Full-node daemon: P2P + Monero's own restricted RPC (the safe-for-public subset wallets use as a "remote node") are auth:none like bitcoin/electrumx's equivalents; unrestricted RPC (full node control) stays gated auth:local. readonly_root works cleanly since the upstream image is FROM scratch with ownership fixed at build time — no runtime chown/setuid needed, unlike bitcoin-knots/core. Verified locally end-to-end before committing: built the upstream Dockerfile, confirmed the generated Cuprated.toml against `cuprated --generate-config`/ `--dry-run`, and ran the real image with the manifest's exact ports/volumes — including discovering that cuprated's own 127.0.0.1-default RPC bind is unreachable through a published host port and needs to bind 0.0.0.0 internally with ports[].bind:127.0.0.1 doing the actual restriction, the same pattern bitcoin-knots' RPC port already uses in this repo. Bumps the unauthenticated_ports_are_all_accounted_for canary (26 -> 28) for cuprate's two auth:none ports, per that test's own review-before-updating contract. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
6.2 KiB
6.2 KiB