 127.0.0.1:5678 (the archipelago RPC). `ports:` is # intentionally empty because host networking bypasses port mapping. # Declared so the APP GATE can see this port. Host networking means Podman # publishes nothing (quadlet skips PublishPort in host mode), so `bind:` here # is a statement of where the container's own nginx listens — 127.0.0.1 — # not a publish instruction. Without this declaration the gate had no idea # the port existed: it was neither protected nor listed as unprotected, and # served the FIPS mesh screen unauthenticated on every interface. ports: - host: 8336 container: 8336 protocol: tcp bind: 127.0.0.1 auth: gated # First-party companion UI: its nginx forwards the node session cookie # to the daemon's authenticated endpoints; without passthrough the gate # strips it and every data call 401s while the page shell renders. session_passthrough: true volumes: [] environment: [] health_check: type: http endpoint: http://127.0.0.1:8336 path: / interval: 30s timeout: 5s retries: 3