Portainer: nodes have been running :latest — which is 2.39.1 — while the manifest pinned 2.19.4 from two years ago. The port migration recreated the container onto that old pin and Portainer refused to start: it migrates a database forward, never backward, so an existing install died with 'schema version does not align' and My Apps showed 'app is not responding' (100.82.34.38). 2.39.1 published as an immutable tag and pinned forward, so existing databases keep working and older ones migrate up. Bitcoin: complements PR #131. That removes the code which kept writing a datadir bitcoin.conf; -allowignoredconf=1 additionally makes an existing one non-fatal, so a node already carrying the file recovers on restart instead of crash-looping until something reinstalls it. App gate login: rebuilt against the dashboard's own design — rotating intro backgrounds served from the gate, the glass panel, the Archipelago mark in its gradient ring, the app's icon as a My Apps tile, and the glass button. Crucially it no longer sends X-Frame-Options: DENY, which made every gated app render as unreachable inside My Apps' embedded frame; frame-ancestors expresses 'only this node may frame me', which X-Frame-Options cannot. OTA origin: primary mirror is now source.archipelago-foundation.org over TLS instead of a bare IP on plaintext. The IP stays as an automatic fallback for nodes whose DNS or clock is broken — both break TLS, and the signature, not the transport, is what establishes trust. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
67 lines
1.4 KiB
YAML
67 lines
1.4 KiB
YAML
app:
|
|
id: portainer
|
|
name: Portainer
|
|
version: 2.19.4
|
|
description: Container management web UI for the local Podman socket.
|
|
category: development
|
|
|
|
container:
|
|
image: 146.59.87.168:3000/lfg2025/portainer:2.39.1
|
|
pull_policy: if-not-present
|
|
data_uid: "1000:1000"
|
|
|
|
dependencies:
|
|
- storage: 1Gi
|
|
|
|
resources:
|
|
memory_limit: 256Mi
|
|
disk_limit: 1Gi
|
|
|
|
security:
|
|
capabilities: [CHOWN, SETUID, SETGID, DAC_OVERRIDE]
|
|
readonly_root: false
|
|
no_new_privileges: true
|
|
network_policy: isolated
|
|
|
|
ports:
|
|
- host: 9000
|
|
container: 9000
|
|
protocol: tcp
|
|
bind: 127.0.0.1
|
|
auth: gated
|
|
|
|
volumes:
|
|
- type: bind
|
|
source: /var/lib/archipelago/portainer
|
|
target: /data
|
|
options: [rw]
|
|
- type: bind
|
|
source: /var/lib/archipelago/portainer/compose
|
|
target: /data/compose
|
|
options: [rw]
|
|
- type: bind
|
|
source: /run/user/1000/podman/podman.sock
|
|
target: /var/run/docker.sock
|
|
options: [rw]
|
|
|
|
environment: []
|
|
|
|
interfaces:
|
|
main:
|
|
name: Web UI
|
|
description: Portainer web interface
|
|
type: ui
|
|
port: 9000
|
|
protocol: http
|
|
path: /
|
|
|
|
metadata:
|
|
icon: /assets/img/app-icons/portainer.webp
|
|
tier: optional
|
|
launch:
|
|
open_in_new_tab: true
|
|
features:
|
|
- Container management dashboard
|
|
- Local Podman socket access
|
|
- Compose stack storage
|