configs/paivana: charge GOA:4200 for example site
This commit is contained in:
parent
d168df26e3
commit
572da9aef9
3 changed files with 157 additions and 6 deletions
|
|
@ -1,13 +1,98 @@
|
|||
# paivana — `paivana.hacktivism.ch`
|
||||
|
||||
GNU Taler **paivana-httpd** reverse-proxy paywall, GOA payments.
|
||||
GNU Taler **paivana-httpd** reverse-proxy paywall (DD 95 / DD 76 style), GOA payments.
|
||||
|
||||
| Item | Value |
|
||||
|------|--------|
|
||||
| Live | `/home/hernani/koopa-paivana/` |
|
||||
| Containers | `koopa-paivana`, `koopa-paivana-upstream` |
|
||||
| Host port | **9025** |
|
||||
| Image | `localhost/koopa-paivana:latest` (built from `Containerfile`) |
|
||||
| Host port | **9025** → Caddy `paivana.hacktivism.ch` |
|
||||
| Currency | **GOA** |
|
||||
| Merchant | `https://taler.hacktivism.ch/instances/goa-shop/` |
|
||||
| Template | `paivana` (`template_type: paivana`, amount **`GOA:4200`**, `website_regex: .*`) |
|
||||
| Access | **`-g`** site-wide: pay once → example upstream free to browse |
|
||||
| Upstream | example site in `upstream/` (compose service) |
|
||||
|
||||
Build: `Containerfile` from `git.taler.net/paivana` + deb.taler.net libs.
|
||||
## Layout
|
||||
|
||||
| Path | Role |
|
||||
|------|------|
|
||||
| `Containerfile` | Multi-stage: build paivana-httpd from `git.taler.net/paivana` + Taler libs |
|
||||
| `compose.yml` | `koopa-paivana` + nginx upstream |
|
||||
| `conf/paivana.conf.template` | Config; secrets substituted at start |
|
||||
| `entrypoint.sh` | Inject secrets → run `paivana-httpd -g -f` |
|
||||
| `secrets/` | **not in git** — live only |
|
||||
| `upstream/` | Protected demo content |
|
||||
| `container-koopa-paivana.service` | systemd --user oneshot compose up |
|
||||
| `taler-systems.gpg` | Deb signing key (build context) |
|
||||
|
||||
## Secrets (live)
|
||||
|
||||
| File | Role |
|
||||
|------|------|
|
||||
| `~/koopa-paivana/secrets/merchant-access-token` | `secret-token:…` for goa-shop |
|
||||
| `~/koopa-paivana/secrets/paivana-secret` | cookie MAC secret (stable across restarts) |
|
||||
|
||||
Mirror notes: `koopa-admin-secrets` → `koopa/home-hernani/koopa-paivana/secrets/` (paths only / examples).
|
||||
|
||||
## Ops
|
||||
|
||||
```bash
|
||||
# as hernani on koopa
|
||||
cd ~/koopa-paivana
|
||||
podman compose build
|
||||
podman compose up -d
|
||||
podman logs -f koopa-paivana
|
||||
curl -si http://127.0.0.1:9025/ | head # 302 → /.well-known/paivana/templates/paivana#…
|
||||
```
|
||||
|
||||
Autostart:
|
||||
|
||||
```bash
|
||||
mkdir -p ~/.config/systemd/user
|
||||
cp ~/koopa-paivana/container-koopa-paivana.service ~/.config/systemd/user/
|
||||
systemctl --user daemon-reload
|
||||
systemctl --user enable --now container-koopa-paivana.service
|
||||
```
|
||||
|
||||
## Network notes
|
||||
|
||||
Rootless pasta cannot hairpin public DNS for the merchant. Compose sets:
|
||||
|
||||
```yaml
|
||||
extra_hosts:
|
||||
- "taler.hacktivism.ch:host-gateway"
|
||||
```
|
||||
|
||||
so `paivana-httpd` can load templates from the merchant API.
|
||||
|
||||
## Caddy
|
||||
|
||||
Vhost → `127.0.0.1:9025` (see `configs/caddy/Caddyfile`).
|
||||
Flags `-g` (site-wide payment) and `-f` (X-Forwarded-For).
|
||||
|
||||
## Merchant template
|
||||
|
||||
```bash
|
||||
curl -X POST 'https://taler.hacktivism.ch/instances/goa-shop/private/templates' \
|
||||
-H "Authorization: Bearer secret-token:…" \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d '{
|
||||
"template_id": "paivana",
|
||||
"template_description": "Paivana paywall (GOA)",
|
||||
"template_contract": {
|
||||
"template_type": "paivana",
|
||||
"summary": "Access to paivana.hacktivism.ch",
|
||||
"website_regex": ".*",
|
||||
"choices": [{ "amount": "GOA:4200", "description": "Unlock example site (then free to browse)" }]
|
||||
}
|
||||
}'
|
||||
```
|
||||
|
||||
## Docs
|
||||
|
||||
- https://docs.taler.net/taler-paivana-manual.html
|
||||
- https://docs.taler.net/design-documents/095-captcha-100.html
|
||||
- https://docs.taler.net/design-documents/076-paywall-proxy.html
|
||||
- https://docs.taler.net/manpages/paivana.conf.5.html
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue