25 lines
2 KiB
Markdown
25 lines
2 KiB
Markdown
# Config mirrors (from host koopa)
|
||
|
||
Directories are named to match **live podman container names** where possible.
|
||
|
||
| Directory | Live container | Image (typical) |
|
||
|-----------|----------------|-----------------|
|
||
| `taler-hacktivism/` | `taler-hacktivism` | `taler-hacktivism-live:landing` |
|
||
| `taler-hacktivism-bank/` | `taler-hacktivism-bank` | **`taler-hacktivism-banking:live`** |
|
||
| `taler-exchange/` | conf inside exchange container | (see exchange-ansible) |
|
||
| `taler-exchange-ansible/` | **`taler-hacktivism-exchange-ansible`** | `taler-hacktivism-exchange-ansible:landing` |
|
||
| `bank-landing/` `exchange-landing/` `merchant-landing/` | nginx landing snippets | ports 9013–9015 |
|
||
| `koopa-*` apps | `koopa-castopod`, `koopa-bonfire`, … | compose mirrors |
|
||
| `tops/` | `koopa-tops-ng1` … `ng3` | `nginxinc/nginx-unprivileged:1.27-alpine` (non-root, :8080) |
|
||
| `caddy/` `firewalld/` `systemd/` | host services | |
|
||
| `tor/` | **`koopa-tor-relay`** (podman host net) | `localhost/koopa-tor-relay:latest` (**non-root** uid 1000) |
|
||
| `nym/` | **`koopa-nym`** (nym.com nym-node) | `localhost/koopa-nym:latest` (**non-root** uid 1000) |
|
||
| `paivana/` | **`koopa-paivana`** (+ upstream) | `localhost/koopa-paivana:latest` (**non-root**); upstream unprivileged nginx |
|
||
| `forgejo/` | **`koopa-forgejo`** | rootless image + `user: 1000` + `userns keep-id` |
|
||
| `prime/` | jellyfin / qbittorrent | linuxserver **PUID/PGID=1000** |
|
||
|
||
**Container process privilege policy:** service processes must not run as root inside the container when we control the image/compose. Pattern: uid/gid **1000** + rootless podman **`userns_mode: keep-id`** (see forgejo/nym/tor/paivana). Official DB images already drop to `postgres`/`redis`/`mysql`. Exceptions: **`taler-exchange-ansible`** (lab image with root SSH — not production service), third-party app images without a rootless variant (bonfire/castopod — track upstream).
|
||
|
||
**Authoritative running inventory:** `host/overview/LIVE.md`.
|
||
|
||
Secrets never live here — `SECRETS.md` / `koopa-admin-secrets`.
|