koopa-admin-log/configs
2026-09-16 23:55:47 +02:00
..
bank-landing ops: GOA vanilla landings stats wdGet + collect greening 2026-09-16 23:55:47 +02:00
bbb ops: paivana and caddy config refresh 2026-09-09 00:52:54 +02:00
bonfire bonfire: TODO to file Chromium login stall upstream 2026-08-17 14:59:27 +02:00
caddy ops: GOA vanilla landings stats wdGet + collect greening 2026-09-16 23:55:47 +02:00
castopod docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
cryptpad config: update READMEs and compose files for various services 2026-09-12 21:37:05 +02:00
decidim decidim: mirror koopa-decidim setup (9027, docs for /sm showcase) 2026-08-24 08:49:26 +02:00
exchange-landing ops: GOA vanilla landings stats wdGet + collect greening 2026-09-16 23:55:47 +02:00
firewalld docs: map koopa-nym secrets to koopa-admin-secrets paths 2026-07-16 16:29:19 +02:00
forgejo config: update READMEs and compose files for various services 2026-09-12 21:37:05 +02:00
galene config: update READMEs and compose files for various services 2026-09-12 21:37:05 +02:00
goa-backups goa: backup docs under backups/goa before regio-ng 2026-09-04 14:40:19 +02:00
lab-local ops: GOA merchant-first 2026-09-15 daylog + lab-hosts + APPLY driver 2026-09-16 02:48:57 +02:00
lemmy lemmy: hacktivism extra_themes + apply-branding 2026-08-17 15:04:19 +02:00
meet config: update READMEs and compose files for various services 2026-09-12 21:37:05 +02:00
merchant-landing ops: GOA vanilla landings stats wdGet + collect greening 2026-09-16 23:55:47 +02:00
notes config: update READMEs and compose files for various services 2026-09-12 21:37:05 +02:00
nym nym: polish Containerfile, compose, entrypoint, and README. 2026-07-16 23:50:57 +02:00
paivana config: update READMEs and compose files for various services 2026-09-12 21:37:05 +02:00
prime docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
shared ops: GOA vanilla landings stats wdGet + collect greening 2026-09-16 23:55:47 +02:00
systemd monitoring: koopa login-health timer snapshot on SSH login 2026-08-06 17:10:22 +02:00
taler-exchange docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
taler-exchange-ansible docs: new root as prior history lost (orphan + GC); ~215 commits not recoverable 2026-07-13 10:12:00 +02:00
taler-hacktivism docs/ops: merchant portal instance ids must be lowercase (avoid 401) 2026-07-17 22:36:54 +02:00
taler-hacktivism-bank bank: raise DEFAULT_DEBT_LIMIT to libeufin amount ceiling. 2026-07-16 20:49:21 +02:00
tops docs: tops compose refresh and configs inventory index. 2026-07-17 01:07:00 +02:00
tor tor: change from bookworm-slim to stable-slim; w/ old id online again 2026-09-02 23:15:06 +02:00
ports.md config: update READMEs and compose files for various services 2026-09-12 21:37:05 +02:00
README.md ops: paivana and caddy config refresh 2026-09-09 00:52:54 +02:00

Config mirrors (from host koopa)

Directories are named to match live podman container names where possible.

Directory Live container Image (typical)
taler-hacktivism/ taler-hacktivism taler-hacktivism-live:landing
taler-hacktivism-bank/ taler-hacktivism-bank taler-hacktivism-banking:live
taler-exchange/ conf inside exchange container (see exchange-ansible)
taler-exchange-ansible/ taler-hacktivism-exchange-ansible taler-hacktivism-exchange-ansible:landing
bank-landing/ exchange-landing/ merchant-landing/ nginx landing snippets ports 90139015
koopa-* apps koopa-castopod, koopa-bonfire, koopa-lemmy, koopa-decidim, … compose mirrors
tops/ koopa-tops-ng1ng3 nginxinc/nginx-unprivileged:1.27-alpine (non-root, :8080)
caddy/ firewalld/ systemd/ host services
tor/ koopa-tor-relay (podman host net) localhost/koopa-tor-relay:latest (non-root uid 1000)
nym/ koopa-nym (nym.com nym-node) localhost/koopa-nym:latest (non-root uid 1000)
paivana/ koopa-paivana + paywalls + upstream localhost/koopa-paivana:latest (non-root); public 9025/90289030
notes/ koopa-silverbullet (SilverBullet) localhost/koopa-silverbullet:cachyos (backend 127.0.0.1:19128; paywall 9028)
forgejo/ koopa-forgejo rootless image + user: 1000 + userns keep-id
prime/ jellyfin / qbittorrent linuxserver PUID/PGID=1000

Container process privilege policy: service processes must not run as root inside the container when we control the image/compose. Pattern: uid/gid 1000 + rootless podman userns_mode: keep-id (see forgejo/nym/tor/paivana). Official DB images already drop to postgres/redis/mysql. Exceptions: taler-exchange-ansible (lab image with root SSH — not production service), third-party app images without a rootless variant (bonfire/castopod — track upstream).

Authoritative running inventory: host/overview/LIVE.md.

Secrets never live here — SECRETS.md / koopa-admin-secrets.