Adds apps/podsteadr (main Fastify+Vue app, container.build from the podsteadr repo), apps/podsteadr-mediamtx (RTMP/WHIP ingest, HLS, recording), and apps/podsteadr-blossom (BUD-02 media blobs), wired together on a dedicated podsteadr-net bridge network per the multi-container pattern documented in docs/app-developer-guide.md (indeedhub's api/relay/minio/redis/postgres siblings). All podsteadr ports are auth: none with a rationale, since it's a public podcast/livestream server whose RSS feeds, HLS playback, and blob reads must stay reachable by third-party clients with no Archipelago session — the app already gates its own sensitive routes with NIP-98 and per-stream secret keys. Also updates apps/PORTS.md, apps/README.md, and bumps the reviewed unauthenticated-port count in core/container/src/manifest.rs's unauthenticated_ports_are_all_accounted_for test (25 -> 31) to acknowledge the six new auth:none ports. Regenerated catalog-derived files (core/archipelago/src/fips/app_ports.rs, neode-ui/src/views/appSession/generatedAppSessionConfig.ts) via scripts/generate-app-catalog.py. All three manifests pass scripts/validate-app-manifest.sh and `cargo test -p archipelago-container manifest`.
46 lines
1.8 KiB
Markdown
46 lines
1.8 KiB
Markdown
# Archipelago App Manifests
|
|
|
|
Containerized applications for the Archipelago Bitcoin Node OS. All apps run in rootless Podman with security hardening (cap-drop ALL, readonly root, non-root user, memory limits).
|
|
|
|
## App Categories
|
|
|
|
### Bitcoin & Lightning
|
|
- **bitcoin-knots** — Full Bitcoin node (v28.1)
|
|
- **lnd** — Lightning Network Daemon (v0.17.4-beta)
|
|
- **btcpay-server** — Payment processor (v1.13.5)
|
|
- **mempool** — Block explorer and fee estimator (v2.5.0)
|
|
- **electrumx** — Electrum server
|
|
- **fedimint** — Federated Bitcoin minting (v0.10.0)
|
|
|
|
### Nostr
|
|
- **nostr-rs-relay** — High-performance Rust relay (v0.9.0)
|
|
- **nostrudel** — Nostr web client (v0.40.0)
|
|
|
|
### Web5 & Identity
|
|
- **did-wallet** — Web5 DID Wallet
|
|
|
|
### Self-Hosted Services
|
|
- **podsteadr** — Nostr-native podcast publishing and livestreaming (RTMP/WebRTC ingest, HLS, RSS, Blossom media)
|
|
- **nextcloud** (v28), **jellyfin** (v10.8.13), **immich** (release), **photoprism** (v240915)
|
|
- **vaultwarden** (v1.30.0-alpine), **penpot** (v2.4)
|
|
- **homeassistant** (v2024.1), **filebrowser** (v2.27.0), **searxng** (2024.11.17)
|
|
- **ollama** (v0.5.4), **grafana** (v10.2.0), **portainer** (v2.19.4)
|
|
|
|
### Networking
|
|
- **tailscale** (stable), **nginx-proxy-manager** (v2.12.1)
|
|
|
|
### Custom & External
|
|
- **indeedhub** — Bitcoin documentary streaming (custom build)
|
|
- **router** — Mesh routing and network management
|
|
- **botfights** — External web app
|
|
|
|
## Manifest Format
|
|
|
|
Each app has a `manifest.yml` defining container image, resources, dependencies, security policies, health checks, and network config. See [`docs/app-manifest-spec.md`](../docs/app-manifest-spec.md) for the spec.
|
|
|
|
## Quick Reference
|
|
|
|
- [PORTS.md](./PORTS.md) — Complete port mapping
|
|
- [QUICKSTART.md](./QUICKSTART.md) — Build and run apps
|
|
- [DEVELOPMENT.md](./DEVELOPMENT.md) — Development workflow
|