With registry push access, the 24 mirror-backed apps stopped being blocked. Ten images are now mirrored (single-platform amd64, matching the existing convention) and their pins moved: alby-hub v1.23.0 -> v1.24.0 mempool-frontend v3.0.1 -> v3.3.1 (mempool, archy-mempool-web) mempool-backend v3.0.0 -> v3.3.1 fedimintd v0.10.0 -> v0.10.1 gatewayd v0.10.0 -> v0.10.1 nostr-rs-relay 0.9.0 -> 0.10.0 portainer 2.39.1 -> 2.39.6 vaultwarden 1.30.0-alpine -> 1.37.1-alpine jellyfin 10.8.13 -> 10.11.11 home-assistant 2026.7.3 -> 2026.8.2 Every one verified pullable from our mirror after copying, so none can become an image-not-found on a node. image-versions.sh moved in lockstep — it is the baseline the update badge compares against when the catalog does not cover an app, and leaving it behind would have kept advertising an update that had already been applied. Chosen by risk, not by count: these are patch/minor bumps with no data migration. The ones held back are held for a reason each — Postgres 15->18 and 16->18 refuse to start on an older cluster, Redis 7->8, Valkey 7->9, Nextcloud 29->32 must go one major at a time, plus uptime-kuma 1->2, grafana 10->13, electrumx 1->2, photoprism, and core-lightning's three years of schema migrations. Those are each a migration plan, not a pin edit. LND (v0.18.4 -> v0.21.2) is held separately: it is only a minor bump by version but it migrates its channel database irreversibly, and this box holds real funds. Note the checker still reports several of these as behind, and that is correct: it reads the *catalog* pin, which is what nodes actually act on. These land when the catalog is regenerated and re-signed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
121 lines
3.9 KiB
YAML
121 lines
3.9 KiB
YAML
app:
|
|
id: fedimint
|
|
name: Fedimint Guardian
|
|
version: 0.10.0
|
|
# Where this app comes from, so scripts/check-upstream-releases.py can
|
|
# tell us when the pin below has fallen behind. Without it nothing can:
|
|
# container.image names our mirror, not the project it was mirrored from.
|
|
upstream:
|
|
kind: github
|
|
repo: fedimint/fedimint
|
|
description: Federated Bitcoin minting service with built-in Guardian UI. Privacy-preserving Bitcoin custody.
|
|
|
|
container:
|
|
image: source.archipelago-foundation.org/lfg2025/fedimintd:v0.10.1
|
|
pull_policy: if-not-present
|
|
network: archy-net
|
|
entrypoint: ["sh", "-lc"]
|
|
custom_args:
|
|
- |-
|
|
until state="$(curl -sS --connect-timeout 5 -m 45 -u "$FM_BITCOIND_USERNAME:$FM_BITCOIND_PASSWORD" -H "Content-Type: application/json" --data-binary '{"jsonrpc":"1.0","id":"fedimint-wait","method":"getblockchaininfo","params":[]}' "$FM_BITCOIND_URL/")" && echo "$state" | grep -q '"initialblockdownload":false'; do
|
|
echo "Waiting for Bitcoin RPC sync at $FM_BITCOIND_URL...";
|
|
sleep 30;
|
|
done;
|
|
exec fedimintd
|
|
derived_env:
|
|
- key: FM_P2P_URL
|
|
template: fedimint://{{HOST_MDNS}}:8173
|
|
- key: FM_API_URL
|
|
template: ws://{{HOST_MDNS}}:8174
|
|
# Resolves to whichever bitcoin container is running (Knots/Core/future
|
|
# distro) instead of a hardcoded name — the guardian works on any node
|
|
# regardless of which Bitcoin software it runs.
|
|
- key: FM_BITCOIND_URL
|
|
template: "http://{{BITCOIN_HOST}}:8332"
|
|
secret_env:
|
|
- key: FM_BITCOIND_PASSWORD
|
|
secret_file: bitcoin-rpc-password
|
|
data_uid: "1000:1000"
|
|
|
|
dependencies:
|
|
- app_id: bitcoin-core
|
|
version: ">=26.0"
|
|
- storage: 20Gi
|
|
|
|
resources:
|
|
cpu_limit: 4
|
|
memory_limit: 4Gi
|
|
disk_limit: 20Gi
|
|
|
|
security:
|
|
capabilities: []
|
|
readonly_root: true
|
|
network_policy: isolated
|
|
|
|
ports:
|
|
- host: 8173
|
|
container: 8173
|
|
protocol: tcp
|
|
auth: none
|
|
auth_rationale: >-
|
|
Fedimint guardian consensus. Other guardians speak the federation's own
|
|
authenticated protocol here; a login page would break consensus.
|
|
- host: 8174
|
|
container: 8174
|
|
protocol: tcp
|
|
auth: none
|
|
auth_rationale: >-
|
|
Fedimint guardian API for federation clients, which authenticate to the
|
|
federation itself and cannot hold a browser session.
|
|
# Public launch port 8175 is owned by archy-fedimint-ui, which serves a
|
|
# wait page while Bitcoin syncs and proxies here after fedimintd starts.
|
|
# 8175 is NOT declared here. It is served by the archy-fedimint-ui
|
|
# companion, a different container, and declaring it on this app made the
|
|
# orchestrator try to publish 8175 from fedimintd — colliding with the
|
|
# companion that already holds it, so start_container failed forever and
|
|
# fedimint crash-looped (a fleet node, 2026-08-05). The companion's nginx
|
|
# is pinned to 127.0.0.1, which is what actually closes that port; the
|
|
# gate reports it rather than fronting it.
|
|
- host: 8177
|
|
container: 8175
|
|
protocol: tcp
|
|
bind: 127.0.0.1
|
|
auth: local
|
|
|
|
volumes:
|
|
- type: bind
|
|
source: /var/lib/archipelago/fedimint
|
|
target: /data
|
|
options: [rw]
|
|
|
|
environment:
|
|
- FM_DATA_DIR=/data
|
|
# FM_BITCOIND_URL comes from derived_env ({{BITCOIN_HOST}}) above, not a
|
|
# hardcoded name — do not re-add it here.
|
|
- FM_BITCOIND_USERNAME=archipelago
|
|
- FM_BITCOIN_NETWORK=bitcoin
|
|
- FM_BIND_P2P=0.0.0.0:8173
|
|
- FM_BIND_API=0.0.0.0:8174
|
|
- FM_BIND_UI=0.0.0.0:8175
|
|
|
|
health_check:
|
|
type: http
|
|
endpoint: http://localhost:8175
|
|
path: /
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
|
|
interfaces:
|
|
main:
|
|
name: Guardian UI
|
|
description: Fedimint Guardian wait/proxy UI
|
|
type: ui
|
|
port: 8175
|
|
protocol: http
|
|
path: /
|
|
|
|
bitcoin_integration:
|
|
rpc_access: admin
|
|
sync_required: true
|