Portainer: nodes have been running :latest — which is 2.39.1 — while the manifest pinned 2.19.4 from two years ago. The port migration recreated the container onto that old pin and Portainer refused to start: it migrates a database forward, never backward, so an existing install died with 'schema version does not align' and My Apps showed 'app is not responding' (100.82.34.38). 2.39.1 published as an immutable tag and pinned forward, so existing databases keep working and older ones migrate up. Bitcoin: complements PR #131. That removes the code which kept writing a datadir bitcoin.conf; -allowignoredconf=1 additionally makes an existing one non-fatal, so a node already carrying the file recovers on restart instead of crash-looping until something reinstalls it. App gate login: rebuilt against the dashboard's own design — rotating intro backgrounds served from the gate, the glass panel, the Archipelago mark in its gradient ring, the app's icon as a My Apps tile, and the glass button. Crucially it no longer sends X-Frame-Options: DENY, which made every gated app render as unreachable inside My Apps' embedded frame; frame-ancestors expresses 'only this node may frame me', which X-Frame-Options cannot. OTA origin: primary mirror is now source.archipelago-foundation.org over TLS instead of a bare IP on plaintext. The IP stays as an automatic fallback for nodes whose DNS or clock is broken — both break TLS, and the signature, not the transport, is what establishes trust. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
127 lines
5.4 KiB
YAML
127 lines
5.4 KiB
YAML
app:
|
|
id: bitcoin-core
|
|
name: Bitcoin Core
|
|
version: 28.4.0
|
|
description: Reference Bitcoin Core node with dynamic prune/full-mode startup based on host disk.
|
|
|
|
container_name: bitcoin-core
|
|
|
|
container:
|
|
image: 146.59.87.168:3000/lfg2025/bitcoin:28.4
|
|
pull_policy: if-not-present
|
|
network: archy-net
|
|
entrypoint: ["sh", "-lc"]
|
|
custom_args:
|
|
# Sync-speed flags: -par=0 uses every core (was capped at 2 by
|
|
# --cpus=2, now removed for bitcoin/electrumx). -dbcache sized to
|
|
# the IBD sweet spot - 4GB on full nodes, 1GB on pruned. Container
|
|
# --memory=8g (config.rs::get_memory_limit) leaves headroom for
|
|
# mempool + connections.
|
|
#
|
|
# -printtoconsole=0: foreground bitcoind defaults console logging ON,
|
|
# which pushed every IBD "UpdateTip" line through conmon into journald
|
|
# (>1 GB/day on a fresh node). bitcoind still writes debug.log in the
|
|
# datadir (/var/lib/archipelago/bitcoin/debug.log, self-shrunk on
|
|
# restart) — use that for deep debugging; podman logs only carries
|
|
# entrypoint/startup errors.
|
|
- >-
|
|
BITCOIND="$(command -v bitcoind || true)";
|
|
if [ -z "$BITCOIND" ]; then
|
|
BITCOIND="$(find /opt -path '*/bin/bitcoind' -type f 2>/dev/null | sort | tail -n 1)";
|
|
fi;
|
|
if [ -z "$BITCOIND" ]; then
|
|
echo "bitcoind not found in image" >&2;
|
|
exit 127;
|
|
fi;
|
|
RPC_USER="$(printenv BITCOIN_RPC_USER)";
|
|
RPC_PASS="$(printenv BITCOIN_RPC_PASS)";
|
|
RPC_CONF="/tmp/rpc.conf";
|
|
umask 077;
|
|
{ echo "rpcuser=$RPC_USER"; echo "rpcpassword=$RPC_PASS"; } > "$RPC_CONF";
|
|
# A stray bitcoin.conf in the datadir is FATAL when -conf points
|
|
# elsewhere: bitcoind refuses to start with "contains a bitcoin.conf
|
|
# file which is ignored", and the app crash-loops (100.82.34.38,
|
|
# 2026-08-05 — Exited(1) every few seconds). Our -conf carries the
|
|
# RPC credentials and the flags below are the authoritative config,
|
|
# so the datadir file is legacy debris; say so out loud rather than
|
|
# failing, and let bitcoind start.
|
|
if [ -f /home/bitcoin/.bitcoin/bitcoin.conf ]; then
|
|
echo "archipelago: ignoring legacy /home/bitcoin/.bitcoin/bitcoin.conf; RPC config comes from $RPC_CONF and the flags below" >&2;
|
|
fi;
|
|
RPC_TXRELAY_AUTH="$(printenv BITCOIN_RPC_TXRELAY_RPCAUTH || true)";
|
|
DISK_GB_VALUE="$(printenv DISK_GB || true)";
|
|
RPC_HEADROOM="-rpcthreads=16 -rpcworkqueue=256";
|
|
RPC_TXRELAY_FLAGS="-rpcwhitelistdefault=0";
|
|
if [ -n "$RPC_TXRELAY_AUTH" ]; then
|
|
RPC_TXRELAY_FLAGS="$RPC_TXRELAY_FLAGS -rpcauth=$RPC_TXRELAY_AUTH -rpcwhitelist=txrelay:sendrawtransaction,submitpackage,testmempoolaccept,getmempoolinfo,getrawmempool,getmempoolentry,getnetworkinfo,getblockchaininfo,getblockcount,getblockhash,getblock,getblockheader,getrawtransaction,gettxout,gettxspendingprevout,decoderawtransaction,decodescript,estimatesmartfee,uptime,ping,getconnectioncount,getpeerinfo,getindexinfo,getdeploymentinfo,getchaintips";
|
|
fi;
|
|
if [ "${DISK_GB_VALUE:-0}" -lt 1000 ]; then
|
|
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -prune=550 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=1024 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
|
else
|
|
exec "$BITCOIND" -datadir=/home/bitcoin/.bitcoin -conf="$RPC_CONF" -allowignoredconf=1 -printtoconsole=0 -server=1 -txindex=1 -rpcallowip=0.0.0.0/0 -rpcbind=0.0.0.0:8332 -listen=1 -bind=0.0.0.0:8333 -dbcache=4096 -par=0 -maxconnections=125 $RPC_HEADROOM $RPC_TXRELAY_FLAGS;
|
|
fi
|
|
derived_env:
|
|
- key: DISK_GB
|
|
template: "{{DISK_GB}}"
|
|
secret_env:
|
|
- key: BITCOIN_RPC_PASS
|
|
secret_file: bitcoin-rpc-password
|
|
- key: BITCOIN_RPC_TXRELAY_RPCAUTH
|
|
secret_file: bitcoin-rpc-txrelay-rpcauth
|
|
data_uid: "100101:100101"
|
|
|
|
dependencies:
|
|
- storage: 500Gi
|
|
|
|
resources:
|
|
cpu_limit: 0
|
|
memory_limit: 4Gi
|
|
disk_limit: 500Gi
|
|
|
|
security:
|
|
capabilities: [CHOWN, FOWNER, SETUID, SETGID, DAC_OVERRIDE]
|
|
readonly_root: false
|
|
network_policy: isolated
|
|
|
|
ports:
|
|
# RPC is auth-only: publish host-local ONLY - the LAN cannot reach
|
|
# nodeIP:8332. In-node consumers (lnd, fedimint, btcpay, mempool-api)
|
|
# dial the container's archy-net alias directly (bitcoin-core:8332),
|
|
# which needs no publish at all. Do NOT bind the archy-net gateway
|
|
# (10.89.0.1): rootlessport binds in the HOST netns where that address
|
|
# does not exist, and the whole unit crash-loops (2026-07-09, .228).
|
|
# P2P 8333 stays public.
|
|
- host: 8332
|
|
container: 8332
|
|
protocol: tcp
|
|
bind: 127.0.0.1
|
|
auth: local
|
|
- host: 8333
|
|
container: 8333
|
|
protocol: tcp
|
|
auth: none
|
|
auth_rationale: >-
|
|
Bitcoin p2p gossip. Peers are anonymous by design and speak the Bitcoin wire protocol, not HTTP.
|
|
|
|
volumes:
|
|
- type: bind
|
|
source: /var/lib/archipelago/bitcoin
|
|
target: /home/bitcoin/.bitcoin
|
|
options: [rw]
|
|
|
|
environment:
|
|
- BITCOIN_RPC_USER=archipelago
|
|
|
|
health_check:
|
|
type: tcp
|
|
endpoint: localhost:8332
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
|
|
bitcoin_integration:
|
|
rpc_access: admin
|
|
sync_required: true
|
|
testnet_support: false
|
|
pruning_support: true
|