koopa-admin-log/configs/README.md
Hernâni Marques 360fb363de docs: tops compose refresh and configs inventory index.
Update tops stack notes and configs/README service listing.
2026-07-17 01:07:00 +02:00

2 KiB
Raw Blame History

Config mirrors (from host koopa)

Directories are named to match live podman container names where possible.

Directory Live container Image (typical)
taler-hacktivism/ taler-hacktivism taler-hacktivism-live:landing
taler-hacktivism-bank/ taler-hacktivism-bank taler-hacktivism-banking:live
taler-exchange/ conf inside exchange container (see exchange-ansible)
taler-exchange-ansible/ taler-hacktivism-exchange-ansible taler-hacktivism-exchange-ansible:landing
bank-landing/ exchange-landing/ merchant-landing/ nginx landing snippets ports 90139015
koopa-* apps koopa-castopod, koopa-bonfire, … compose mirrors
tops/ koopa-tops-ng1ng3 nginxinc/nginx-unprivileged:1.27-alpine (non-root, :8080)
caddy/ firewalld/ systemd/ host services
tor/ koopa-tor-relay (podman host net) localhost/koopa-tor-relay:latest (non-root uid 1000)
nym/ koopa-nym (nym.com nym-node) localhost/koopa-nym:latest (non-root uid 1000)
paivana/ koopa-paivana (+ upstream) localhost/koopa-paivana:latest (non-root); upstream unprivileged nginx
forgejo/ koopa-forgejo rootless image + user: 1000 + userns keep-id
prime/ jellyfin / qbittorrent linuxserver PUID/PGID=1000

Container process privilege policy: service processes must not run as root inside the container when we control the image/compose. Pattern: uid/gid 1000 + rootless podman userns_mode: keep-id (see forgejo/nym/tor/paivana). Official DB images already drop to postgres/redis/mysql. Exceptions: taler-exchange-ansible (lab image with root SSH — not production service), third-party app images without a rootless variant (bonfire/castopod — track upstream).

Authoritative running inventory: host/overview/LIVE.md.

Secrets never live here — SECRETS.md / koopa-admin-secrets.