With registry push access, the 24 mirror-backed apps stopped being blocked. Ten images are now mirrored (single-platform amd64, matching the existing convention) and their pins moved: alby-hub v1.23.0 -> v1.24.0 mempool-frontend v3.0.1 -> v3.3.1 (mempool, archy-mempool-web) mempool-backend v3.0.0 -> v3.3.1 fedimintd v0.10.0 -> v0.10.1 gatewayd v0.10.0 -> v0.10.1 nostr-rs-relay 0.9.0 -> 0.10.0 portainer 2.39.1 -> 2.39.6 vaultwarden 1.30.0-alpine -> 1.37.1-alpine jellyfin 10.8.13 -> 10.11.11 home-assistant 2026.7.3 -> 2026.8.2 Every one verified pullable from our mirror after copying, so none can become an image-not-found on a node. image-versions.sh moved in lockstep — it is the baseline the update badge compares against when the catalog does not cover an app, and leaving it behind would have kept advertising an update that had already been applied. Chosen by risk, not by count: these are patch/minor bumps with no data migration. The ones held back are held for a reason each — Postgres 15->18 and 16->18 refuse to start on an older cluster, Redis 7->8, Valkey 7->9, Nextcloud 29->32 must go one major at a time, plus uptime-kuma 1->2, grafana 10->13, electrumx 1->2, photoprism, and core-lightning's three years of schema migrations. Those are each a migration plan, not a pin edit. LND (v0.18.4 -> v0.21.2) is held separately: it is only a minor bump by version but it migrates its channel database irreversibly, and this box holds real funds. Note the checker still reports several of these as behind, and that is correct: it reads the *catalog* pin, which is what nodes actually act on. These land when the catalog is regenerated and re-signed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
105 lines
3.8 KiB
YAML
105 lines
3.8 KiB
YAML
app:
|
|
id: fedimint-gateway
|
|
name: Fedimint Gateway
|
|
version: 0.10.0
|
|
# Where this app comes from, so scripts/check-upstream-releases.py can
|
|
# tell us when the pin below has fallen behind. Without it nothing can:
|
|
# container.image names our mirror, not the project it was mirrored from.
|
|
upstream:
|
|
kind: github
|
|
repo: fedimint/fedimint
|
|
description: Fedimint gateway service with automatic LND-or-LDK backend selection.
|
|
|
|
container:
|
|
image: source.archipelago-foundation.org/lfg2025/gatewayd:v0.10.1
|
|
pull_policy: if-not-present
|
|
network: archy-net
|
|
entrypoint: ["sh", "-lc"]
|
|
# The bitcoind host comes from $FM_BITCOIND_URL, filled by the
|
|
# {{BITCOIN_HOST}} derived-env below — it resolves to whichever bitcoin
|
|
# container is actually running (Knots, Core, or any future distro archy
|
|
# ships), so the gateway is never pinned to one node's container name.
|
|
# (Was hardcoded http://host.archipelago:8332 — the host gateway IP where
|
|
# bitcoind does not listen — which crash-looped the gateway, 2026-07-22.)
|
|
custom_args:
|
|
- >-
|
|
if [ -f /lnd/tls.cert ] && [ -f /lnd/data/chain/bitcoin/mainnet/admin.macaroon ]; then
|
|
exec gatewayd --data-dir /data --listen 0.0.0.0:8176 --bcrypt-password-hash "$FEDI_HASH" --network bitcoin --bitcoind-url "$FM_BITCOIND_URL" --bitcoind-username "$FM_BITCOIND_USERNAME" --bitcoind-password "$FM_BITCOIND_PASSWORD" lnd --lnd-rpc-host lnd:10009 --lnd-tls-cert /lnd/tls.cert --lnd-macaroon /lnd/data/chain/bitcoin/mainnet/admin.macaroon;
|
|
else
|
|
exec gatewayd --data-dir /data --listen 0.0.0.0:8176 --bcrypt-password-hash "$FEDI_HASH" --network bitcoin --bitcoind-url "$FM_BITCOIND_URL" --bitcoind-username "$FM_BITCOIND_USERNAME" --bitcoind-password "$FM_BITCOIND_PASSWORD" ldk --ldk-lightning-port 9737 --ldk-alias archipelago-gateway;
|
|
fi
|
|
derived_env:
|
|
- key: FM_BITCOIND_URL
|
|
template: "http://{{BITCOIN_HOST}}:8332"
|
|
# The gateway's admin API is gated by a bcrypt password hash. Generate it on
|
|
# first install (random password + its bcrypt hash, both 0600 rootless-owned)
|
|
# so the app installs from its manifest alone — `fedimint-gateway-hash` holds
|
|
# the hash passed to gatewayd, `fedimint-gateway-hash.pw` the plaintext for
|
|
# any client that must authenticate. Self-heals a wrongly root-owned hash.
|
|
generated_secrets:
|
|
- name: fedimint-gateway-hash
|
|
kind: bcrypt
|
|
secret_env:
|
|
- key: FM_BITCOIND_PASSWORD
|
|
secret_file: bitcoin-rpc-password
|
|
- key: FEDI_HASH
|
|
secret_file: fedimint-gateway-hash
|
|
data_uid: "1000:1000"
|
|
|
|
dependencies:
|
|
- app_id: bitcoin-core
|
|
version: ">=26.0"
|
|
- app_id: fedimint
|
|
version: ">=0.10.0"
|
|
|
|
resources:
|
|
cpu_limit: 2
|
|
memory_limit: 2Gi
|
|
disk_limit: 10Gi
|
|
|
|
security:
|
|
capabilities: []
|
|
readonly_root: true
|
|
network_policy: isolated
|
|
|
|
ports:
|
|
- host: 8176
|
|
container: 8176
|
|
protocol: tcp
|
|
auth: none
|
|
auth_rationale: >-
|
|
Fedimint gateway API, protected by its own bcrypt password (--bcrypt-password-hash)
|
|
and reached by federation peers and clients that cannot hold a browser session.
|
|
- host: 9737
|
|
container: 9737
|
|
protocol: tcp
|
|
auth: none
|
|
auth_rationale: >-
|
|
LDK Lightning p2p for the gateway. The BOLT-8 noise handshake authenticates and
|
|
encrypts the connection itself.
|
|
|
|
volumes:
|
|
- type: bind
|
|
source: /var/lib/archipelago/fedimint-gateway
|
|
target: /data
|
|
options: [rw]
|
|
- type: bind
|
|
source: /var/lib/archipelago/lnd
|
|
target: /lnd
|
|
options: [ro]
|
|
|
|
environment:
|
|
- FM_BITCOIND_USERNAME=archipelago
|
|
|
|
health_check:
|
|
type: http
|
|
endpoint: http://localhost:8176
|
|
path: /
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
|
|
bitcoin_integration:
|
|
rpc_access: admin
|
|
sync_required: true
|