#!/bin/sh # Shared entrypoint for both apps/nostr-vpn (daemon) and apps/nostr-vpn-web # (control panel) -- they're the same image, differing only in the args # this script execs into (see each manifest's container.entrypoint/custom_args). # # Seeds a minimal config.toml with our chosen listen_port BEFORE nvpn's own # bootstrap (config_bootstrap.rs::load_or_default_config) ever runs, so the # very first boot never has to self-heal off upstream's default 51820 -- # archy-x250 fleet nodes already run archipelago-wg on that port (found in # Phase 0 testing, see docs/nostr-vpn-integration-plan.md). Every AppConfig # field has #[serde(default = ...)], confirmed by reading # crates/nostr-vpn-core/src/config/types.rs directly, so a partial TOML here # merges cleanly with nvpn's own defaults (including the self-generated # Nostr seller identity) instead of needing a full config. # # Never overwrites an existing config.toml: this volume may already hold a # seller's identity, wallet, and pending Cashu credit adopted from the old # root-mode install (/var/lib/archipelago/nostr-vpn) -- clobbering it would # be a real funds-safety bug, not just a config reset. set -eu NVPN_LISTEN_PORT="${NVPN_LISTEN_PORT:-51822}" CONFIG_DIR=/data/config/nvpn CONFIG_PATH="$CONFIG_DIR/config.toml" mkdir -p "$CONFIG_DIR" /data/home if [ ! -f "$CONFIG_PATH" ]; then cat > "$CONFIG_PATH" <