Demo images / Build & push demo images (push) Failing after 2m13s
The repo is source code and guidelines only. Nothing about how Archipelago's own fleet is run, or how the team works, stays in it. Untracked (kept on disk, gitignored) — 250 files: - .planning/ (199) and loop/ — internal development process - fleet operations tooling that targets specific nodes: deploy-to-target, deploy-tailscale, deploy-config-defaults, setup-target-dev, setup-aiui-server, setup-https-dev, debug-frontend, node-profile, fleet-fips-pair/unpair, image-recipe/sync-from-live.sh - image-recipe/INTEGRATION-GUIDE.md and docs/multinode-testing-plan.md, both of which are live-server workflow and fleet node inventories - the Phase 10 on-node verification and evidence records, which cite .planning/ as their evidence base KEY-05-ENTROPY-ENFORCEMENT.md was initially moved out with the other Phase 10 docs and then put back: it is cited as normative rationale from ten places in the codebase, including core/clippy.toml, which bans rand::thread_rng and points at it for the reason. That makes it a guideline, not an internal record. Node names removed from source (48 occurrences across comments, manifests and test fixtures): archi-dev-box, archy-x250*, shorty-s, framework-pt, zaza-optiplex, archi-thinkpad. Comments keep the engineering context and the date, which is what carried the meaning; the machine name did not. Three of those were live test values rather than comments and were replaced with valid stand-ins, not prose: two mDNS hostnames and a mesh peer name. An earlier pass substituted "a test node" into a hostname assertion, producing an invalid hostname; caught and fixed as test-node.local. Wipe mechanism: .local-only/manifest.txt inventories every local-only path and .local-only/wipe.sh deletes them on one confirmation, refusing to touch anything git still tracks. Both are themselves untracked, so the public repo does not carry a map of internal filenames. Verified: cargo check -p archipelago --all-features clean; archipelago-container 75/75 tests pass; appOrigin vitest 7/7; audit-secrets 5/5; every relative link in tracked markdown resolves (0 broken). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
66 lines
2.3 KiB
YAML
66 lines
2.3 KiB
YAML
app:
|
|
id: lnd-ui
|
|
name: LND UI
|
|
version: 1.0.0
|
|
description: |
|
|
Archipelago-native HTTP frontend for LND. Runs nginx inside a
|
|
container and serves static assets. LND connection info is fetched
|
|
via an absolute URL that the host nginx routes to the archipelago
|
|
backend on 127.0.0.1:5678, so no upstream auth is baked in.
|
|
|
|
container:
|
|
build:
|
|
context: /opt/archipelago/docker/lnd-ui
|
|
dockerfile: Dockerfile
|
|
tag: localhost/lnd-ui:local
|
|
|
|
dependencies:
|
|
- app_id: lnd
|
|
|
|
resources:
|
|
memory_limit: 64Mi
|
|
|
|
security:
|
|
readonly_root: false
|
|
network_policy: host
|
|
|
|
# Host networking: the container's nginx listens on 18083 directly (see
|
|
# docker/lnd-ui/nginx.conf), because it has to proxy the archipelago backend
|
|
# on 127.0.0.1:5678 same-origin — a bridge container cannot reach that, and
|
|
# the cross-origin fallback broke the app on http-only nodes. `ports:` is
|
|
# intentionally empty because host networking bypasses port mapping, exactly
|
|
# as in apps/bitcoin-ui/manifest.yml.
|
|
#
|
|
# This previously declared `bridge` with 18083:80, which publishes the host
|
|
# port to a container port where nothing listens. scripts/container-specs.sh
|
|
# carried the identical mistake and was fixed alongside this; recreating from
|
|
# it on a test node left :18083 refusing connections.
|
|
# Declared so the APP GATE can see this port. Host networking means Podman
|
|
# publishes nothing (quadlet skips PublishPort in host mode), so `bind:` here
|
|
# is a statement of where the container's own nginx listens — 127.0.0.1 —
|
|
# not a publish instruction. Without this declaration the gate had no idea
|
|
# the port existed: it was neither protected nor listed as unprotected, and
|
|
# served the LND screen unauthenticated on every interface.
|
|
ports:
|
|
- host: 18083
|
|
container: 18083
|
|
protocol: tcp
|
|
bind: 127.0.0.1
|
|
auth: gated
|
|
# First-party companion UI: its nginx forwards the node session cookie
|
|
# to the daemon's authenticated endpoints; without passthrough the gate
|
|
# strips it and every data call 401s while the page shell renders.
|
|
session_passthrough: true
|
|
|
|
volumes: []
|
|
|
|
environment: []
|
|
|
|
health_check:
|
|
type: http
|
|
endpoint: http://127.0.0.1:18083
|
|
path: /
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|